Dejan Lukic shares some advice:
AI agents don’t ask permission before every query. Instead, they themselves decide which tools to call and chain together. That’s a fundamentally different risk model than traditional access control – and it’s exactly why MCP (Model Context Protocol) servers connected to databases need their own security playbook.
This guide covers the failure modes to watch for: confused deputy, token passthrough, prompt injection, over-scoped credentials, and session hijacking. Then, how to prevent those failure modes – using authentication, authorization, and least-privilege controls.
Treat them like any other often-confused employee. Which, in many environments, means making them sysadmins.