The break is at the tool boundary, not in the model text. Once an AI agent can act on a user’s behalf, a poisoned tool description can steer it into making real email, calendar, document, or business-system changes that look authorized but are not.
Microsoft Incident Response now frames MCP tool poisoning as a live attack pattern in read-write enterprise agents, not a prompt-abuse issue for passive summarizers. The guidance is aimed at Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry agents, and the Microsoft Defender controls around them, where a trusted connector can be the thing that turns an agent into a data-loss path.
That shifts the defender’s problem from filtering bad prompts to governing tool descriptions, connectors, and agent permissions. If the agent can act, the trust placed in its tools becomes the trust boundary that an attacker tries to subvert.
AI-Native vs. AI-Washed: How to Evaluate AppSec Tooling
Not every AI-native security tool is what it claims to be. Use these five vendor interview questions to cut through the hype and find tools that actually rebuilt something.
Identity: The operational control plane for agentic AI
As concerns grow that autonomous AI could outpace traditional security, organizations must move past static credentials toward a dynamic, lifecycle approach to agentic identity.