White Paper | Connecting AI to Enterprise Data

White Paper | Connecting AI to Enterprise Data

Your employees are connecting AI to enterprise data through MCP servers. Learn the six risks that follow and what it takes to make those connections safe.

White Paper | Connecting AI to Enterprise Data

Connecting AI to Enterprise Data

What changes the moment you plug it in,

the risks that follow, and what it takes to do it safely.

A I S E C U R I T Y R I S K G U I D E · O C T O B E R 2 0 2 6

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 02

EXECUTIVE SUMMARY

The business wants AI on top of the data. Your people have already connected it.

Employees are connecting AI assistants to company data on their own, and this guide explains what

changes when they do, which risks follow, and what it takes to let it happen safely. The connection

itself takes a few lines of configuration in the assistant’s settings. From then on the assistant reads

and writes the shared drive, the ticketing system or the database with the employee’s full

permissions, even though no ticket was filed and nothing crossed the network in a form most

security tools would recognize.

Connecting AI to enterprise data used to be an integration project run by IT. Today it happens on

laptops, through the Model Context Protocol (MCP) servers and connectors that ship with Claude,

ChatGPT, Copilot, Cursor and similar tools. The business has good reason to want it, since an

assistant that can see the data does far more useful work, so for a security leader the real task is to

make it safe rather than to stop it.

When the connection is made, three things change at once. The data path changes, because a tool

now reads at machine speed where a person used to paste a paragraph. The person who configures

the connection changes, from IT to the individual employee. And the direction of trust changes,

because instructions now flow back in through the content the model reads while data flows out to

it. The risks in chapter 2 and the requirements in chapter 4 all follow from these three changes.

86%

of MCP servers run on local

machines, not in production

environments

75%

of organizations already have

Claude Code in use

47%

of security leaders can identify all

the agents in their environment

Sources: Practical DevSecOps, 20261 · ITBrief, July 20262 · Okta Global CISO Insights 20263

WHO THIS GUIDE IS FOR

The CIO or CISO who owns employee AI usage and is being asked to let AI assistants

work on top of company data.

The risks, requirements, framework mapping and checklist stand on their own, whether or not you

ever buy anything. Check Point enters on the last page only.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 03

01 The Moment of Connection

This guide follows one ordinary case. In the last week of the quarter a finance analyst is preparing

the board pack, and the numbers live in three places: the finance shared drive, the ticketing system

where business units answer questions, and a reporting database. The analyst already uses a

desktop AI assistant, and connecting it to those three systems takes ten minutes and a configuration

file. From then on the assistant can read every file the analyst can read, open and update tickets,

and run queries against the database, at machine speed and without asking twice.

None of this is unusual or malicious. It is exactly the kind of productive AI use most organizations

want to encourage, and it is also the point at which the security picture changes in three ways at

once.

Desktop AI assistant

the analyst’s laptop

MCP servers and connectors

one configuration file

Shared drive

Ticketing system

Reporting database

1 Reads and writes at machine speed, with the user’s full permissions.

2 Configured by the employee in one local file. IT never sees a request.

3 Instructions travel back the same way, inside tool descriptions and documents.

One connection, three changes. The assistant reaches the data with the analyst’s permissions and can write as well

as read (1). The connection is configured on the laptop rather than by IT (2). Instructions travel back along the same

path, inside tool descriptions and the documents the assistant reads (3).

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 04

What changes, in three parts

01 The data path changes

Before the connection, data reached the model one paste at a time, chosen by a person

who could see what they were sharing. After it, a tool reads at machine speed, with the

connecting user’s full permissions, across every file and record that user can reach. Many

of these tools can also write: update a ticket, send a message, change a row. The exposure

moves from what someone chose to share to everything the account can touch.

02 Who configures the connection changes

MCP servers and connectors are set up by the people who use them, in a local

configuration file or in the settings of a SaaS AI workspace. Roughly 86 percent of MCP

servers run on local machines1. Because nobody asks IT, there is no request to approve or

record, and no inventory of what is connected to what exists anywhere. Analysts have

started to name this surface: Gartner’s August 2026 Market Overview for AI Usage Control

flags local agents that use MCP servers as a workspace attack surface that proxies and

browser extensions alone cannot cover4.

