DEV Community

Cover image for OWASP Has Mapped MCP Risk. Enterprises Still Have to Govern It.
Obot AI
Obot AI

Posted on • Originally published at obot.ai

OWASP Has Mapped MCP Risk. Enterprises Still Have to Govern It.

By Bill Maxwell, Software Architect Obot AI

In April 2026, Microsoft disclosed a critical function in its hosted MCP service that required no authentication. OWASP had already named exactly this risk — MCP07:2025, Insufficient Authentication & Authorization — in its MCP Top 10. The risk was mapped. The control wasn't enforced.

That gap is the subject of this post.

OWASP now covers AI risk across three distinct layers: LLM applications, agentic systems, and MCP servers specifically. Together they give security teams a useful map. What they don't do is tell you where enforcement actually happens — because the MCP spec deliberately leaves that to implementers. The July 28 specification says so explicitly: MCP "cannot enforce these security principles at the protocol level."

So what does enforcing them actually require? Obot Software Architect Bill Maxwell breaks it down into four questions every enterprise running MCP needs to be able to answer at any moment: what MCP servers exist, who is acting through them, what are they authorized to do right now, and what can you prove after the fact.

The controls aren't new. What changed is the operating conditions they have to hold under.

⏱ 11-minute read · 📓 Full article

Originally published on Obot AI

Top comments (0)