Already in force

Where are your AI governance artifacts? Where is your proof? See what the law expects →

§ Perspective · MCP Gateways · September 30, 2026

The master key
nobody wrote down.

A newer class of product hands your AI assistant one key that opens everything. It is a useful category solving a real problem. Who owns yours?

By Lindsay Hiebert · Founder · CISSP

A single brass master key on a dark ledger page, rows of smaller keys faint behind it, passing through a sealed record to reach six connected systems.

Ten keys, or one.

For two years the conversation about AI and your data was about individual connectors. One assistant, one system, one key. Someone connected the chatbot to the CRM. Someone else pointed a coding assistant at a database. Each key could be found, named and taken back.

A newer class of product changes the shape of the problem. It hands the AI assistant one key that opens everything: the CRM, the ERP, the HR system, finance, the warehouse, and the on-premises database that still runs the business. Products like Zapier MCP, Composio, CData Connect AI and Workato Enterprise MCP do this well. They do it because customers asked for it. An assistant that can reach one system at a time is a demo. An assistant that can reach all of them is a colleague. This is a useful category solving a real problem.

It is also the single most important object in the building to govern.

Two shapes of the same key.

Some vendors run the key ring for you. They operate the connectors, hold or broker the credentials, and carry your data through their infrastructure. That is the managed connector catalog. Zapier MCP, Composio, CData Connect AI and Workato are examples.

Some vendors hand you the ring and you run it yourself. You operate the gateway and the servers behind it, and the vendor never holds a credential. That is the bring-your-own-server gateway. Docker MCP Gateway, Microsoft MCP Gateway and Kong AI Gateway are examples.

Both are legitimate. Each asks a different question of the company that deploys it. When a vendor holds the key, the question is who governs the vendor and every credential behind it. When you hold the key, the question is who operates it and what policy it enforces. The glossary entry for MCP Gateway sets out both shapes in full.

Three questions.

A master key deserves three questions, and none of them is technical.

Who owns yours? One name, not a team.

Where is it written down what it may open, and whether it may write or only read?

Are the people and agents holding it tied to your identity system, or to a shared password that was copied into a configuration file somewhere?

Those three questions are now a finding SanctumShield raises: the MCP Gateway Governance Gap. If the answers exist, the finding closes. If they do not, the report says so, on a date.

This is not theoretical.

The people who study this closely are saying the same three things: name an owner, scope the access, govern the identity.

12,520
Internet-accessible MCP services across 8,758 unique IP addresses as of April 28, 2026, reachable without authentication; over 21,000 in the dataset by May 6
25%
of enterprise GenAI applications will experience at least five minor security incidents per year by 2028, up from 9% in 2025; 15% at least one major incident per year by 2029, up from 3%
492
MCP servers found running with no client authentication or traffic encryption, exposing 1,402 tools; about 74% hosted on major cloud providers and more than 90% giving direct read access to the data source

Censys counted the internet-reachable ones. Trend Micro read what they exposed: more than 90 percent of the servers it found gave direct read access to the data source, in natural language, to anyone who arrived. Gartner put a forecast on the consequence and named the mechanism. Aaron Lord, Sr. Director Analyst at Gartner, put it this way: “MCP was built for interoperability, ease of use and flexibility first, so security mistakes can manifest without continuous oversight for agentic AI.” His recommendation was a formal security review for MCP use cases, reinforced with authentication and authorization “tailored specifically for AI agents, not inherited from human user roles.”

An owner. A scope. A governed identity. The research and the finding ask the same three questions.

What the law already asks.

None of this waits for a new AI statute. GDPR Article 28 has said since 2018 that a vendor which processes personal data on your behalf is a processor, and that the relationship must be recorded in a contract stating what the processor may do. HIPAA says the same for business associates at 45 CFR §164.308(b). A managed connector catalog that carries your data is that vendor. Outsourcing the work never outsources the obligation.