03 The direction of trust changes

Data flows out to the model, and that is the risk most teams plan for. Instructions also flow

in, which is easier to miss. A tool’s description, a retrieved document, a ticket comment

and a web page are all text the model reads, and the model may treat any of it as an

instruction. Connecting an assistant to a data source therefore connects it to everyone who

can write into that source.

THE PREMISE

The three changes also give you a quick test for any control, existing or proposed:

ask which of them it addresses. A control that addresses none of them may still be

useful, but it is solving a different problem.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 05

02 The Risks, Named

Six risks follow from the three changes. Each is described in plain language and then shown

through the analyst’s board pack, because most of them come from ordinary use rather than from

an attack.

Over-reach

The assistant reads with the user’s full permissions, far beyond what the task needs. A

question about one cost center can pull every file the analyst has ever been granted into the

model’s context, including the folders nobody remembered they could open.

I N T H E S C E N A R I O

Asked for the quarter’s travel spend, the assistant scans the whole finance drive, including a

folder of unreleased restructuring plans, and summarizes it into the draft.

Exfiltration through tools

Any tool that can write or reach outside becomes an exit. Data that came in through one

connection can leave through another: a ticket comment, an email, an API call, a public

repository. Each step on its own is an authorized action, and only the combination amounts to a

breach.

I N T H E S C E N A R I O

A planted document asks the assistant to “file a summary of the attached figures” in a ticket

that is visible to an external contractor. The assistant complies, and nothing in the log looks

wrong.

Unsanctioned connections

This covers servers nobody reviewed, look-alike packages and connections set up months ago

and never removed. Public registries hold thousands of MCP servers, most never scanned, with

look-alikes published under names one character away from the official one1. In cloud

environments, 38 percent of MCP servers found had no authentication at all5. OWASP now lists

Shadow MCP Servers in its MCP Top 106.

I N T H E S C E N A R I O

The database server the analyst installed came from a blog post. It works, but nobody knows

who maintains it, what else it does, or that it will still be configured after the board pack ships.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 06

Tool poisoning and indirect prompt injection

The model reads tool descriptions and retrieved content as text, and text can carry instructions.

A modified tool description or a planted paragraph in a document can redirect an assistant

while every individual action stays within its permissions. Microsoft’s 2026 disclosure of tool-

description poisoning described exactly this: exfiltration in which every step was technically

authorized7.

I N T H E S C E N A R I O

A vendor invoice in the shared drive contains a paragraph in white text on a white background.

The assistant reads it, and quietly attaches the pricing sheet to its next ticket update.

Credential sprawl

MCP configuration files hold the credentials for every connection, such as API tokens, database

connection strings and OAuth secrets, often in plain text and often synced to a cloud drive or

committed to a repository. One count found more than 24,000 secrets in MCP configuration files

on public GitHub1.

I N T H E S C E N A R I O

The analyst’s database connection string sits in a JSON file in the home folder, next to a

personal backup that syncs to a consumer cloud account.

Personal-account leakage

Here the tool is approved but the account is not. The same assistant, signed into a personal

account, sends company data to a workspace the company does not control and cannot audit,

with no agreed terms on training or retention.

I N T H E S C E N A R I O

Working late from home, the analyst signs into the assistant with a personal login. The

connections still work, and the conversation history now lives outside the company.

Three of these six need no attacker.

Over-reach, unsanctioned connections and personal-account leakage happen through ordinary,

well-intentioned use. Controls built to recognize malicious traffic miss them, because none of the

traffic involved is malicious.

M A P P E D T O R E C O G N I Z E D F R A M E W O R K S

Chapter 5 maps each of these six risks to the requirement that addresses it and to the matching entries in the

OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, the OWASP MCP Top 10 and MITRE

ATLAS.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 07

03 Why Guardrails Are Not Enough

Two objections come up whenever this topic does. One is that model vendors invest heavily in safety,

so the models should be safe out of the box. The other is that the stack already has data loss

prevention, identity, a web gateway and a firewall. Both are partly right, and both miss the same

thing: the connection itself.

Model safety governs what the model will say and what it refuses. It does not govern what your

employee connected it to, which account they used, or what a planted document asked it to do with

data it was allowed to read, which is why a safe model on an unsafe connection still makes an

unsafe system.

