New MCP specification addresses the main barrier to enterprise adoption
Ars Technica Samuel Axon ● Covered by 7 sources
MCP, the protocol AI agents use to talk to apps, just got a major enterprise-focused overhaul. Big companies wanted stability and security guarantees before betting their systems on it — now they're getting them.
Based on reporting by Ars Technica, Samuel Axon — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
MCP started life as a scrappy little connector, something that let an AI model reach into apps running on your own laptop. That was fine for hobbyists and early adopters. It was never going to fly in a bank's IT department. The new specification, released this week, is essentially MCP admitting it wants to grow up and get a corporate job.
The headline change is a formal deprecation policy, and it's more consequential than it sounds. Under the new rules, any feature slated for removal has to stick around for at least 12 months after deprecation is announced, with an exception carved out only for critical security patches. That single guarantee removes a big chunk of the risk that had been keeping cautious enterprises on the sidelines. Nobody wants to build a production pipeline on a protocol that might yank the rug out from under them next quarter.
That 12-month buffer fits into a broader pattern running through this update: MCP rethinking its own foundations now that it's being asked to work at a scale nobody designed for two years ago. What began as a way to wire a model to files and tools on a single machine now has to behave predictably across fleets of servers, security teams, and compliance checklists it was never built with in mind.
Governance-wise, MCP sits under the Agentic AI Foundation, itself part of the Linux Foundation, which gives it the look of a neutral, community-run standard. Anthropic created it not quite two years ago and still holds real sway, since several of the project's key maintainers work there. But the contributor list has widened considerably — OpenAI, Google, Microsoft, and Amazon are all putting engineering time into it, and it's showing up across a growing swath of developer tools and everyday software far beyond Anthropic's own ecosystem.
My take — AI-written commentary, not fact-checked reporting
Anthropic effectively controlling the rulebook while pretending it's neutral open governance is the same trick every tech giant plays with 'open' standards — see Google and Android, or Meta and Llama's license. I don't think that disqualifies MCP, but enterprises adopting it should know exactly whose priorities get baked into 'community' decisions when push comes to shove.
Read more about this at: Ars Technica