FB pixel

AI agent delegation via MCP has gaps a Murderbot could walk through

Gluu CEO’s MCP Dev Summit presentation explains the need for many ‘Governor Modules’
Categories Access Control  |  Biometrics News
AI agent delegation via MCP has gaps a Murderbot could walk through
 

The introduction of Model Context Protocol (MCP) open standard developed by Anthropic has advanced the data-sharing capabilities of AI agents and the systems they interact with, but the question of how to secure these interactions from rogue agents and a host of other threats remains open.

Gluu Founder and CEO Michael Schwartz presented his vision for secure AI agent authorization in a talk titled “Golem to Murderbot: Challenges with Agentic Security Delegation via MCP” at the MCP Dev Summit 2026 in New York City.

The Hebrew story of the Golem from late antiquity raises the question of how an automated actor can be relied on to carry out the intent of the person who automates it. In the story, the Golem becomes unruly as it carries out its task. The “truth” – the equivalent for an AI agent of its mission – becomes more unstable with each change in its network context.

Fortunately, a “kill switch” is built into the Golem.

In Murderbot, a series of books by Martha Wells adapted into an Apple TV series, the “Corporation” which controls “SecuBots” like Murderbot uses a “Governor Module,” a software module which monitors and “punishes” them for policy violations. The title character has gone rogue and hacked its Governor Module, but must fool a second oversight mechanism, the “Hub System,” that everything is in order by feeding data back to it.

Murderbot’s presence is necessary as a security agent to reduce the risk in the scenario the story depicts to the point where it is insurable.

Automation and risk reduction

Schwartz argues that while some people tend to see zero trust in a typical agentic AI flow as a matter of enforcing security at an MCP Gateway, because it is a chokepoint, “we should be good.

“But this would imply that all the traffic is trusted beyond the gateway, which is sort of the definition of what zero trust seeks to avoid in the first place,” Schwartz says.

Instead, “each service needs a Governor Module,” in the form of a policy engine embedded with each service. Each would then produce decision logs, scaling security data and requiring “more operational leverage” for humans to make use of it to take security actions.

Schwartz then explained that human authentication is pretty much solved with mechanisms like passkeys and digital wallets, and even software authentication is for the most part functionally solved.

Authorization is another matter. From an enterprise perspective, the question is: “under what conditions is access allowed?”

The answer may depend on things that have nothing to do with the properties of an AI agent requesting data on behalf of a human. Schwartz gives the example of data governed by agreements between different organizations.

Authorization therefore needs to move beyond role-based access control to policies that include context and complexity.

This leads to his case for using Cedar as “a policy syntax that is analyzable.”

Schwartz concluded his talk by presenting the concept of GovOps, an operating model for enterprise governance through risk management, accountability and transparency.

“Identity is the key for accountability,” Schwartz says, “not authorization.”

The presentation is posted to Schwartz Identerati Office Hours channel.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Governance can keep DPI working for people when other stakeholders turn against them

The promise of digital public infrastructure is in the scale and efficiency that allows governments to improve inclusion and service…

 

Digi Yatra passes 100M journeys as IATA trial validates global interoperability

India’s Digi Yatra platform is making moves toward international deployment after an IATA-led trial showed it can interoperate with global…

 

FBI seeks industry input on biometric algorithms for NGI modernization

The scale of the system is one of the most important details in the notice The Federal Bureau of Investigation…

 

Brazil’s digital regulator invites comment on updates to age verification guidance

Brazil has opened a period of public consultation on its guidance document covering age verification mechanisms, including biometric methods. Per…

 

GitHub exposure points to broader contractor identity security gaps at CISA

A public GitHub repository reportedly maintained by an employee of Nightwing, a contractor supporting the Cybersecurity and Infrastructure Security Agency…

 

Digital identity must be built for interoperability from day one, says Margins CEO

Prominent Ghanaian entrepreneur and Margins ID Group founder and CEO Moses Kwesi Baiden Jnr. has argued that national digital identity…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events