TL;DR: MCP security is now a data-governance problem as much as a tooling problem, according to Nightfall: agents can move sensitive information through local stdio and remote transports that legacy DLP, endpoint, and network controls often do not reconstruct, while the report cites 98% GenAI adoption and 49% AI agent usage across 35,000+ enterprise applications. The control gap is no longer visibility alone, but whether organisations can inspect and stop machine-speed data movement before it leaves approved boundaries.
NHIMG editorial — based on content published by Nightfall: Best AI Agent Security & MCP Security Platforms for MCP Tool Call Security in 2026
By the numbers:
- Nightfall's 2026 AI Agent Risk & Action Report analyzed more than 35,000 enterprise applications and reports 98% GenAI adoption, 49% AI agent usage, and 81% of GenAI usage occurring outside the three providers security teams were monitoring.
- Nightfall says its detection engine delivers 95% precision out of the box and cuts false positives by 95% compared with a 5% to 25% baseline for legacy pattern-matching DLP.
- Nightfall says endpoint coverage across macOS and Windows devices can be achieved within a week, with endpoint agents deploying via MDM in approximately 30 minutes.
Questions worth separating out
Q: What breaks when MCP tool calls are not inspected like normal data flows?
A: Security teams lose visibility into the actual context of agent actions, including tool arguments, responses, and delegated steps.
Q: Why do MCP-enabled agents complicate access governance?
A: Because the decision is no longer only who can log in.
Q: How do you know if MCP security controls are actually working?
A: You know MCP controls are working when untrusted endpoints are blocked, privileged tool calls are minimal, and audit logs show only approved commands and data flows.
Practitioner guidance
- Define MCP server trust boundaries Inventory every MCP server, the identities that can reach it, and whether its tools are read-only, read/write, or destructive.
- Inspect local and remote agent transports Test whether your controls see both local stdio sessions and remote Streamable HTTP traffic, because missing either path leaves a gap in tool-call visibility.
- Apply inline enforcement to high-risk tool calls Use block, redact, quarantine, or approval workflows for actions that move secrets, source code, or regulated data.
What's in the full article
Nightfall's full article covers the operational detail this post intentionally leaves for the source:
- Platform-by-platform evaluation of MCP discovery, inspection depth, and enforcement approach
- Deployment characteristics for local stdio, remote HTTP, and IDE-connected agent workflows
- Feature-level comparisons of block, redact, quarantine, and approval-based remediation options
- Implementation notes on how Nightfall maps prompts, tool calls, and shell commands across agent sessions
👉 Read Nightfall's analysis of MCP tool call security platforms →
MCP tool call security: are your controls keeping up with agents?
Explore further