Boards have their own line. Delaware’s Caremark doctrine, restated in Marchand v. Barnhill in 2019, asks whether the directors made a good-faith effort to put a reporting system in place for a mission-critical risk. A key that reaches every system in the company is difficult to describe as anything else.

The AI-specific duties are already in force too. EU AI Act Article 4 has required measures supporting AI literacy since February 2, 2025. Article 50 transparency has applied since August 2, 2026. Colorado SB 26-189 takes effect January 1, 2027. So the questions a regulator, an underwriter or a director will ask are not new ones. Can you show the contract that names the vendor as your processor? Can you point to the line in the register where the gateway sits? Can you name the person who signed off on what it may open?

The bet you are making by waiting.

Not acting is not neutral. It is a decision to keep a master key in circulation without an inventory of what it opens or a name against who holds it, and to bet the business that nobody will ask. Ignorance is not a defense. The law is clear, and it has been clear for years. The only question a delay answers is who will be the one to find the gap first: you, or the person asking.

What the record looks like.

One register entry for the gateway, with the connected systems recorded as children beneath it. A named owner. A one-page scope of what the agents behind it may and may not do, with a signer. Evidence that the identities flowing through it come from your identity provider, not a shared secret. That is a governance artifact. It is what a board, an underwriter or a regulator will ask to see, and it fits on a page.

How SanctumShield helps, stated plainly.

The audit now asks the question. It names the gateway in the Executive Risk Report as a Tier-1 dependency, flags the gap when any of the three basics is missing, and gives you the dated, third-party-verifiable record. SanctumShield sits above the gateway and is complementary to it. The vendor enforces and logs. You prove you govern. A gateway is a control point. It does not, by itself, constitute governance, and no vendor claims it does.

A program, not a check.

Governance is a continuous program, not a one-time check. Gateways add connectors monthly. People change roles. Free tiers get switched on by someone who needed the work done on a Tuesday. The register is reviewed monthly for the same reason the key is: because the building changes.

Free, no account

The Board AI Register template now carries a gateway row: owner, scope record, identity source, connected systems, review date.

Get the Board AI Register template →
Sources

As of September 30, 2026. Vendors are named as examples of a category; none is a competitor to SanctumShield and none is ranked.

§ Why this is a legal question, not a tooling preference

Everything above is an argument about method. Underneath it sits an obligation that does not depend on which method you pick. Documented, dated, demonstrable governance is what the law asks for, and the dates have stopped being in the future.

EU AI Act Article 4 — AI literacy
In force since February 2, 2025. National enforcement began August 2, 2026.
EU AI Act Article 50 — transparency
Applies since August 2, 2026.
Colorado SB 26-189
Effective January 1, 2027.
EU AI Act Articles 12, 14 and 17 — record-keeping, human oversight, quality management
High-risk regime: December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

Read those together and the shape is consistent. Each one asks an organization to produce something — a measure taken, a disclosure made, a record kept, a review performed — and to be able to show it after the fact. None of them names a product, a platform or a link, and nothing here should be read as saying a law requires one. What a law requires is the record. Making that record dated and third-party-verifiable is simply how you let an auditor, an underwriter or a board confirm it without being handed the contents, or being asked to take your word for it.

And literacy is not one obligation among several. It is the one the others rest on. You cannot exercise due diligence over a system you cannot recognise, and you cannot govern an authority you do not understand you have delegated.

That is why Article 4 sits in the opening chapter of the Act, ahead of the risk tiers, and why it applied eighteen months before the high-risk regime does. The duty is to take measures that support the development of AI literacy among the people operating AI on the organization’s behalf — and the useful version of that is matched to the seat. What a director needs to recognise is not what a developer needs to recognise, and neither is what the person pasting a contract into a browser tab needs to recognise. A single org-wide module satisfies the form and misses the point.

Continue exploring on SanctumShield

The full library — 290 pages of CISO-grade content.

SanctumShield maintains the deepest publicly-available reference set for mid-market agentic-AI governance — primary-source cited, continuously refreshed. Related deep-dives on this article’s topic:

The Master Key Nobody Wrote Down — SanctumShield