What each layer sees, and what it misses L AY E R S E E S M I S S E S

Model vendor safety Harmful requests, jailbreak

attempts, content-policy

violations.

Which data was connected, by whom, and

whether an instruction came from the user or

from a document the model read.

Data loss prevention Sensitive patterns in email,

uploads and browser sessions.

Data moving inside a local MCP session on the

laptop, or between two SaaS services through a

connector. Neither looks like an upload.

Identity and single

sign-on

Who signed in, and with which

account.

What the signed-in assistant does next with the

permissions it inherited. The July 2026 MCP

specification made OAuth 2.1 mandatory8; that

settles sign-on, not scope.

Web gateway and

CASB

Traffic to known AI services,

sanctioned or not.

MCP servers that run locally and never produce

network traffic, and tool calls carried inside an

approved application’s own session.

Network firewall Connections between hosts. The meaning of a tool call: whether it reads or

writes, what it carries, and whether the content

is an instruction.

THE TWO BLIND SPOTS

Local servers never touch the network, and connections made inside a SaaS AI

workspace never cross the endpoint. Any answer has to cover both, and the existing

stack was not built to see either.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 08

04 What It Takes

This chapter sets out five requirements in the order a security team can deliver them: see the

connections, decide which are allowed, constrain what they can do, inspect what passes through

them, and prove it afterwards. Together they form one layer between the assistant and the data.

Each is written the way a buyer might put it in a requirements document, with a question for your

own team beneath it.

01 See every connection

Keep an inventory of every MCP server and connector in use, showing which AI client it is

attached to, which tools it exposes, which users have it, how often it is called, and where it

came from. Build it from the configuration on the endpoint and from the AI services

themselves, because network traffic alone will never show a local server.

A S K Y O U R T E A M

How many MCP servers are configured on our laptops today, and who could answer that within

the hour?

02 Decide which connections are allowed

Set an allow list by server, tool, user group and AI client, with a request-and-approve path for

new servers that is faster than working around it. Check where a server came from before it is

trusted, and make sure a connection that should not be there can be removed.

A S K Y O U R T E A M

If an employee wanted to connect an assistant to the finance drive tomorrow, what would they do,

and would we know?

03 Constrain what each connection can do

Separate read from write and narrow each tool’s scope to the task. Redact sensitive values in

flight instead of blocking the whole connection. Add a managed-account condition, so that an

approved tool on a personal account is treated differently from the same tool on a company

account.

A S K Y O U R T E A M

Can we let an assistant read the database while denying it the ability to change a row?

D I S C O V E R

G O V E R N

G O V E R N

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 09

04 Inspect both directions

Examine tool definitions before the assistant sees them. Examine each tool call on the way

out, meaning the arguments and the data it carries, and on the way back, meaning the result

and any instruction hidden inside it. Decide to allow, block or ask before the action completes,

with the option to observe first and enforce later.

A S K Y O U R T E A M

If a document told the assistant to send data somewhere, what would stop it?

05 Prove it afterwards

Keep one record per tool definition and per tool call, showing who, which server, which tool,

what was decided and why, and make it exportable to the SIEM. This is the evidence a board,

an auditor or an incident responder will ask for, and the only way to know the other four

requirements are working.

A S K Y O U R T E A M

Could we reconstruct what an assistant did with company data last Tuesday?

One control point for all five.

All five requirements sit where an assistant meets the data, which is why, delivered together, they

answer the second objection from chapter 3. That takes one control point where connections are

made, on the endpoint and inside the AI services people already use, with one policy and one

record across both.

P R O T E C T

P R O T E C T

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 10

05 The Mapping

Security leaders are asked to show that a new risk maps to controls, and to the frameworks the

board and the auditors already recognize. This table connects each of the six risks to the

requirement that addresses it, and to the corresponding entries in three OWASP lists, the Top 10 for

LLM Applications 20269, the Top 10 for Agentic Applications 202610 and the MCP Top 106, and in

MITRE ATLAS11.

