Analysis · curated 23 Sep 2026
Guidance for Responsible and Safe Usage - AI - Policies & Guidance - Department of Information Technology
First reported maryland.gov
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
Maryland DoIT's MCP security guidance gives defenders a governmental framework for vetting and governing agentic AI tool connections to internal systems, addressing a fast-growing and under-secured attack surface.
Maryland's Department of Information Technology published Version 2.0 of its 'Guidance for Responsible and Safe Usage' governance card for MCP (Model Context Protocol) server security, covering the risk landscape, vetting criteria for MCP servers, safe usage guidelines for state staff, and special guidance for BYOD, desktop clients, and browser agents. The document notes that MCP-enabled AI can take actions such as reading files, sending messages, and querying databases, and that decentralized MCP registries mean there is no single trusted source of truth.