{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-020.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-020",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-020.json",
    "title": "MCP authorisation (spec 2026-07-28)",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Where a remote MCP server uses authorisation, discovery uses protected-resource metadata, token requests carry the resource parameter, the audience is validated and no token is passed through, the issuer is validated, and scopes are stepped up instead of granted as omnibus ones; the MCP version each server speaks is recorded.",
    "failureModes": [
      "ASI03: Delegated identities, inherited privileges and cached credentials let an agent (or whoever steers it) act with rights the requesting user never had."
    ],
    "scope": "Agents that call remote MCP servers over HTTP where the server uses authorisation.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Token requests naming the resource; audience-check alerts; MCP version in the registry",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "agent-identity-scoped-credentials",
        "title": "Agent Identity & Scoped Credentials",
        "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
      }
    ],
    "seeds": [
      {
        "id": "mcp-authorization",
        "title": "MCP authorisation (spec 2026-07-28)",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        },
        {
          "id": "AIGE-OBL-CSA-AICM-AGENTIC",
          "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
        },
        {
          "id": "AIGE-OBL-NIST-AGENTS",
          "name": "NIST AI Agent Standards Initiative (2026)",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "asi03",
          "externalId": "ASI03",
          "name": "Identity and Privilege Abuse",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
        }
      ],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 21,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"MCP authorization as of 2026-07-28\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "Prefer Client ID Metadata Documents to Dynamic Client Registration, which the 2026-07-28 specification deprecates, and keep the allowed client domains as policy.",
      "MCP secures the hop between one client and one server; which agent sits behind the client, and for whom, is the workload identity's job."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
