From the Obot AI team
An organization can have its EU AI Act risk tiers mapped, ISO/IEC 42001 certification underway, and a model review board that meets every month — and still have no answer to a basic operational question: which of the MCP servers its agents can reach were ever vetted for anything?
The problem is structural. Most enterprise AI governance frameworks — the EU AI Act, NIST AI RMF, ISO/IEC 42001 — were built to govern models: their training data, outputs, and risk classification. None of them were designed to answer for an agent's runtime decision to call an MCP tool. The entire tool layer is effectively ungoverned even in organizations with mature AI governance programs.
This post maps exactly where general AI governance frameworks stop at the model boundary, and what an MCP-specific governance layer actually needs to include: policy, risk classification, registration-time vetting, runtime monitoring, audit trails, and a maturity model for managing the tool layer.
If your organization is running MCP in production and has a governance program that doesn't explicitly cover it — this is the framework you're missing.
⏱ 18-minute read · 📓 Full article
Originally published on Obot AI
Top comments (0)