
Ten keys, or one.
For two years the conversation about AI and your data was about individual connectors. One assistant, one system, one key. Someone connected the chatbot to the CRM. Someone else pointed a coding assistant at a database. Each key could be found, named and taken back.
A newer class of product changes the shape of the problem. It hands the AI assistant one key that opens everything: the CRM, the ERP, the HR system, finance, the warehouse, and the on-premises database that still runs the business. Products like Zapier MCP, Composio, CData Connect AI and Workato Enterprise MCP do this well. They do it because customers asked for it. An assistant that can reach one system at a time is a demo. An assistant that can reach all of them is a colleague. This is a useful category solving a real problem.
It is also the single most important object in the building to govern.
Two shapes of the same key.
Some vendors run the key ring for you. They operate the connectors, hold or broker the credentials, and carry your data through their infrastructure. That is the managed connector catalog. Zapier MCP, Composio, CData Connect AI and Workato are examples.
Some vendors hand you the ring and you run it yourself. You operate the gateway and the servers behind it, and the vendor never holds a credential. That is the bring-your-own-server gateway. Docker MCP Gateway, Microsoft MCP Gateway and Kong AI Gateway are examples.
Both are legitimate. Each asks a different question of the company that deploys it. When a vendor holds the key, the question is who governs the vendor and every credential behind it. When you hold the key, the question is who operates it and what policy it enforces. The glossary entry for MCP Gateway sets out both shapes in full.
Three questions.
A master key deserves three questions, and none of them is technical.
Who owns yours? One name, not a team.
Where is it written down what it may open, and whether it may write or only read?
Are the people and agents holding it tied to your identity system, or to a shared password that was copied into a configuration file somewhere?
Those three questions are now a finding SanctumShield raises: the MCP Gateway Governance Gap. If the answers exist, the finding closes. If they do not, the report says so, on a date.
This is not theoretical.
The people who study this closely are saying the same three things: name an owner, scope the access, govern the identity.
Censys counted the internet-reachable ones. Trend Micro read what they exposed: more than 90 percent of the servers it found gave direct read access to the data source, in natural language, to anyone who arrived. Gartner put a forecast on the consequence and named the mechanism. Aaron Lord, Sr. Director Analyst at Gartner, put it this way: “MCP was built for interoperability, ease of use and flexibility first, so security mistakes can manifest without continuous oversight for agentic AI.” His recommendation was a formal security review for MCP use cases, reinforced with authentication and authorization “tailored specifically for AI agents, not inherited from human user roles.”
An owner. A scope. A governed identity. The research and the finding ask the same three questions.
What the law already asks.
None of this waits for a new AI statute. GDPR Article 28 has said since 2018 that a vendor which processes personal data on your behalf is a processor, and that the relationship must be recorded in a contract stating what the processor may do. HIPAA says the same for business associates at 45 CFR §164.308(b). A managed connector catalog that carries your data is that vendor. Outsourcing the work never outsources the obligation.
Boards have their own line. Delaware’s Caremark doctrine, restated in Marchand v. Barnhill in 2019, asks whether the directors made a good-faith effort to put a reporting system in place for a mission-critical risk. A key that reaches every system in the company is difficult to describe as anything else.
The AI-specific duties are already in force too. EU AI Act Article 4 has required measures supporting AI literacy since February 2, 2025. Article 50 transparency has applied since August 2, 2026. Colorado SB 26-189 takes effect January 1, 2027. So the questions a regulator, an underwriter or a director will ask are not new ones. Can you show the contract that names the vendor as your processor? Can you point to the line in the register where the gateway sits? Can you name the person who signed off on what it may open?
The bet you are making by waiting.
Not acting is not neutral. It is a decision to keep a master key in circulation without an inventory of what it opens or a name against who holds it, and to bet the business that nobody will ask. Ignorance is not a defense. The law is clear, and it has been clear for years. The only question a delay answers is who will be the one to find the gap first: you, or the person asking.
What the record looks like.
One register entry for the gateway, with the connected systems recorded as children beneath it. A named owner. A one-page scope of what the agents behind it may and may not do, with a signer. Evidence that the identities flowing through it come from your identity provider, not a shared secret. That is a governance artifact. It is what a board, an underwriter or a regulator will ask to see, and it fits on a page.
How SanctumShield helps, stated plainly.
The audit now asks the question. It names the gateway in the Executive Risk Report as a Tier-1 dependency, flags the gap when any of the three basics is missing, and gives you the dated, third-party-verifiable record. SanctumShield sits above the gateway and is complementary to it. The vendor enforces and logs. You prove you govern. A gateway is a control point. It does not, by itself, constitute governance, and no vendor claims it does.
A program, not a check.
Governance is a continuous program, not a one-time check. Gateways add connectors monthly. People change roles. Free tiers get switched on by someone who needed the work done on a Tuesday. The register is reviewed monthly for the same reason the key is: because the building changes.
The Board AI Register template now carries a gateway row: owner, scope record, identity source, connected systems, review date.
Get the Board AI Register template →- MCP Servers on the Internet — Censys, MCP Servers on the Internet (Mark Ellzey, May 27, 2026). 12,520 Internet-accessible MCP services across 8,758 unique IP addresses as of April 28, 2026, reachable without authentication; over 21,000 in the dataset by May 6.
- Gartner Predicts 25% of All Enterprise GenAI Applications Will Experience At Least Five Minor Security Incidents Per Year By 2028 — Gartner press release, April 9, 2026. Quotes from Aaron Lord, Sr. Director Analyst.
- MCP Security: Network-Exposed Servers Are Backdoors to Your Private Data — Trend Micro Research (Alfredo Oliveira and David Fiser), July 16, 2025. 492 MCP servers found running with no client authentication or traffic encryption, exposing 1,402 tools; about 74% hosted on major cloud providers and more than 90% giving direct read access to the data source.
- GDPR Article 28 — processor obligations and the written contract that governs them
- HIPAA 45 CFR §164.308(b) — business associate contracts and other arrangements
- Marchand v. Barnhill (Del. 2019) — the Caremark line: a board must make a good-faith effort to put a reporting system in place for mission-critical risk
- EU AI Act — Article 4 (AI literacy, in force February 2, 2025), Article 50 (transparency, in force August 2, 2026), Annex III high-risk (December 2, 2027), Annex I embedded high-risk (August 2, 2028), per Regulation (EU) 2026/1744
- Colorado SB 26-189 — effective January 1, 2027
- SanctumShield glossary: MCP Gateway — the two architectures and the questions each one asks
- SanctumShield finding type: MCP Gateway Governance Gap — the three conditions, and what the Executive Risk Report records
As of September 30, 2026. Vendors are named as examples of a category; none is a competitor to SanctumShield and none is ranked.