
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Enterprises rapidly adopting AI agents via Model Context Protocol (MCP) face significant security risks. These autonomous agents, with high-level access to sensitive systems, outpace existing security controls, creating vulnerabilities such as indirect prompt injection, potential data breaches, and operational disruptions. No actual incident reported, but credible hazards exist.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system component—the Model Context Protocol used by AI assistants to connect to external tools—and details how its exploitation leads to direct harm by enabling attackers to intercept and manipulate AI interactions. The described attack can cause violations of data privacy, unauthorized control over AI-driven processes, and harm to enterprise operations, fitting the definition of an AI Incident. The vulnerability has been demonstrated and is not merely a theoretical risk, indicating realized or ongoing harm potential. Therefore, this event qualifies as an AI Incident rather than a hazard or complementary information.[AI generated]