The two-door problem: splitting governance across an MCP gateway and an LLM gateway leaves a gap

· Source: Stacklok · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cybersecurity & Data Privacy · Depth: Advanced, medium

Summary

AI agent governance faces a "two-door problem" where agents interact with models via an AI gateway and invoke tools through an MCP gateway. Enterprises commonly deploy separate vendors for these functions, creating a critical security gap. This split governance allows cross-door attacks, such as prompt injection or data exfiltration, to exploit the seam by entering through one gateway (e.g., a tool result) and exiting through another (e.g., a model call), bypassing detection. Unified governance, provided by a single vendor, addresses this by ensuring consistent identity across actions, enabling a single policy definition for both gateways, and consolidating audit trails into one timeline. While small, internal, or single-door agent deployments might tolerate split governance, unified solutions are essential for agents utilizing both models and tools, those under audit or compliance obligations, and organizations defending against sophisticated cross-door attacks.

Key takeaway

For AI Security Engineers evaluating agent security solutions, recognize that splitting governance between separate model and tool call gateways introduces critical vulnerabilities. If your agents both call models and invoke tools, or if you face audit obligations, you must prioritize unified governance from a single vendor. This approach ensures consistent identity, a single policy framework, and a consolidated audit trail, effectively closing the seam exploited by prompt injection and data exfiltration attacks.

Key insights

The "two-door problem" in AI agent governance arises from splitting model and tool call monitoring, creating a critical security gap.

Principles

Method

Unified governance integrates model and tool call monitoring within a single control plane, enforcing consistent policies and identity across both gateways to detect cross-door attacks.

In practice

Topics

Best for: AI Security Engineer, AI Architect, Director of AI/ML

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Stacklok.