Securing MCP and AI agents with hardware-signed approvals
Prompt-level safeguards are not a security boundary. Infrastructure-level enforcement means the service performing the action structurally cannot execute a dangerous tool call without a human signature over the exact parameters.
The Model Context Protocol has become the common way to connect LLM applications to external tools and databases. Giving autonomous agents access to execution tools introduces a category of operational risk that most teams are still handling with prose.
- Prompt injection can steer a model into executing commands its operator never intended.
- Hallucination can drop tables or overwrite production code with complete confidence.
- Unsupervised agents leave no accountable record of who decided anything.
Why prompt rules are not a control
Most teams start with prompt engineering: "Please ask the user for permission before deleting files." This is a request, not a constraint. It lives in the same channel as the attack, it is subject to the same context-window pressure as everything else, and it fails silently — you find out it did not hold by discovering the consequence.
Real security requires that the service performing the action structurally lack the capability to execute a high-risk tool call without a cryptographic signature from a human — and that the agent hold no other route to it. Not that the agent be instructed not to. That it cannot.
The execution flow
AI Agent INTYGA Gateway Browser tab Authenticator
(MCP client) policy check approval UI Touch ID / YubiKey
| | | |
|-- tool call ------>| | |
| |-- challenge ------>| |
| | |-- WebAuthn ------->|
| |<---------------- signature -------------|
|<-- receipt --------| | |
| | | |
your service verifies the receipt offline, then executes once- Policy evaluation. Read-only tool calls — get_weather, search_docs — execute immediately. Interrupting those is how you train people to stop reading prompts.
- Out-of-band challenge. High-risk calls such as execute_sql_mutation or transfer_funds trigger a WebAuthn challenge bound to the exact tool arguments.
- Biometric sign-off. The human touches Touch ID or a YubiKey in their browser. Nothing to install.
- Verified execution. The receipt is checked against the parameters about to be executed, then the tool call completes exactly once.
What this means for the EU AI Act
Article 14 requires effective human oversight of high-risk AI systems, and in practice the ability to demonstrate that oversight to a regulator.
Be precise about what the regulation does and does not say. It does not prescribe cryptography, and no vendor can sell you Article 14 conformity. What it does is put the evidentiary burden on you. When the question is whether a human meaningfully authorized this specific action, a signature bound to the exact tool call and its parameters is a materially stronger answer than a row in a database you administer.
Anyone offering you instant compliance is selling you a problem you will discover during an audit.