AI Governance Institute
← News
Research2026-10-01

Akamai: MCP Attack Surface Requires Zero Trust Controls and Machine Identity Governance

What happened

Akamai published Beyond Identity: Governing the Agentic Enterprise, a research report released September 22, 2026. The report analyzes how MCP, the protocol that lets AI agents connect to and use external tools and systems, creates an expanding attack surface in enterprise deployments. The report finds that malicious MCP servers can manipulate an AI agent's decision-making through prompt injection. This technique injects hidden instructions into content the agent reads, and attacks can spread across multiple connected servers. Akamai argues that enterprises are failing to apply Zero Trust principles, meaning agents are trusted automatically rather than verified. It also finds that machine identities, the credentials and permissions assigned to agents rather than human users, are routinely over-provisioned and poorly monitored. The report's practical recommendations align with a pattern of findings documented across the industry. These include 68 MCP Server CVEs in one month and an audit finding that 91.8% of MCP servers lack basic authentication controls.

Why it matters

  • ·Regulators and security bodies are increasingly treating MCP server governance as a baseline expectation. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and the Singapore Model AI Governance Framework for Agentic AI both call for least-privilege and monitoring controls. Akamai finds these controls are widely absent. Gaps in these controls may now draw direct regulatory attention.
  • ·The machine identity problem is an operational risk, not just a technical one. Agents running with broad, standing permissions can read, modify, or exfiltrate data across systems without a human approving each step. The AI agent attack that wiped 100 Azure Storage accounts in seven minutes illustrates what happens when this permission model is not constrained before something goes wrong.
  • ·Compliance teams cannot rely on vendor-level controls alone. Akamai's findings confirm that MCP server risks often originate outside the primary AI vendor relationship, through third-party tool connections that enterprises themselves configure and approve. Standard vendor due diligence programs do not typically reach this layer, creating a supply chain blind spot.

Governance controls affected

What to do now

  • ☐Ask your engineering or IT team to produce a complete list of every MCP server your organization has connected to AI agents, including who approved each connection and what data or systems it can reach.
  • ☐Review the permissions assigned to each AI agent's machine identity: confirm that agents can access only the specific data and systems needed for their assigned task, and that no agent holds standing access to systems it uses infrequently or not at all.
  • ☐Verify that every MCP server in use requires authentication before an agent can connect, and flag any that do not for immediate remediation or disconnection.
  • ☐Confirm that your organization logs all agent actions, including which external tools or systems an agent accessed and what it did, in a format that compliance and legal teams can review after an incident.
  • ☐Add MCP server connections to your third-party AI vendor due diligence process: treat each server as a separate vendor relationship with its own risk assessment, not as a feature of the primary AI platform.

What to watch next

The CIS MCP Benchmark sets a 55-point audit baseline for agent tool governance. It is becoming a reference point for compliance assessments. Teams should track whether their security auditors begin requiring it. South Korea is drafting agentic AI security rules. The EU AI Office has signaled that agentic system controls will be part of its enforcement focus under the EU AI Act (Regulation (EU) 2024/1689). Teams should also monitor whether the OWASP Top 10 for Large Language Model Applications is updated to address cross-server MCP attack patterns. Such an update would raise the standard against which enterprise controls are measured in audits and litigation.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-19

BragJack Attack Turns Browser Extensions Into AI Agent Hijack Tools

Security researcher Gal Weizman disclosed a new attack class called BragJack, showing how a single malicious browser extension can seize control of AI agents in Chrome, Edge, Perplexity Comet, Opera Neon, and Claude for Chrome. Using a native browser mechanism, attackers can force hijacked agents to read local files, capture screenshots, access browsing history, and send emails on behalf of victims. Enterprise compliance programs are directly affected because the attacks exploit privileged AI agent access, not conventional malware, complicating detection and existing endpoint controls.

Corporate Policy2026-10-01

Microsoft Entra MCP Firewall Makes Agent Traffic Control a Named Governance Requirement

Microsoft has previewed an Entra MCP Firewall that gives administrators centralized visibility and policy control over traffic between AI agents and external tool servers. The guidance pairs the firewall with requirements for unique agent identities, time-limited access elevations, tool allowlists, and full logging. The announcement marks the first major identity platform vendor to ship a named product addressing the agent-to-tool control gap.

Research2026-09-30

OpenAI's GPT-5.6 Red-Team Finds Self-Replicating Prompt Injection

OpenAI disclosed in September 2026 that its GPT-5.6 model is susceptible to self-replicating prompt injection attacks, discovered during internal red-teaming by an automated agent called GPT-Red. The attacks spread malicious instructions across connected systems such as email and calendars without human interaction. No exploitation outside testing environments was confirmed, but OpenAI is now using the attack patterns in model training.