Policy enforcement verification, cross-vendor attested registries, and privacy-preserving auditability in MCP
Investigate and develop formal verification methods for enforcing safety and security policies in MCP-based agent workflows; design cross-vendor interoperable attested registries for MCP tools and servers; and create privacy-preserving auditability mechanisms that provide verifiable provenance and compliance evidence without exposing sensitive data.
References
However, significant research challenges remain. Questions around formal verification of policy enforcement, cross-vendor interoperability of attested registries, and privacy-preserving auditability are still open areas of study.
Another open question is how external auditors can independently verify selected evidence without exposing sensitive agent communications, risk records, mitigation details, or business data.
These approaches are early and carry open questions (e.g., registry governance, attestation cost, and the circularity of using one trust system to bootstrap another), and we present them as a promising but unsettled direction rather than a solution.