Two communications-compliance vendors made closely related strategic moves on the same day. Smarsh launched a Model Context Protocol server alongside AskSmarsh AI and expanded agentic capabilities. Shield announced general availability of its own MCP server for governed access to surveillance data and insights.

The coincidence matters more than either announcement in isolation. MCP is an open protocol that is rapidly emerging as a common interface through which AI assistants and agents reach enterprise tools and data. In regulated industries, that creates a difficult problem: how do you give an agent access to communications archives, investigations and surveillance intelligence without creating a new governance bypass?

Smarsh says its architecture retains role-based access, audit logging and chain-of-custody controls. Shield says its MCP server provides governed access to live surveillance data from MCP-enabled AI tools. Shield describes itself as the first communications-risk platform to do this; that “first” claim is Shield’s own and has not been independently established by AI360.

Both vendors are effectively arguing that AI access should inherit controls comparable to those applied to human users - permissions, auditability, policy enforcement and evidentiary integrity. That is significant for banks and insurers because communications archives contain some of the most sensitive information in the organisation.

The emerging design principle is to bring AI to governed data rather than export governed data into uncontrolled AI environments. If more compliance vendors follow, MCP could become part of the regulated-enterprise control plane.


Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.
Share this post
The link has been copied!