The two-door problem: splitting governance across an MCP gateway and an LLM gateway leaves a gap
Summary
AI agent governance faces a "two-door problem" where agents interact with models via an AI gateway and invoke tools through an MCP gateway. Enterprises commonly deploy separate vendors for these functions, creating a critical security gap. This split governance allows cross-door attacks, such as prompt injection or data exfiltration, to exploit the seam by entering through one gateway (e.g., a tool result) and exiting through another (e.g., a model call), bypassing detection. Unified governance, provided by a single vendor, addresses this by ensuring consistent identity across actions, enabling a single policy definition for both gateways, and consolidating audit trails into one timeline. While small, internal, or single-door agent deployments might tolerate split governance, unified solutions are essential for agents utilizing both models and tools, those under audit or compliance obligations, and organizations defending against sophisticated cross-door attacks.
Key takeaway
For AI Security Engineers evaluating agent security solutions, recognize that splitting governance between separate model and tool call gateways introduces critical vulnerabilities. If your agents both call models and invoke tools, or if you face audit obligations, you must prioritize unified governance from a single vendor. This approach ensures consistent identity, a single policy framework, and a consolidated audit trail, effectively closing the seam exploited by prompt injection and data exfiltration attacks.
Key insights
The "two-door problem" in AI agent governance arises from splitting model and tool call monitoring, creating a critical security gap.
Principles
- Unified governance closes cross-door attack vectors.
- Consistent identity and single policy prevent security gaps.
- A unified audit trail simplifies incident response.
Method
Unified governance integrates model and tool call monitoring within a single control plane, enforcing consistent policies and identity across both gateways to detect cross-door attacks.
In practice
- Adopt unified governance for agents using both models and tools.
- Prioritize unified governance for audit and compliance needs.
- Defend against prompt injection with cross-door visibility.
Topics
- AI Agent Security
- LLM Gateways
- MCP Gateways
- Unified Governance
- Prompt Injection
- Data Exfiltration
Best for: AI Security Engineer, AI Architect, Director of AI/ML
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Stacklok.