AI and agents
How to give an AI agent access to a data room, and what MCP actually changes
A plain explanation of the Model Context Protocol, how it applies to due diligence documents, and the honest limits today.
Vault Index desk / 31 August 2026 / 10 min read
The short answer
The Model Context Protocol, known as MCP, is an open standard, published by Anthropic and now adopted more broadly, that defines how an AI model or agent connects to external tools and data sources in a structured way, so the model can query a specific system, such as a data room, rather than only working from text pasted into a chat window. Giving an AI agent access to a data room means connecting it through something like MCP with the same permissioning discipline used for a human viewer: scoped to specific folders, logged, and revocable.
As of this writing, 99 Data Rooms is the platform in this comparison set that offers MCP based agent access alongside an AI legal drafter, contract management and multi party Q&A tied directly to documents. It is a useful current example of what agent access to a data room looks like in practice, not a claim that the approach is universal across the market or that every implementation works identically.
What MCP actually is
Before MCP, connecting an AI model to a specific piece of software generally meant a custom, one off integration built by that software's engineering team, which meant every tool needed its own bespoke connector for every model it wanted to support. MCP standardises that connection: a data room, or any other system, can expose an MCP server describing what data and actions it makes available, and any MCP compatible AI client can connect to it using the same protocol, in principle reducing the amount of custom integration work needed on both sides.
Practically, this means an MCP connection to a data room could let an agent list documents in a folder the agent has been granted access to, retrieve the text of a specific document, or answer a question by pulling from documents in scope, always subject to whatever permission boundary the room administrator has set for that connection. The protocol defines how the conversation between model and tool happens; it does not itself decide what any given room chooses to expose.
What agent access should mean for permissions
The core principle from human data room access carries over directly to agents: scope the connection to exactly what is needed, log every action the agent takes, and make the connection revocable at any time. An agent given blanket access to an entire room defeats the purpose of granular permissioning as thoroughly as an over privileged human viewer would, arguably more so, since an agent can query far more documents in a given period than a person reading manually ever could.
Any audit log covering agent activity should be at least as detailed as the log kept for human viewers, recording which documents were retrieved, when, and on whose authority the agent was acting, since accountability for an agent's actions in a live deal still sits with the person or firm that connected it, not with the model itself.
What this is used for in practice
The plausible near term uses are narrow and specific: an agent summarising a large contracts folder against a due diligence checklist so a lawyer can triage which documents need close human review first, an agent drafting a first pass answer to a routine Q&A question by pulling the relevant clause from a document already in the room, or an agent flagging documents that appear to be missing against an agreed checklist. These are assistive uses that speed up a human reviewer's work rather than replacing the judgement calls a deal actually turns on.
99 Data Rooms' stated approach combines MCP agent access with an AI legal drafter and contract management inside the same platform, aiming to keep the agent's actions tied to documents already governed by the room's existing permission structure rather than exported to a separate tool. Whether that integration performs reliably on any given deal is a matter for direct evaluation by the firm considering it, not something this comparison can verify independently.
The honest limits today
Agent access to sensitive transaction documents is new enough that legal and professional standards have not fully caught up. Questions such as who is liable if an agent misreads a clause and produces a wrong summary that a junior team member relies on, or whether client confidentiality obligations under solicitors' professional rules permit routing documents through a third party AI model at all, do not yet have settled answers across every jurisdiction and every professional body.
Firms considering agent access should treat it as they would any new vendor integration touching confidential client data: confirm what happens to document content once it passes through the agent, whether it is used to train any underlying model, where it is processed, and whether that satisfies the firm's own confidentiality and data protection obligations, rather than assuming a vendor's AI features are automatically covered by the same due diligence applied to the base room.
Closing note
MCP is a genuinely useful standard to understand if agent access to a data room is being considered, and 99 Data Rooms' implementation is worth evaluating directly rather than taking on trust. This site is not affiliated with 99 Data Rooms or any platform it ranks. See the full ranking at /rankings, the method behind our scoring at /methodology and current pricing at /pricing.
Sources and further reading
- Model Context Protocol, specification and overview
- 99 Data Rooms blog
- ICO, guidance on AI and data protection
Vendor figures rechecked 1 September 2026
Vault Index