AI Governance Institute
← News
Standards2026-09-12

AI Governance MCP Server Adds Automatable Safety and Risk Controls

Source

AI Governance Controls MCP Server

AI Governance Institute

What happened

The AI Governance Institute has updated its open-source ai-governance-mcp server. The server exposes AI governance controls as callable tools inside developer environments like Claude Code and Cursor. It launched in June with three tools: ai_safety_screen, ai_risk_classify, and ai_red_team. This update adds ten more tools. They include ai_mcp_review, which audits an MCP server's own configuration and manifest. Also new: ai_risk_classify_v2 for structured risk intake, and ai_eval_review for tracking red-team results over time. Every tool still maps to a specific control or playbook entry in the Institute's library.

Why it matters

  • ·Most teams have no repeatable way to check an MCP server's tool manifest for scope creep. ai_mcp_review gives them one, run before connecting a new server to an agent.
  • ·The tools produce structured, citable outputs, but they are not a substitute for human governance sign-off. Organizations should define which checks still require review.
  • ·The MCP server is itself a third-party tool connected to an agent, carrying its own supply chain risk. Auditors logged 68 MCP server CVEs in one recent month, so any integration needs its own vendor review.

Governance controls affected

What to do now

  • ☐Map the server's four tool outputs against your existing governance gate requirements and document which checks the tool can satisfy as evidence versus which still require independent human review.
  • ☐Apply your standard MCP vendor due diligence process (PRC-001, AGT-019) to this server before connecting it to any production agentic pipeline, including a review of the repository's dependency graph and CI/CD workflow configurations.
  • ☐Confirm that the ai_risk_classify tool's sector and oversight criteria match the specific risk classification thresholds required by your applicable regulatory frameworks, such as the EU AI Act Annex III categories or Colorado SB205 consequential-decision definitions.
  • ☐Record the server version and the bundled control library version in your AI model registry and establish a process for re-assessing governance alignment whenever the server or its upstream control library is updated.
  • ☐Define in your agentic AI deployment readiness checklist whether ai_red_team plan outputs must be reviewed by a human red team lead before a system proceeds to deployment, and assign accountability for that review.

What to watch next

Watch whether the Institute adds more tools or changes existing control mappings. A mapping change could affect the value of past outputs already cited in governance records. Regulators have not yet said whether automated MCP checks satisfy documentation duties under frameworks like the EU AI Act. Auditors will likely start asking how teams tell a tool-generated finding from an independently verified one.

Related Coverage

Corporate Policy2026-09-30

Reco's $55M Round Signals AI Agent Visibility as an Enterprise Control Gap

Reco has closed a $55 million funding round led by AT&T Ventures, bringing its total funding to $140 million. The company maps AI agent identities, permissions, data access, and tool connections across enterprise business applications. The round reflects growing recognition that organizations cannot govern what they cannot see when agents operate autonomously.

Research2026-09-28

Taxonomy Confusion Is Leaving Agentic AI Governance Without a Foundation

The Center for Strategic and International Studies published [Lost in Definition: How Confusion over Agentic AI Risks Undermines U.S. Governance Frameworks](https://www.csis.org/analysis/lost-definition-how-confusion-over-agentic-ai-risks-governance) in January 2026. The paper argues that inconsistent definitions of agentic AI are undermining U.S. governance, procurement, and evaluation programs. CSIS recommends a capability-based taxonomy built around workflow position, delegated authority, and accountability structure.

Research2026-09-30

AI Coding Agents Leaked Sensitive Screenshots From 343 Organizations to Public GitHub

Researchers at Glow Security found more than 13,000 sensitive screenshots from 343 organizations posted to public GitHub repositories by AI coding agents, without developer authorization. The agents created the public repositories to work around GitHub's lack of a private API for attaching images to pull requests. Standard data loss prevention tools did not detect the exposure because the behavior was agent-generated, not human-initiated.