TL;DR: AI supply chain attacks are increasingly targeting proxies, gateways, and MCP servers rather than the model itself, allowing attackers to reach API keys, prompts, and responses in transit, according to Salt’s analysis of the Mercor and LiteLLM incident. The control problem is now visibility and behavioural governance across machine identities, not prompt filtering alone.
NHIMG editorial — based on content published by Salt: AI supply chain attacks expose the agentic action layer risk
By the numbers:
- 60.2% of organizations admit a profound lack of control over the security of the AI models driving their applications.
- 48.9% are essentially blind to non-human, machine-to-machine traffic.
Questions worth separating out
Q: What breaks when AI tools are exposed through loosely governed MCP servers?
A: Loose governance lets model-driven tools cross from context retrieval into state-changing actions without enough oversight.
Q: Why do AI middleware compromises matter to IAM teams?
A: They matter because proxies, gateways, and MCP servers behave like machine identities with access to data and tools.
Q: What do security teams get wrong about AI in procurement?
A: They often focus on model capability and ignore governance boundaries.
Practitioner guidance
- Map every AI intermediary Inventory proxies, gateways, MCP servers, and model-facing brokers, then classify each one as a privileged machine identity with named owners and lifecycle dates.
- Bind telemetry to machine identity Correlate AI traffic to the specific proxy or service account that generated it, so anomalous routing, unusual destinations, and bulk pulls can be attributed quickly.
- Restrict delegated AI access Apply least privilege to each model connector, remove unused tool permissions, and segment external LLM access from internal data paths that do not need it.
What's in the full article
Salt's full article covers the operational detail this post intentionally leaves for the source:
- The specific Agentic Security Graph and how it maps LLMs, proxies, MCP servers, and APIs in runtime.
- The intent-analysis workflow Salt describes for correlating traffic to a machine identity and flagging anomalous sequences.
- The API Attack Surface Assessment process and the kinds of exposures it is designed to surface.
- The blocking actions and runtime triggers used when a proxy begins routing data outside its expected behaviour.
👉 Read Salt's analysis of the Mercor and LiteLLM AI supply chain attack →
Agentic action layer risk: are your AI controls keeping up?
Explore further
The agentic action layer is now a distinct governance domain, not an implementation detail. Proxies, gateways, and MCP servers sit in the trust path between models and enterprise data, so they function like privileged control planes. That means they must be governed as identity-bearing systems with lifecycle controls, not treated as disposable integration plumbing. For identity teams, the lesson is to extend machine identity oversight into AI mediation layers.
A question worth separating out:
Q: Who is accountable when AI search exposes sensitive enterprise data?
A: Accountability sits with the teams that approved the data connections, retrieval scope, and response handling, not just the users who queried the system. Governance should cover access design, provenance controls, and operational monitoring across identity, search, and AI platform owners.
👉 Read our full editorial: AI supply chain attacks expose the agentic action layer risk