TL;DR: Model Context Protocol and Agent2Agent protocols let foundation models move from answering questions to taking actions across tools and data sources, which Collibra argues raises the stakes for governed data, cross-functional use cases, and approved AI actions. The core issue is no longer model capability alone, but whether identity, data, and task context are controlled before AI systems can act.
Editorial analysis by NHI Mgmt Group, based on content published by Collibra: “The bookends of AI: Why data and business impact still define success”.
Key questions
Q: What breaks when AI agents bypass a centralized MCP gateway?
A: When agents bypass a centralized MCP gateway, security controls fragment across notebooks, scripts, and individual servers.
Q: Why do A2A workflows increase identity governance risk for AI programmes?
A: A2A increases risk because delegation can move across multiple machine actors before a human sees the result.
Q: How should security teams govern AI agents in shared workspaces?
A: Security teams should treat the workspace audience as part of the authorization decision.
Practitioner guidance
- Define approved action boundaries for AI agents Document which tool actions, data sources, and workflow steps an AI agent may perform without additional approval.
- Classify MCP-connected tools as access surfaces Inventory every tool exposed through MCP and assign an owner, purpose, and review cadence.
- Build delegation controls for A2A workflows Map which agent can hand off work to another agent, what context carries forward, and where the chain must stop for human approval.
Bottom line: MCP and A2A do not just expand AI capability, they change the governance question from output quality to authorised action.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Model Context Protocol creates an authorisation problem, not just an integration problem. Once an AI system can reach tools and data sources through a shared protocol, the governance question shifts to who authorised the action, not whether the model could technically perform it. That means identity controls have to define permissible action space before runtime, because the model is now operating with side effects. Practitioners should stop treating tool connectivity as neutral plumbing and start treating it as a governed access path.
A few things that frame the scale:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How do you know when an AI agent has outgrown its current access model?
A: An AI agent has outgrown its access model when it can initiate or complete actions that were never explicitly reviewed as part of the business process. Signs include broad tool reach, unclear handoff points, and approvals that describe intent but not the actual action set.
👉 Read our full editorial: Model context protocol changes the governance model for AI agents