R I S K R E Q U I R E M E N T

O W A S P T O P 1 0 L I S T S · L L M ( 2 0 2 6 ) , A G E N T I C

( 2 0 2 6 ) , M C P ( 2 0 2 5 ) M I T R E AT L A S

Over-reach See (01), Constrain

(03)

LLM03 Excessive Agency

ASI03 Identity and Privilege Abuse

MCP02 Privilege Escalation via Scope Creep

AML.T0057 LLM Data

Leakage

Exfiltration

through tools

Inspect (04),

Constrain (03)

LLM03 Excessive Agency

ASI02 Tool Misuse

MCP06 Intent Flow Subversion

AML.T0086 Exfiltration via

AI Agent Tool Invocation

Unsanctioned

connections

See (01), Decide

(02)

LLM04 Supply Chain

ASI04 Agentic Supply Chain Vulnerabilities

MCP09 Shadow MCP Servers

MCP04 Software Supply Chain Attacks

AML.T0010 AI Supply

Chain Compromise

Tool poisoning and

indirect injection

Inspect (04) LLM01 Prompt Injection

LLM08 Hidden Context Exposure

ASI01 Agent Goal Hijack

MCP03 Tool Poisoning

MCP10 Context Injection and Over-Sharing

AML.T0051.001 Indirect

Prompt Injection

AML.T0110 AI Agent Tool

Poisoning

Credential sprawl See (01), Constrain

(03)

LLM02 Sensitive Information Disclosure

ASI03 Identity and Privilege Abuse

MCP01 Token Mismanagement and Secret

Exposure

AML.T0055 Unsecured

Credentials

Personal-account

leakage

Decide (02),

Constrain (03),

Prove (05)

LLM02 Sensitive Information Disclosure

ASI03 Identity and Privilege Abuse

MCP07 Insufficient Authentication and

Authorization

AML.T0057 LLM Data

Leakage

Framework entries as published in the current editions of the three OWASP lists and the ATLAS matrix. The requirement numbers refer to

chapter 4. Requirement 05, Prove it afterwards, answers MCP08 Lack of Audit and Telemetry across every row.

How to use it. The table is built to go to the board as one page. The two left-hand columns are what

you act on, and the two right-hand columns are the vocabulary auditors and regulators will use

when they ask whether you did.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 11

06 The Checklist

The ten questions lift straight into a requirements document or an RFP. Answer them for your own

environment first; each points to the chapter 4 requirement that closes the gap.

Q U E S T I O N Ye s P a r t ly N o t y e t

01 Can we list every MCP server and connector configured on

employee devices and inside our AI workspaces? R E Q 0 1

02 Do we know which tools each connection exposes, and

whether each one reads or writes? R E Q 0 1

03 Do we know who uses each connection, how often it is

called, and where the server came from? R E Q 0 1

04 Is there an approved path to request a new connection, and

is it faster than the workaround? R E Q 0 2

05 Can we remove a connection that should not be there, on

every device that has it? R E Q 0 2

06 Can we let a connection read a system while denying write,

delete and execute? R E Q 0 3

07 Can sensitive values be redacted inside a tool call without

blocking the whole connection? R E Q 0 3

08 Are tool descriptions and tool results inspected for

instructions before the assistant acts on them? R E Q 0 4

09 Can an unsafe tool call be stopped before it completes, with

the option to ask a human first? R E Q 0 4

10 Can we reconstruct, per tool call, what an assistant did

with company data and why it was allowed? R E Q 0 5

Y O U R R E S U LT

Ten yes answers mean the three changes from

chapter 1 are seen, governed and provable.

Every Partly or Not yet points to the

requirement in the REQ column to start with.

U S I N G I T W I T H A V E N D O R

Replace “Can we” with “The solution must” and

each question becomes a requirement. Ask for a

demonstration of questions 06 to 10.

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 12

NEXT STEPS

Where to go from here.

In most organizations, employees connected AI to company data before anyone wrote a policy for it,

so the choice now is whether those connections become visible, governed and provable. The five

requirements in chapter 4 do that without slowing the business down. Start with the checklist, take

the mapping to the board, and use the pieces below to go deeper on each surface.

W H E R E T H I S G U I D E F I T S

The AI Exposure Ten, a five-minute self-check across all employee AI use · Protecting Intelligence, the enterprise

guide to AI security as a whole · Shadow AI Is Already in Your Workforce, on the unsanctioned tools these

connections often run inside.

