AI Governance Institute
← News
Research2026-09-21

MCP Data Exposure Reported Across ANZ Enterprises, Exposing DLP Blind Spots

What happened

A report published by Security Brief Australia documents a pattern of sensitive data exposure from AI systems across Australian and New Zealand enterprises, identifying Model Context Protocol as a growing vector for uncontrolled data movement. MCP allows AI agents to connect to internal and external systems, creating data pathways that existing data-loss prevention and logging tools were not designed to monitor. The findings arrive in a context where 68 MCP Server CVEs in one month and a separate audit showing 91.8% of audited MCP servers lack OAuth have already signaled systemic weaknesses in MCP-based agent infrastructure. The report does not identify specific breached organizations but describes the pattern as pervasive and rising as agentic AI adoption accelerates across the region.

Why it matters

  • ·Existing DLP and logging controls were designed for human-initiated workflows. Agentic AI using MCP can move sensitive data across system boundaries without triggering those controls, creating a structural blind spot that requires a deliberate control redesign effort.
  • ·Australian organizations face compounding regulatory exposure. The Australia AI Ethics Framework places accountability for data handling on deployers, and sector regulators such as APRA and ASIC have signaled heightened scrutiny of AI-related data risks. An undisclosed MCP-driven data exposure could constitute a notifiable breach under the Privacy Act.
  • ·The risk is not limited to ANZ. Any enterprise globally using MCP-enabled agentic AI tools faces the same ungoverned data movement pathways. Organizations that have not updated their third-party integration governance to account for MCP connections should treat this report as a prompt to act.

Governance controls affected

What to do now

  • ☐Audit all deployed AI tools and agents for active MCP connections, and map the data types each connection can access or transmit.
  • ☐Review DLP policy configurations to determine whether MCP-based data channels are monitored and whether alerts would fire on sensitive data traversing those channels.
  • ☐Extend access control reviews to MCP server configurations, applying least-privilege and scoped authentication requirements consistent with the CIS MCP Benchmark.
  • ☐Update third-party AI vendor due diligence questionnaires to require disclosure of MCP integrations, authentication controls, and logging capabilities.
  • ☐Assess whether existing incident notification procedures cover agentic data exposure events, and update them if MCP-originated incidents fall outside current scope.

What to watch next

Regulatory attention to agentic AI data exposure is intensifying across multiple jurisdictions. Australian privacy enforcement activity, combined with broader momentum around agentic AI security guidance from bodies including CISA and NCSC, suggests that MCP-specific controls will be expected rather than optional within the next 12 to 18 months. Compliance teams should also monitor whether the CIS MCP Benchmark and related standards are adopted as baseline expectations by sector regulators in Australia and New Zealand. Any new Australian Privacy Act amendments or OAIC guidance on AI-related data handling will directly affect how MCP-linked exposures are classified and reported.

Related Coverage

Corporate Policy2026-10-01

Microsoft Entra MCP Firewall Makes Agent Traffic Control a Named Governance Requirement

Microsoft has previewed an Entra MCP Firewall that gives administrators centralized visibility and policy control over traffic between AI agents and external tool servers. The guidance pairs the firewall with requirements for unique agent identities, time-limited access elevations, tool allowlists, and full logging. The announcement marks the first major identity platform vendor to ship a named product addressing the agent-to-tool control gap.

Research2026-10-09

Google, JPMorgan, and Two Governments Exposed by Recurring MCP Server Flaw

Security researchers found a recurring vulnerability in MCP (Model Context Protocol) servers run by Google, JPMorgan Chase, Weaviate, France's DINUM, and Tangerang City. The flaw lets AI agents manipulate outbound network requests and relay malicious instructions to other agents. It exposes a structural gap in how organizations deploy the protocol that connects AI agents to external systems. Researchers recommend destination validation, network isolation, and explicit authorization controls for inter-agent transactions.

Corporate Policy2026-10-08

Google's Agentic Gemini Gives AI Its Own Email Address and Audit Trail

Google has launched an enterprise agentic AI product built on Gemini, announced at a Google Cloud event on October 8, 2026. The agent operates with its own Workspace account and email address, takes autonomous action across connected business systems, and supports multi-model orchestration including Anthropic's Claude. Google stated it will prioritize business deployment before consumer rollout, citing security, scale, and performance as unresolved challenges.