Session

License and SBOM Gaps in AI Agent Tooling

As AI agents increasingly rely on the Model Context Protocol (MCP) to connect with tools and data sources, developers are pulling in third-party MCP servers at a rapid pace, many built by small teams with inconsistent licensing practices and little to no SBOM coverage. This creates a compliance blind spot that most organizations haven't caught up to yet: unclear license terms on community-built MCP servers, missing dependency manifests, and unvetted code running with elevated permissions inside agent workflows. In this talk, I'll walk through what this risk actually looks like in practice and share concrete steps teams can take today: auditing licenses properly, generating SBOMs for MCP servers, and putting basic governance checkpoints in place. The goal is simple: bring the same supply chain discipline we already apply to traditional open-source dependencies to this fast-moving new layer of AI tooling.

Sanika Kotgire

AI & Data Engineer @ ZS | AWS Community Builder | Author | Public Speaker

Pune, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top