AI Governance MCP Server Adds Automatable Safety and Risk Controls
What happened
The AI Governance Institute has updated its open-source ai-governance-mcp server. The server exposes AI governance controls as callable tools inside developer environments like Claude Code and Cursor. It launched in June with three tools: ai_safety_screen, ai_risk_classify, and ai_red_team. This update adds ten more tools. They include ai_mcp_review, which audits an MCP server's own configuration and manifest. Also new: ai_risk_classify_v2 for structured risk intake, and ai_eval_review for tracking red-team results over time. Every tool still maps to a specific control or playbook entry in the Institute's library.
Why it matters
- ·Most teams have no repeatable way to check an MCP server's tool manifest for scope creep. ai_mcp_review gives them one, run before connecting a new server to an agent.
- ·The tools produce structured, citable outputs, but they are not a substitute for human governance sign-off. Organizations should define which checks still require review.
- ·The MCP server is itself a third-party tool connected to an agent, carrying its own supply chain risk. Auditors logged 68 MCP server CVEs in one recent month, so any integration needs its own vendor review.
Governance controls affected
What to do now
- ☐Map the server's four tool outputs against your existing governance gate requirements and document which checks the tool can satisfy as evidence versus which still require independent human review.
- ☐Apply your standard MCP vendor due diligence process (PRC-001, AGT-019) to this server before connecting it to any production agentic pipeline, including a review of the repository's dependency graph and CI/CD workflow configurations.
- ☐Confirm that the ai_risk_classify tool's sector and oversight criteria match the specific risk classification thresholds required by your applicable regulatory frameworks, such as the EU AI Act Annex III categories or Colorado SB205 consequential-decision definitions.
- ☐Record the server version and the bundled control library version in your AI model registry and establish a process for re-assessing governance alignment whenever the server or its upstream control library is updated.
- ☐Define in your agentic AI deployment readiness checklist whether ai_red_team plan outputs must be reviewed by a human red team lead before a system proceeds to deployment, and assign accountability for that review.
What to watch next
Watch whether the Institute adds more tools or changes existing control mappings. A mapping change could affect the value of past outputs already cited in governance records. Regulators have not yet said whether automated MCP checks satisfy documentation duties under frameworks like the EU AI Act. Auditors will likely start asking how teams tell a tool-generated finding from an independently verified one.
Stay ahead of stories like this
Get developments like this, plus everything else that matters in AI governance. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
