NSA Warns AI Model Context Protocol Lacks Security
The National Security Agency warns that the rapid adoption of the Model Context Protocol for AI agents has outpaced the development of necessary security models.
The National Security Agency issued a report in May 2026 titled “Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation,” urging organizations to adopt security-by-design principles for AI deployments. The agency warns that the rapid proliferation of the Model Context Protocol, a communication standard for agentic AI, has outpaced the development of its security model.
The report identifies several critical risks, including dynamic tool-calling and implicit trust relationships. It specifically highlights an inverted architecture where MCP servers execute actions on behalf of a client, which creates new attack paths. These vulnerabilities are further complicated by the probabilistic nature of Large Language Models, which can cause hallucinations and propagate errors across integrated systems.
To mitigate these threats, the agency recommends implementing real-time monitoring, enhanced audit logs, and targeted training for developers. The guidance emphasizes that overarching governance is required to ensure AI agents operate within secure guardrails.