Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

MCP servers and AI action-layer risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: MCP servers have moved from developer experiments into production infrastructure, where they connect AI agents to real systems through APIs and create a new action layer for access control and monitoring, according to Salt. The central issue is not model quality but whether organisations can see, govern, and contain machine-speed actions before they become invisible backdoors.

NHIMG editorial — based on content published by Salt: MCP servers and the AI action layer risk in production

By the numbers:

Questions worth separating out

Q: How should security teams govern MCP servers used by AI coding assistants?

A: Treat MCP servers as privileged trust boundaries, not simple data sources.

Q: Why do MCP-based agents create more risk than ordinary API integrations?

A: Because the agent is choosing actions, chaining tools, and preserving context across steps.

Q: What do organisations get wrong about AI safety and access control?

A: Organisations often focus on model outputs while ignoring the privileges behind the model.

Practitioner guidance

  • Inventory every MCP-connected identity and tool path Build a live register of agents, MCP servers, downstream APIs, and the service accounts or tokens used to connect them.
  • Scope tool permissions to the minimum viable action set Replace broad run-any-query or shared API keys with task-specific permissions, explicit tool allowlists, and separate identities for high-risk actions.
  • Add behavioural detection for off-script agent activity Baseline normal agent sequences and alert when an agent suddenly changes query volume, exports data, touches new systems, or chains multiple privileged actions.

What's in the full article

Salt's full article covers the operational detail this post intentionally leaves for the source:

  • The article's three-pillar operating model for seeing, governing, and protecting agentic infrastructure.
  • The specific posture and protection patterns Salt associates with MCP server risk, including intent analysis and behavioural baselining.
  • The vendor's own examples of how discovery, policy templates, and alerts are applied across AI agents, MCP servers, and APIs.
  • The source article's compliance framing for EU AI Act and ISO 42001 alignment in agentic environments.

👉 Read Salt's analysis of MCP server risk and the AI action layer →

MCP servers and AI action-layer risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

The real risk has moved from model output to delegated execution. MCP servers are the place where intent becomes action, and that is where identity governance becomes operational rather than theoretical. Once an agent can press buttons on behalf of a user or workflow, the security question is no longer only what the model knows. It is what the agent is authorised to do, at runtime, across every connected API.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What should teams do if an MCP server can execute OS commands?

A: Treat it as privileged execution and place it under the same scrutiny as administrative access. Restrict who can deploy it, separate the identity it uses from lower-risk tools, and monitor command paths continuously. If the server can reach the operating system, the boundary has already moved beyond ordinary integration risk.

👉 Read our full editorial: MCP servers expose the new AI action layer risk in production



   
ReplyQuote
Share: