White Paper | Connecting AI to Enterprise Data
Your employees are connecting AI to enterprise data through MCP servers. Learn the six risks that follow and what it takes to make those connections safe.

Connecting AI to Enterprise Data
What changes the moment you plug it in,
the risks that follow, and what it takes to do it safely.
A I S E C U R I T Y R I S K G U I D E · O C T O B E R 2 0 2 6
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 02
EXECUTIVE SUMMARY
The business wants AI on top of the data. Your people have already connected it.
Employees are connecting AI assistants to company data on their own, and this guide explains what
changes when they do, which risks follow, and what it takes to let it happen safely. The connection
itself takes a few lines of configuration in the assistant’s settings. From then on the assistant reads
and writes the shared drive, the ticketing system or the database with the employee’s full
permissions, even though no ticket was filed and nothing crossed the network in a form most
security tools would recognize.
Connecting AI to enterprise data used to be an integration project run by IT. Today it happens on
laptops, through the Model Context Protocol (MCP) servers and connectors that ship with Claude,
ChatGPT, Copilot, Cursor and similar tools. The business has good reason to want it, since an
assistant that can see the data does far more useful work, so for a security leader the real task is to
make it safe rather than to stop it.
When the connection is made, three things change at once. The data path changes, because a tool
now reads at machine speed where a person used to paste a paragraph. The person who configures
the connection changes, from IT to the individual employee. And the direction of trust changes,
because instructions now flow back in through the content the model reads while data flows out to
it. The risks in chapter 2 and the requirements in chapter 4 all follow from these three changes.
86%
of MCP servers run on local
machines, not in production
environments
75%
of organizations already have
Claude Code in use
47%
of security leaders can identify all
the agents in their environment
Sources: Practical DevSecOps, 20261 · ITBrief, July 20262 · Okta Global CISO Insights 20263
WHO THIS GUIDE IS FOR
The CIO or CISO who owns employee AI usage and is being asked to let AI assistants
work on top of company data.
The risks, requirements, framework mapping and checklist stand on their own, whether or not you
ever buy anything. Check Point enters on the last page only.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 03
01 The Moment of Connection
This guide follows one ordinary case. In the last week of the quarter a finance analyst is preparing
the board pack, and the numbers live in three places: the finance shared drive, the ticketing system
where business units answer questions, and a reporting database. The analyst already uses a
desktop AI assistant, and connecting it to those three systems takes ten minutes and a configuration
file. From then on the assistant can read every file the analyst can read, open and update tickets,
and run queries against the database, at machine speed and without asking twice.
None of this is unusual or malicious. It is exactly the kind of productive AI use most organizations
want to encourage, and it is also the point at which the security picture changes in three ways at
once.
Desktop AI assistant
the analyst’s laptop
MCP servers and connectors
one configuration file
Shared drive
Ticketing system
Reporting database
1 Reads and writes at machine speed, with the user’s full permissions.
2 Configured by the employee in one local file. IT never sees a request.
3 Instructions travel back the same way, inside tool descriptions and documents.
One connection, three changes. The assistant reaches the data with the analyst’s permissions and can write as well
as read (1). The connection is configured on the laptop rather than by IT (2). Instructions travel back along the same
path, inside tool descriptions and the documents the assistant reads (3).
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 04
What changes, in three parts
01 The data path changes
Before the connection, data reached the model one paste at a time, chosen by a person
who could see what they were sharing. After it, a tool reads at machine speed, with the
connecting user’s full permissions, across every file and record that user can reach. Many
of these tools can also write: update a ticket, send a message, change a row. The exposure
moves from what someone chose to share to everything the account can touch.
02 Who configures the connection changes
MCP servers and connectors are set up by the people who use them, in a local
configuration file or in the settings of a SaaS AI workspace. Roughly 86 percent of MCP
servers run on local machines1. Because nobody asks IT, there is no request to approve or
record, and no inventory of what is connected to what exists anywhere. Analysts have
started to name this surface: Gartner’s August 2026 Market Overview for AI Usage Control
flags local agents that use MCP servers as a workspace attack surface that proxies and
browser extensions alone cannot cover4.
03 The direction of trust changes
Data flows out to the model, and that is the risk most teams plan for. Instructions also flow
in, which is easier to miss. A tool’s description, a retrieved document, a ticket comment
and a web page are all text the model reads, and the model may treat any of it as an
instruction. Connecting an assistant to a data source therefore connects it to everyone who
can write into that source.
THE PREMISE
The three changes also give you a quick test for any control, existing or proposed:
ask which of them it addresses. A control that addresses none of them may still be
useful, but it is solving a different problem.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 05
02 The Risks, Named
Six risks follow from the three changes. Each is described in plain language and then shown
through the analyst’s board pack, because most of them come from ordinary use rather than from
an attack.
Over-reach
The assistant reads with the user’s full permissions, far beyond what the task needs. A
question about one cost center can pull every file the analyst has ever been granted into the
model’s context, including the folders nobody remembered they could open.
I N T H E S C E N A R I O
Asked for the quarter’s travel spend, the assistant scans the whole finance drive, including a
folder of unreleased restructuring plans, and summarizes it into the draft.
Exfiltration through tools
Any tool that can write or reach outside becomes an exit. Data that came in through one
connection can leave through another: a ticket comment, an email, an API call, a public
repository. Each step on its own is an authorized action, and only the combination amounts to a
breach.
I N T H E S C E N A R I O
A planted document asks the assistant to “file a summary of the attached figures” in a ticket
that is visible to an external contractor. The assistant complies, and nothing in the log looks
wrong.
Unsanctioned connections
This covers servers nobody reviewed, look-alike packages and connections set up months ago
and never removed. Public registries hold thousands of MCP servers, most never scanned, with
look-alikes published under names one character away from the official one1. In cloud
environments, 38 percent of MCP servers found had no authentication at all5. OWASP now lists
Shadow MCP Servers in its MCP Top 106.
I N T H E S C E N A R I O
The database server the analyst installed came from a blog post. It works, but nobody knows
who maintains it, what else it does, or that it will still be configured after the board pack ships.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 06
Tool poisoning and indirect prompt injection
The model reads tool descriptions and retrieved content as text, and text can carry instructions.
A modified tool description or a planted paragraph in a document can redirect an assistant
while every individual action stays within its permissions. Microsoft’s 2026 disclosure of tool-
description poisoning described exactly this: exfiltration in which every step was technically
authorized7.
I N T H E S C E N A R I O
A vendor invoice in the shared drive contains a paragraph in white text on a white background.
The assistant reads it, and quietly attaches the pricing sheet to its next ticket update.
Credential sprawl
MCP configuration files hold the credentials for every connection, such as API tokens, database
connection strings and OAuth secrets, often in plain text and often synced to a cloud drive or
committed to a repository. One count found more than 24,000 secrets in MCP configuration files
on public GitHub1.
I N T H E S C E N A R I O
The analyst’s database connection string sits in a JSON file in the home folder, next to a
personal backup that syncs to a consumer cloud account.
Personal-account leakage
Here the tool is approved but the account is not. The same assistant, signed into a personal
account, sends company data to a workspace the company does not control and cannot audit,
with no agreed terms on training or retention.
I N T H E S C E N A R I O
Working late from home, the analyst signs into the assistant with a personal login. The
connections still work, and the conversation history now lives outside the company.
Three of these six need no attacker.
Over-reach, unsanctioned connections and personal-account leakage happen through ordinary,
well-intentioned use. Controls built to recognize malicious traffic miss them, because none of the
traffic involved is malicious.
M A P P E D T O R E C O G N I Z E D F R A M E W O R K S
Chapter 5 maps each of these six risks to the requirement that addresses it and to the matching entries in the
OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, the OWASP MCP Top 10 and MITRE
ATLAS.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 07
03 Why Guardrails Are Not Enough
Two objections come up whenever this topic does. One is that model vendors invest heavily in safety,
so the models should be safe out of the box. The other is that the stack already has data loss
prevention, identity, a web gateway and a firewall. Both are partly right, and both miss the same
thing: the connection itself.
Model safety governs what the model will say and what it refuses. It does not govern what your
employee connected it to, which account they used, or what a planted document asked it to do with
data it was allowed to read, which is why a safe model on an unsafe connection still makes an
unsafe system.
What each layer sees, and what it misses L AY E R S E E S M I S S E S
Model vendor safety Harmful requests, jailbreak
attempts, content-policy
violations.
Which data was connected, by whom, and
whether an instruction came from the user or
from a document the model read.
Data loss prevention Sensitive patterns in email,
uploads and browser sessions.
Data moving inside a local MCP session on the
laptop, or between two SaaS services through a
connector. Neither looks like an upload.
Identity and single
sign-on
Who signed in, and with which
account.
What the signed-in assistant does next with the
permissions it inherited. The July 2026 MCP
specification made OAuth 2.1 mandatory8; that
settles sign-on, not scope.
Web gateway and
CASB
Traffic to known AI services,
sanctioned or not.
MCP servers that run locally and never produce
network traffic, and tool calls carried inside an
approved application’s own session.
Network firewall Connections between hosts. The meaning of a tool call: whether it reads or
writes, what it carries, and whether the content
is an instruction.
THE TWO BLIND SPOTS
Local servers never touch the network, and connections made inside a SaaS AI
workspace never cross the endpoint. Any answer has to cover both, and the existing
stack was not built to see either.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 08
04 What It Takes
This chapter sets out five requirements in the order a security team can deliver them: see the
connections, decide which are allowed, constrain what they can do, inspect what passes through
them, and prove it afterwards. Together they form one layer between the assistant and the data.
Each is written the way a buyer might put it in a requirements document, with a question for your
own team beneath it.
01 See every connection
Keep an inventory of every MCP server and connector in use, showing which AI client it is
attached to, which tools it exposes, which users have it, how often it is called, and where it
came from. Build it from the configuration on the endpoint and from the AI services
themselves, because network traffic alone will never show a local server.
A S K Y O U R T E A M
How many MCP servers are configured on our laptops today, and who could answer that within
the hour?
02 Decide which connections are allowed
Set an allow list by server, tool, user group and AI client, with a request-and-approve path for
new servers that is faster than working around it. Check where a server came from before it is
trusted, and make sure a connection that should not be there can be removed.
A S K Y O U R T E A M
If an employee wanted to connect an assistant to the finance drive tomorrow, what would they do,
and would we know?
03 Constrain what each connection can do
Separate read from write and narrow each tool’s scope to the task. Redact sensitive values in
flight instead of blocking the whole connection. Add a managed-account condition, so that an
approved tool on a personal account is treated differently from the same tool on a company
account.
A S K Y O U R T E A M
Can we let an assistant read the database while denying it the ability to change a row?
D I S C O V E R
G O V E R N
G O V E R N
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 09
04 Inspect both directions
Examine tool definitions before the assistant sees them. Examine each tool call on the way
out, meaning the arguments and the data it carries, and on the way back, meaning the result
and any instruction hidden inside it. Decide to allow, block or ask before the action completes,
with the option to observe first and enforce later.
A S K Y O U R T E A M
If a document told the assistant to send data somewhere, what would stop it?
05 Prove it afterwards
Keep one record per tool definition and per tool call, showing who, which server, which tool,
what was decided and why, and make it exportable to the SIEM. This is the evidence a board,
an auditor or an incident responder will ask for, and the only way to know the other four
requirements are working.
A S K Y O U R T E A M
Could we reconstruct what an assistant did with company data last Tuesday?
One control point for all five.
All five requirements sit where an assistant meets the data, which is why, delivered together, they
answer the second objection from chapter 3. That takes one control point where connections are
made, on the endpoint and inside the AI services people already use, with one policy and one
record across both.
P R O T E C T
P R O T E C T
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 10
05 The Mapping
Security leaders are asked to show that a new risk maps to controls, and to the frameworks the
board and the auditors already recognize. This table connects each of the six risks to the
requirement that addresses it, and to the corresponding entries in three OWASP lists, the Top 10 for
LLM Applications 20269, the Top 10 for Agentic Applications 202610 and the MCP Top 106, and in
MITRE ATLAS11.
R I S K R E Q U I R E M E N T
O W A S P T O P 1 0 L I S T S · L L M ( 2 0 2 6 ) , A G E N T I C
( 2 0 2 6 ) , M C P ( 2 0 2 5 ) M I T R E AT L A S
Over-reach See (01), Constrain
(03)
LLM03 Excessive Agency
ASI03 Identity and Privilege Abuse
MCP02 Privilege Escalation via Scope Creep
AML.T0057 LLM Data
Leakage
Exfiltration
through tools
Inspect (04),
Constrain (03)
LLM03 Excessive Agency
ASI02 Tool Misuse
MCP06 Intent Flow Subversion
AML.T0086 Exfiltration via
AI Agent Tool Invocation
Unsanctioned
connections
See (01), Decide
(02)
LLM04 Supply Chain
ASI04 Agentic Supply Chain Vulnerabilities
MCP09 Shadow MCP Servers
MCP04 Software Supply Chain Attacks
AML.T0010 AI Supply
Chain Compromise
Tool poisoning and
indirect injection
Inspect (04) LLM01 Prompt Injection
LLM08 Hidden Context Exposure
ASI01 Agent Goal Hijack
MCP03 Tool Poisoning
MCP10 Context Injection and Over-Sharing
AML.T0051.001 Indirect
Prompt Injection
AML.T0110 AI Agent Tool
Poisoning
Credential sprawl See (01), Constrain
(03)
LLM02 Sensitive Information Disclosure
ASI03 Identity and Privilege Abuse
MCP01 Token Mismanagement and Secret
Exposure
AML.T0055 Unsecured
Credentials
Personal-account
leakage
Decide (02),
Constrain (03),
Prove (05)
LLM02 Sensitive Information Disclosure
ASI03 Identity and Privilege Abuse
MCP07 Insufficient Authentication and
Authorization
AML.T0057 LLM Data
Leakage
Framework entries as published in the current editions of the three OWASP lists and the ATLAS matrix. The requirement numbers refer to
chapter 4. Requirement 05, Prove it afterwards, answers MCP08 Lack of Audit and Telemetry across every row.
How to use it. The table is built to go to the board as one page. The two left-hand columns are what
you act on, and the two right-hand columns are the vocabulary auditors and regulators will use
when they ask whether you did.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 11
06 The Checklist
The ten questions lift straight into a requirements document or an RFP. Answer them for your own
environment first; each points to the chapter 4 requirement that closes the gap.
Q U E S T I O N Ye s P a r t ly N o t y e t
01 Can we list every MCP server and connector configured on
employee devices and inside our AI workspaces? R E Q 0 1
02 Do we know which tools each connection exposes, and
whether each one reads or writes? R E Q 0 1
03 Do we know who uses each connection, how often it is
called, and where the server came from? R E Q 0 1
04 Is there an approved path to request a new connection, and
is it faster than the workaround? R E Q 0 2
05 Can we remove a connection that should not be there, on
every device that has it? R E Q 0 2
06 Can we let a connection read a system while denying write,
delete and execute? R E Q 0 3
07 Can sensitive values be redacted inside a tool call without
blocking the whole connection? R E Q 0 3
08 Are tool descriptions and tool results inspected for
instructions before the assistant acts on them? R E Q 0 4
09 Can an unsafe tool call be stopped before it completes, with
the option to ask a human first? R E Q 0 4
10 Can we reconstruct, per tool call, what an assistant did
with company data and why it was allowed? R E Q 0 5
Y O U R R E S U LT
Ten yes answers mean the three changes from
chapter 1 are seen, governed and provable.
Every Partly or Not yet points to the
requirement in the REQ column to start with.
U S I N G I T W I T H A V E N D O R
Replace “Can we” with “The solution must” and
each question becomes a requirement. Ask for a
demonstration of questions 06 to 10.
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 12
NEXT STEPS
Where to go from here.
In most organizations, employees connected AI to company data before anyone wrote a policy for it,
so the choice now is whether those connections become visible, governed and provable. The five
requirements in chapter 4 do that without slowing the business down. Start with the checklist, take
the mapping to the board, and use the pieces below to go deeper on each surface.
W H E R E T H I S G U I D E F I T S
The AI Exposure Ten, a five-minute self-check across all employee AI use · Protecting Intelligence, the enterprise
guide to AI security as a whole · Shadow AI Is Already in Your Workforce, on the unsanctioned tools these
connections often run inside.
