Mugoya Hillarious
AI Security & Governance ResearcherNone
Mugoya Hillarious is an emerging technology professional focused on AI security, governance, and cybersecurity awareness. With a strong background in community leadership and technology advocacy, he has contributed to multiple developer and research communities, including the Cloud Security Alliance AI Safety Working Group and Indabax Uganda, various Google Developer Groups among others.
He actively volunteers across African tech ecosystems, organizing and speaking at technology events, delivering cybersecurity and AI safety awareness sessions, and supporting digital skills development initiatives for students and communities. His work bridges technical innovation with responsible technology use, emphasizing secure and trustworthy AI systems.
Passionate about building secure and well-governed AI systems, he aims to contribute to Africa’s emerging AI governance landscape while supporting technology solutions that create positive social impact.
Abstract
The rapid adoption of AI assistants capable of interacting with external systems has introduced new architectural patterns that require equally new security approaches. FastMCP servers, built around the Model Context Protocol (MCP), enable structured communication between AI models and external tools, allowing applications to expose functionality in a standardized and scalable way. As organizations integrate MCP into production environments, understanding how to secure this interaction layer becomes essential to maintaining system integrity, protecting data, and ensuring reliable AI operations. This session provides a technical exploration of FastMCP server security, focusing on how MCP changes traditional trust boundaries within software systems. The talk explains how MCP handles tool discovery, context exchange, and action execution, and examines how these mechanisms introduce risks that differ from conventional web or API architectures. Participants will gain insight into how AI generated requests interact with backend services and why existing security assumptions must be re-evaluated when software behavior is partially driven by machine reasoning. The presentation analyzes key security considerations across the MCP lifecycle, including identity verification for AI agents, permission modeling for exposed tools, secure handling of contextual data, and protection against manipulation of model inputs and outputs. Special attention is given to designing controlled interfaces that reduce unintended system access while maintaining flexibility for developers building AI-enabled features. In addition to technical safeguards, the session discusses operational practices necessary for maintaining secure MCP environments over time. Topics include observability strategies, logging and auditing mechanisms, runtime monitoring of AI-triggered actions, and incident response considerations specific to agent-mediated systems. Attendees will learn how to establish measurable security controls that support continuous evaluation and improvement of MCP deployments. The talk further situates FastMCP security within organizational AI management practices by demonstrating how MCP components can be incorporated into structured governance processes aligned with ISO/IEC 42001. By linking infrastructure design decisions to risk assessment, documentation, and oversight requirements, the session shows how technical implementation contributes directly to responsible AI system management.