Mia Urman, CEO of AuraPlayer and Oracle ACE Director, is a leading AI and modernization expert helping enterprises evolve their ERP systems.
AI has developed something of a Dr. Jekyll and Mr. Hyde problem. The same technology that is delivering extraordinary productivity is raising very real questions about access, control and unintended actions. An AI assistant that summarizes a report is one thing. An autonomous agent that can create an order, move inventory, pay a supplier or update a mission-critical enterprise system is something else entirely.
We spent years seeing how powerful we could make AI. Now that it is becoming incredibly advanced, we’re having a very different conversation, shifting from “What can we do with AI?” to “What should AI be allowed to do?”
TechCrunch reported that more than 100 technology organizations, including OpenAI, Anthropic, Google and Microsoft, signed an open letter urging both the private and public sectors to work together to defend against AI-related cyber threats. This followed recent incidents showing how autonomous systems moved beyond their intended boundaries to pursue a goal.
At Stripe Sessions in 2026, Nat Friedman, the former CEO of GitHub, said that after realizing he hadn’t drunk enough water that day, he gave what may be the perfect example of a dangerous AI prompt: “You should do whatever it takes to make sure I drink water.” The agent took him seriously and told Friedman to walk to the kitchen and drink a bottle of water. After he complied, the agent sent him a snapshot from his home security camera of himself drinking and congratulated him.
As a technologist, part of me loves this story. As someone who has spent decades working with Oracle enterprise systems, I think: Imagine if that agent connected to your ERP!
The AI did exactly what it was asked. The problem was everything it wasn’t told: where the boundaries were, what required approval and when it needed to stop. And in an enterprise system, these safeguards are crucial.
Gravitee’s “The State of AI Agent Security 2026” survey found that 88% of organizations experienced a confirmed or suspected AI-agent security incident in the previous 12 months, while 85% lacked formal accountability plans for agent behavior.
In a similar study, Arkose Labs found that “97% of respondents expect a material AI-agent-driven security or fraud incident within the next 12 months. … Yet only 6% of security budgets are currently allocated to this risk.”
There is something almost Frankenstein-like about where we’ve arrived. We have succeeded in creating extraordinarily autonomous systems and are now racing to build constraints to curb their power.
Simply put, a new employee may be brilliant. But you still don’t give them administrative access to every Oracle responsibility on their first day. Why should an AI agent be treated any differently?
As organizations look for practical ways to bring AI into their enterprise systems, many are turning to Model Context Protocol (MCP) to connect AI agents with Oracle. The excitement is understandable. But where we give it access matters just as much as what the AI can do with it.
Many MCP servers available today operate at the database layer. That can be extremely powerful for querying information, analytics, development and administrative use cases. But reading enterprise data and executing business transactions directly at the database level have fundamentally different risk profiles.
Imagine an employee asking an AI agent: “Move 500 units of Item A from warehouse X to warehouse Y.” AI is excellent at understanding the intent. It can identify the item, quantity, source and destination. But understanding what someone wants to do is very different from knowing how to execute that transaction safely.
If an AI agent needs to transfer this inventory, we don’t want it deciding which database tables to update or which SQL statements will best accomplish the task. We want it to execute the same governed business process found inside Oracle EBS.
Behind what looks like a simple transaction can sit decades of business logic: validations, approvals, custom workflows and security rules. That logic doesn’t live in database tables. Much of it lives in the application processes organizations have spent years building, testing and securing. In Oracle Forms and EBS environments, the application layer provides the context and guardrails around those transactions. AI can make that governed workflow easier, faster and more seamless. But it shouldn’t become a shortcut around it.
This is where an old friend becomes surprisingly relevant to the AI conversation: the REST API.
Instead of giving an AI agent broad access to the enterprise database, organizations can expose specific, reusable business functions as controlled APIs or REST services.
One service might retrieve an order status, check inventory availability, initiate a subinventory transfer or create a sales order. MCP gives the AI agent a structured way to discover and request these approved business functions under an authorized user.
Think of it this way: AI understands the request. The API defines the boundaries, inputs and response data. Then the Oracle EBS automations execute the business process. This is an architectural approach we’ve spent considerable time developing in our solutions at AuraPlayer: capturing existing, predefined workflows in Oracle Forms and EBS and exposing them as controlled REST services through an MCP server.
This allows the AI agent to initiate the action, but the transaction still travels through the existing application, including its business logic, validations and security controls. Rather than letting the AI agent manipulate the underlying database, a better approach is to give it access to a curated set of business actions that have already been approved and governed.
This distinction becomes increasingly critical as AI moves from read-only to taking action inside our enterprise systems. The goal isn’t to keep AI out but to control how it gets in and what rules it must follow. With the right precautions in place, we’ll give AI the tools it needs to increase productivity without giving it the keys to the castle.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


