UPDATED 09:00 EDT / SEPTEMBER 24 2025

AI

Apiiro expands AI Bill of Materials to govern agents and MCP servers

Application security posture management company Apiiro Ltd. today announced a new update that aims to help enterprises get ahead of the growing risks tied to artificial intelligence adoption by expanding its AI Bill of Materials with AI agent and Model Context Protocol server detection capabilities.

Apiiro first introduced what it calls its visibility-first approach in 2023 with Deep Code Analysis that is designed to uncover generative AI frameworks in codebases. The visibility gave security leaders a baseline for understanding what AI technologies were being introduced and the risks they carried.

Forward to 2025 and the pace of adoption has shifted from experimentation to production deployment, with developers embedding AI models, deploying MCP servers and building AI agents. The result is a new set of challenges for chief information security officers and application security teams, ranging from insecure inputs and outputs to secrets exposure and data leakage.

The new expansion is embedding AI directly into the broader software architecture graph by continuously inventorying AI-specific resources, including agents, frameworks, datasets, artifacts and secrets, contextualizing them alongside application programming interfaces, containers, open source and sensitive data.

The update turns what might look like small, isolated findings into meaningful risk insights. For example, the use of a Hugging Face Python client might seem minor on its own, but when mapped in the graph to a sensitive API and code vulnerabilities, the risk score changes dramatically. The idea is that by normalizing and enriching these issues with runtime and business context, security teams can cut through noise and focus on what truly matters.

Apiiro is also tying AI resources to business services and accountable owners through integrations with configuration management databases such as ServiceNow Inc. That allows security leaders to see where AI lives in the codebase and also who is responsible for governing it.

Developers receive risks contextualized in pull requests with remediation guidance, reducing the friction of separate AI-specific alerts.

The company argues that treating AI as part of the software graph provides a multidimensional view of risk, enabling governance policies that are both enforceable and developer-friendly. For AppSec teams and executives, the approach avoids siloed visibility and supports compliance, threat modeling and policy enforcement across the entire software ecosystem.

“The history of security tells us the same story again and again: cloud, containers, open source – each wave brought innovation and risk,” explains Apiiro. “Organizations that chased technology-specific scanners ended up with fragmented tools and unsustainable backlogs. Those that modeled the entire graph of software risk and governed it holistically were able to scale.”

“AI is the latest chapter, but not a unique one,” the company added. “By embedding AI into the software graph from the start, organizations can innovate with confidence, govern with clarity and avoid repeating the mistakes of past technology waves.”

Image: SiliconANGLE/Reve

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.