Analysis · curated 23 Sep 2026

Guidance for Responsible and Safe Usage - AI - Policies & Guidance - Department of Information Technology

Coverage timeline

23 Sep 2026maryland.gov

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

Maryland DoIT's MCP security guidance gives defenders a governmental framework for vetting and governing agentic AI tool connections to internal systems, addressing a fast-growing and under-secured attack surface.

Maryland's Department of Information Technology published Version 2.0 of its 'Guidance for Responsible and Safe Usage' governance card for MCP (Model Context Protocol) server security, covering the risk landscape, vetting criteria for MCP servers, safe usage guidelines for state staff, and special guidance for BYOD, desktop clients, and browser agents. The document notes that MCP-enabled AI can take actions such as reading files, sending messages, and querying databases, and that decentralized MCP registries mean there is no single trusted source of truth.