AI platforms now ship built-in connectors that let tools like Claude and Copilot read your Slack, Notion, and internal databases on command. The National Security Agency just published its first formal security guidance on the protocol behind them. If your team has connectors turned on, here is what changed and what to check before approving the next one.
A year ago, connecting an AI assistant to your company's tools took custom engineering work. That changed fast. Anthropic now offers enterprise-managed authorization for Claude connectors, letting an administrator approve access to services like Asana, Notion, Slack, and Supabase once, then have every employee inherit that access automatically through their identity provider. Microsoft moved in the same direction, adding agentic authoring and connector support to Power Platform in its September 2026 feature update.
Both moves rely on the same open standard: the Model Context Protocol, or MCP. It is the plumbing that lets an AI model ask a tool to fetch a file, run a query, or send a message on a person's behalf. Connectors are the friendly name. MCP is what actually moves the data.
The scale is what makes this a workforce issue and not a niche engineering one. Across the software development kits that developers use to build MCP connectors, adoption is now close to half a billion downloads a month, and the two most widely used kits have each crossed one billion total downloads according to the protocol's own maintainers. That growth curve means the connectors your team uses today were very likely built or approved in the last several months, often faster than internal policy caught up with them.
MCP is an open protocol that standardizes how an AI assistant discovers and calls outside tools, so one connector can work the same way across many AI products instead of being rebuilt for each one. Your team should care because every connector you turn on is a new path for an AI tool to read company data or take an action, and the protocol itself was not built with strong identity or permission checks baked in.
That gap is exactly what pushed the topic from a developer concern to a team-leader concern this year. The people approving connector requests are increasingly the same people managing certifications, onboarding, and daily workflow, not a dedicated security team. Understanding what a connector actually does before clicking approve is now a baseline part of using AI tools responsibly, which is the kind of judgment AI University's AI certification programs are built to develop in working teams.
The NSA's Artificial Intelligence Security Center published a Cybersecurity Information Sheet on MCP in May 2026, and its core finding is that the protocol's adoption has outpaced the safeguards around it. The guidance names three specific gaps organizations should plan around.
First, MCP allows an AI system to decide on its own to invoke a new tool or take a new action, without a required human check at that moment. Second, the protocol moves data between systems with limited screening of what that data contains, which opens the door to hidden instructions buried in a document, email, or web page a connector reads. Third, MCP does not define how a session maps to a verifiable user identity, and role-based access control is optional rather than built in, so a connector can end up granting the same broad access to everyone who uses it.
None of that means connectors are unsafe to use. It means the controls have to come from how your organization configures and reviews them, not from the protocol alone.
The NSA's guidance is written for security teams, but the underlying advice translates directly for any team leader approving AI tools. It recommends treating MCP connectors the way you would treat a new piece of installed software rather than a simple setting toggle, which means checking who maintains it, how often it is updated, and what data it can reach before turning it on. It also recommends filtering what data flows out through a connector and reviewing what a connector's outputs actually contain, since a compromised or poorly built connector can just as easily feed bad instructions into your AI tool as leak data out of it.
The major AI vendors are now building the governance layer the protocol itself lacks. Anthropic's enterprise-managed authorization lets administrators define which roles get which connectors and revoke access instantly through the identity provider, rather than leaving each employee to authorize services individually. Claude Code's admin console goes further, letting organizations deploy and enforce policy settings across every user, including which MCP servers are allowed and what file access they get.
The protocol itself is also catching up. The July 2026 MCP specification update hardened the authorization model, closing a class of vulnerability where a client's credentials could be replayed against the wrong authorization server, and moved the protocol to a stateless design that is easier to secure at enterprise scale. Under the earlier version of the protocol, a connection had to stay open between a client and a server, which made it harder to load balance and monitor traffic in a busy organization. The stateless design lets each request carry its own identity and permissions, so a security team can inspect and route MCP traffic the same way it already handles other web traffic. These are real improvements. They still depend on an administrator choosing to turn them on and use them correctly.
Most people reading this will never configure an identity provider or approve a connector at the organization level, and that is fine. The judgment call still shows up at your level, just in a smaller form: which connector to request, what to tell it to do, and what to flag when something looks off.
Before you ask an AI tool to connect to a new service, ask your administrator whether it is already on the approved list rather than authorizing it yourself with personal credentials. Once a connector is live, pay attention to what the AI tool is doing with it. A connector that is only supposed to read a shared drive should not be drafting emails or making changes in another system, and an unexpected request for a new permission scope is worth reporting rather than approving on the spot. These are small habits, but they are the ones that keep a well-configured system well configured after the rollout is done.
Before approving a new MCP connector for your team, work through these checks:
| Factor | Individual authorization | Admin-managed authorization |
|---|---|---|
| Who approves access | Each employee, on their own | An administrator, once, for the whole team |
| Permission consistency | Varies person to person | Set centrally and applied uniformly |
| Offboarding | Manual, easy to miss | Revoked automatically through the identity provider |
| Visibility | Limited, scattered across accounts | Centralized in the admin console |
Most teams did not choose to become connector administrators. It happened as a side effect of adopting AI tools that got more capable and more connected month over month. That makes it worth checking where your organization actually stands, since many teams have more connectors already approved than anyone realizes. Starting with a structured AI readiness assessment gives you an honest inventory of what is connected, who approved it, and where the gaps are before you add anything new.
This is also a skills gap, not just a policy gap. The people best positioned to evaluate a connector request are the ones who understand both what the AI tool is trying to do and what the underlying data actually contains. Building that judgment across a team, rather than routing every decision to IT, is central to AI University's approach to practical AI adoption, which treats safe use as a skill you build, not a policy you post once and forget.
Connectors are not going away, and neither is the pace at which vendors are adding them. Treat every new one as a small governance decision rather than a convenience toggle, and your team gets the productivity gain without inheriting the risk the NSA just spent seventeen pages describing.
If you want help mapping which AI connectors your team has active and where the governance gaps are, book a strategy call with AI University to walk through it together.