News•Feb 16, 2026
AWS Security Digest #248 - MCPs Denied
AWS introduced new IAM condition keys that specifically target requests routed through Managed Control Plane (MCP) servers, allowing administrators to deny actions taken via that path. The feature is designed to mitigate risks posed by AI agents that programmatically call AWS APIs, marking the first IAM primitive aimed at controlling AI‑driven access. While it does not block direct SDK calls such as boto3, it offers a policy‑level lever to restrict AI‑generated traffic. The addition reflects AWS’s response to the emerging “AI agents calling AWS APIs” threat vector.