Engineers building AI agents that interact with business systems face a critical security dilemma when connecting those agents to internal APIs, according to a new technical analysis published by The New Stack. The report examines how the Model Context Protocol (MCP) enables agents to reach company data but creates urgent questions about what information those agents should access once connected. The analysis argues that GraphQL, a widely deployed technology, provides a practical solution for controlling exactly which data fields AI agents can read and modify.

The challenge centers on APIs that return broad datasets containing personally identifiable information, sensitive financial details, fraud indicators, and operational data never intended to leave trusted networks, the report explains. When an operations team member asks an AI assistant to identify orders missing shipping deadlines and create inventory transfer requests from other warehouses, the agent must call APIs for current orders and available stock—yesterday's snapshot won't show what remains in inventory that afternoon. Building an MCP server makes internal order management systems reachable to agents quickly, but connecting the agent is the straightforward part. The harder problem involves determining what the agent should view after it arrives. MCP tools that pass along everything from upstream systems pose security risks. Filtering each tool's response leads to maintaining dozens of similar, overlapping tools as finance needs different order views, support requires access to internal notes, and additional teams connect inventory systems.

The report identifies a "deterministic, field-level contract" as the path forward, specifying precisely what each agent can see and do independently of both upstream APIs and downstream agents. MCP defines how agents discover and call tools, while a field-level contract defines what those tools are permitted to access—functioning as different layers that both prove necessary. GraphQL was designed around the concept that API calls should specify the exact fields they need, allowing an order-status lookup to request only status and shipment deadline fields regardless of what else upstream systems provide. If an agent requests a field like internal fraud score or customer Social Security number, a GraphQL server can block the request or render those fields unreachable, with the rule belonging to the field and applying across all operations that request it.

The same field-level control extends to write operations, according to the analysis. Operations employees need permission to request inventory transfers, but a read-only connection would prevent the work while unrestricted access could allow agents to change stock counts, cancel orders, or issue refunds. GraphQL mutations expose particular business actions like requesting inventory transfers, with the runtime authorizing them and underlying services checking current availability and required approvals before accepting requests. A GraphQL layer can sit over existing services that expose REST, gRPC, SOAP, and other protocols without replacing the APIs running the business—the order API continues returning a broad record to the integration layer while the agent receives only the fields it's permitted to see.

GraphQL has supplied this field-level contract to applications for more than a decade, powering billions of daily transactions at Shopify, Netflix, Airbnb, Expedia Group, and Walmart, the report notes. These companies and countless others have built up ten years of experience and production infrastructure running exactly this model. MCP makes business systems reachable by agents, while a field-level contract makes that access something organizations can control. The precision that helped developers build efficient applications quickly proves even more useful when the caller is an agent composing operations at runtime, GraphQL positioned as "a perfect answer sitting right in front of us." For companies racing to deploy AI agents without exposing sensitive data or creating maintenance nightmares, the choice between speed and control may hinge less on new protocols than on recognizing which battle-tested layers already solve the hard problems.