68% of employees use unapproved AI tools at work without employer disclosure, but most shadow AI detection tools only track network-level usage and miss high-risk prompt-layer data exfiltration events. Effective detection requires layered coverage that balances security needs with operational capacity and privacy regulations like GDPR.
Tag: security
80 posts tagged with "security" — Page 2 of 4
92% of organizations agree governing AI agents is critical to enterprise security, but only 44% have implemented policies to do so. This gap stems from a structural mismatch between legacy security models and autonomous agent systems, creating an unbudgeted identity and governance crisis for enterprises.
Anthropic's Model Context Protocol (MCP) has seen widespread enterprise adoption but ships without mandatory authentication, built-in access controls, or audit logging. This architectural gap creates critical security risks including tool poisoning, path traversal vulnerabilities, and ungoverned credential sprawl. Teams must implement gateway-based governance and description pinning to mitigate these threats.
OpenAI's GPT-5.6 launch restricts frontier model access to a small group of U.S. government-vetted 'trusted partners' under a new dual-track release system. This structure creates a hard barrier for the open source community, blocking independent research, transparent benchmarking, and competitive development of open source AI alternatives.
The July 2026 Model Context Protocol specification removes protocol-level session state and the initialize handshake to enable stateless HTTP operation and simple round-robin load balancing. While this cuts infrastructure complexity, it shifts security, state management, and input validation responsibilities to application code, creating new risks for teams without dedicated MCP security engineering expertise.
The July 2026 Model Context Protocol (MCP) stateless specification removes core session and handshake features, requiring unplanned migration work for most existing remote MCP deployments. While it simplifies horizontal scaling, it shifts security responsibilities to development teams and introduces new attack surfaces, with total migration and operational costs often matching or exceeding self-hosted expenses for mid-market teams.
With over 10,000 public MCP servers available in 2026, most carry unpatched security flaws and waste tokens with unnecessary tool definitions. This guide explains why development teams should stick to 3 curated, production-ready servers to cut costs and reduce risk. Learn which servers to prioritize for code, knowledge, and verification tasks.
The fast-growing MCP ecosystem lacks official maintained servers, leaving teams to rely on third-party open source options. Overloading on MCP servers burns context window tokens and hurts agent accuracy, while upcoming protocol revisions and past SDK vulnerabilities require careful, minimal server curation.
The July 2026 MCP stateless spec update removes protocol-level session tracking, shifting full logging and monitoring responsibility to individual implementers. Most native MCP server logs fail enterprise compliance requirements for auditability and regulatory standards like SOC 2 and GDPR. This guide outlines current best practices for MCP observability and new gaps introduced by the spec change.