TL;DR: Tool routing, not just model routing, is what lets AI agents generate images, transcribe audio, search the web, and publish content through MCP servers, skills, and API calls, according to WorkOS. The governance problem is no longer model choice alone, but whether agents can invoke capabilities safely and within bounded identity scope.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Model Routing vs Tool Routing: How to give your AI agents superpowers”.
Key questions
Q: What breaks when an AI agent is allowed to call tools without strict scope controls?
A: The main failure is privilege expansion.
Q: Why does tool routing increase risk more than model routing?
A: Model routing changes which LLM thinks, but tool routing changes what the agent can actually do.
Q: How should security teams govern MCP servers used by AI coding assistants?
A: Treat MCP servers as privileged trust boundaries, not simple data sources.
Practitioner guidance
- Inventory every tool route Document each MCP server, skill, and API connection an agent can reach, then classify it by the business action it enables and the identity context it inherits.
- Scope tools by task boundary Limit each agent to the smallest viable tool set for the workflow it is supposed to perform, and separate publishing, retrieval, and execution paths where possible.
- Review chained capabilities Test whether two tools combined create a materially broader action path than either one alone, especially when search, code execution, and publishing are linked.
Bottom line: AI agents become materially more capable when tool routing gives them access to external services through MCP, skills, and API calls.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Tool routing is the real identity boundary for AI agents: the model is only the decision layer, while MCP-connected tools define what the system can actually do. That means governance failures will appear first as overbroad capability exposure, not as poor model selection. Practitioners should treat each tool path as a delegated entitlement with its own risk profile.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations separate content creation tools from publishing tools for agents?
A: Yes, when the workflow permits it. Separating content creation from publishing reduces the chance that a single agent session can both generate and release material without an independent control point. That separation also improves review, because the system can inspect output before it becomes externally visible.
👉 Read our full editorial: Tool routing changes what AI agents can do with MCP