How Check Point helps

Check Point AI Security secures how employees use AI, including the connections they make

between assistants and company data. On the endpoint, it discovers the MCP servers your people

have configured, governs which servers, tools and operations each assistant may use, inspects each

tool call in both directions before it completes, and records every decision. Inside the AI services

already in use, it shows which connectors are active and what data moves through them. It also

secures the AI applications and agents your own teams build.

L E A R N M O R E

To learn how Check Point secures the connections

between AI and enterprise data, contact your Check

Point account team.

checkpoint.com/ai-security

https://www.checkpoint.com/resources/items/checklist-the-ai-exposure-ten https://www.checkpoint.com/resources/items/white-paper-protecting-intelligence https://www.checkpoint.com/resources/items/white-paper-shadow-ai-is-already-in-your-workforce https://www.checkpoint.com/ai-security/ https://www.checkpoint.com/ai-security/

C O N N E C T I N G A I T O E N T E R P R I S E D ATA 13

References.

1 Practical DevSecOps, MCP Security Statistics 2026 (local MCP servers, registry look-alikes and secrets

in MCP configuration files), 2026.

https://www.practical-devsecops.com/mcp-security-statistics-2026-report/

2 ITBrief, coverage of 2026 enterprise AI usage data (Claude Code in use at 75 percent of organizations),

29 July 2026.

https://itbrief.asia/story/netskope-says-downstream-ai-data-breaches-are-surging

3 Okta, Global CISO Insights 2026, 29 July 2026.

https://www.okta.com/newsroom/articles/global-ciso-insights-2026/

4 Gartner, Market Overview for AI Usage Control, 20 August 2026 (subscription).

https://www.gartner.com/

5 Wiz, State of AI in the Cloud 2026, April 2026.

https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026

6 OWASP, MCP Top 10 (2025), including MCP09 Shadow MCP Servers.

https://owasp.org/www-project-mcp-top-10/

7 Cloud Security Alliance, Research note on Microsoft’s MCP tool-description poisoning disclosure, 11

July 2026.

https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-tool-description-poisoning-20260711-cs/

8 Model Context Protocol, Specification 2026-07-28 (authorization based on OAuth 2.1).

https://modelcontextprotocol.io/specification/2026-07-28

9 OWASP GenAI Security Project, Top 10 for LLM Applications 2026.

https://genai.owasp.org/llm-top-10/

10 OWASP GenAI Security Project, Top 10 for Agentic Applications 2026.

https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

11 MITRE, ATLAS: Adversarial Threat Landscape for AI Systems.

https://atlas.mitre.org/

https://www.practical-devsecops.com/mcp-security-statistics-2026-report/ https://itbrief.asia/story/netskope-says-downstream-ai-data-breaches-are-surging https://www.okta.com/newsroom/articles/global-ciso-insights-2026/ https://www.gartner.com/ https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026 https://owasp.org/www-project-mcp-top-10/ https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-tool-description-poisoning-20260711-cs/ https://modelcontextprotocol.io/specification/2026-07-28 https://genai.owasp.org/llm-top-10/ https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ https://atlas.mitre.org/

W O R L D W I D E H E A D Q U A R T E R S

Check Point Software Technologies Ltd.

5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel

Tel: 972-3-753-4555

U . S . H E A D Q U A R T E R S

Check Point Software Technologies, Inc.

100 Oracle Parkway, Suite 800, Redwood City, CA 94065

Tel: 1-800-429-4391

www.checkpoint.com

© 2026 Check Point Software Technologies Ltd. All

rights reserved. Check Point and the Check Point logo are trademarks of Check Point Software Technologies Ltd.

connecting_ai: question_01: yes: Off partly: Off not_yet: Off

question_02: yes: Off partly: Off not_yet: Off

question_03: yes: Off partly: Off not_yet: Off

question_04: yes: Off partly: Off not_yet: Off

question_05: yes: Off partly: Off not_yet: Off

question_06: yes: Off partly: Off not_yet: Off

question_07: yes: Off partly: Off not_yet: Off

question_08: yes: Off partly: Off not_yet: Off

question_09: yes: Off partly: Off not_yet: Off

question_10: yes: Off partly: Off not_yet: Off


Item Type: pdf