How Check Point helps
Check Point AI Security secures how employees use AI, including the connections they make
between assistants and company data. On the endpoint, it discovers the MCP servers your people
have configured, governs which servers, tools and operations each assistant may use, inspects each
tool call in both directions before it completes, and records every decision. Inside the AI services
already in use, it shows which connectors are active and what data moves through them. It also
secures the AI applications and agents your own teams build.
L E A R N M O R E
To learn how Check Point secures the connections
between AI and enterprise data, contact your Check
Point account team.
checkpoint.com/ai-security
https://www.checkpoint.com/resources/items/checklist-the-ai-exposure-ten https://www.checkpoint.com/resources/items/white-paper-protecting-intelligence https://www.checkpoint.com/resources/items/white-paper-shadow-ai-is-already-in-your-workforce https://www.checkpoint.com/ai-security/ https://www.checkpoint.com/ai-security/
C O N N E C T I N G A I T O E N T E R P R I S E D ATA 13
References.
1 Practical DevSecOps, MCP Security Statistics 2026 (local MCP servers, registry look-alikes and secrets
in MCP configuration files), 2026.
https://www.practical-devsecops.com/mcp-security-statistics-2026-report/
2 ITBrief, coverage of 2026 enterprise AI usage data (Claude Code in use at 75 percent of organizations),
29 July 2026.
https://itbrief.asia/story/netskope-says-downstream-ai-data-breaches-are-surging
3 Okta, Global CISO Insights 2026, 29 July 2026.
https://www.okta.com/newsroom/articles/global-ciso-insights-2026/
4 Gartner, Market Overview for AI Usage Control, 20 August 2026 (subscription).
https://www.gartner.com/
5 Wiz, State of AI in the Cloud 2026, April 2026.
https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026
6 OWASP, MCP Top 10 (2025), including MCP09 Shadow MCP Servers.
https://owasp.org/www-project-mcp-top-10/
7 Cloud Security Alliance, Research note on Microsoft’s MCP tool-description poisoning disclosure, 11
July 2026.
https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-tool-description-poisoning-20260711-cs/
8 Model Context Protocol, Specification 2026-07-28 (authorization based on OAuth 2.1).
https://modelcontextprotocol.io/specification/2026-07-28
9 OWASP GenAI Security Project, Top 10 for LLM Applications 2026.
https://genai.owasp.org/llm-top-10/
10 OWASP GenAI Security Project, Top 10 for Agentic Applications 2026.
https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
11 MITRE, ATLAS: Adversarial Threat Landscape for AI Systems.
https://atlas.mitre.org/
https://www.practical-devsecops.com/mcp-security-statistics-2026-report/ https://itbrief.asia/story/netskope-says-downstream-ai-data-breaches-are-surging https://www.okta.com/newsroom/articles/global-ciso-insights-2026/ https://www.gartner.com/ https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026 https://owasp.org/www-project-mcp-top-10/ https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-tool-description-poisoning-20260711-cs/ https://modelcontextprotocol.io/specification/2026-07-28 https://genai.owasp.org/llm-top-10/ https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ https://atlas.mitre.org/
W O R L D W I D E H E A D Q U A R T E R S
Check Point Software Technologies Ltd.
5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel
Tel: 972-3-753-4555
U . S . H E A D Q U A R T E R S
Check Point Software Technologies, Inc.
100 Oracle Parkway, Suite 800, Redwood City, CA 94065
Tel: 1-800-429-4391
www.checkpoint.com
© 2026 Check Point Software Technologies Ltd. All
rights reserved. Check Point and the Check Point logo are trademarks of Check Point Software Technologies Ltd.
connecting_ai: question_01: yes: Off partly: Off not_yet: Off
question_02: yes: Off partly: Off not_yet: Off
question_03: yes: Off partly: Off not_yet: Off
question_04: yes: Off partly: Off not_yet: Off
question_05: yes: Off partly: Off not_yet: Off
question_06: yes: Off partly: Off not_yet: Off
question_07: yes: Off partly: Off not_yet: Off
question_08: yes: Off partly: Off not_yet: Off
question_09: yes: Off partly: Off not_yet: Off
question_10: yes: Off partly: Off not_yet: Off