Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

Open agent protocols need institutions

Anthropic's December 9 donation moves the Model Context Protocol (MCP) to a new institution for artificial intelligence (AI): the Agentic AI Foundation (AAIF), a directed fund under the Linux Foundation. Anthropic, Block, and OpenAI co-found the effort, with support from several other major technology companies.

The transfer recognizes a lesson that recurs throughout technical history: an open protocol needs more than accessible code. It needs an institution people expect to outlast any one vendor's strategy.

MCP provides a common way for artificial intelligence (AI) applications to connect with tools and data. In the year since its introduction, it has spread across model providers, development environments, cloud platforms, and thousands of public servers.

Adoption at that speed makes stewardship more consequential. The protocol begins to carry assumptions about identity, tool descriptions, permissions, errors, and how systems discover one another.

Neutrality creates credible commitment

Organizations invest in a standard when they believe they can build on it without being trapped by a competitor's unilateral control. Neutral governance can make that belief more credible.

It provides a forum for changes, transparent decision processes, intellectual-property rules, release discipline, and participation by competing implementers. It also creates somewhere for users to raise needs that no single vendor has an incentive to prioritize.

Neutrality is not the absence of power. It is a structure for making power visible and contestable.

Compatibility requires unglamorous work

A specification can be open while implementations remain inconsistent. Durable interoperability depends on conformance tests, version negotiation, reference implementations, migration guidance, and clear rules for deprecation.

Security needs the same treatment. A tool protocol connects agents to capabilities that may read sensitive data or produce external effects. The ecosystem needs coordinated vulnerability handling, secure defaults, server identity, permission patterns, provenance, and ways to communicate urgent changes across implementations.

The National Institute of Standards and Technology guidance on cybersecurity supply chains is relevant because a protocol expands the web of components on which a system depends. Openness improves inspectability; it does not remove supply-chain risk.

Institutions preserve knowledge

Standards accumulate rationale that does not fit in the final specification. Why does the group reject an alternative? Which compatibility failure drives a constraint? Which threat changes an authentication rule? Without an institutional memory, future maintainers can repeat old debates or remove a guardrail whose purpose is no longer visible.

Working groups should preserve decision records, threat models, implementation notes, test cases, and post-incident learning. That documentation is part of the protocol's infrastructure.

Adopters still own their boundary

Foundation stewardship does not make every server trustworthy or every integration appropriate. Implementing organizations must still inventory connections, verify publishers, restrict permissions, monitor behavior, and maintain an exit path.

Open protocols reduce the cost of connection. Good institutions reduce the uncertainty around their evolution. Responsible adopters manage what passes through the connection.

MCP's move to a foundation is therefore more than a change in repository governance. It is a step from a successful interface toward durable public infrastructure—unfinished, contested, and worth tending.

Sources and research trail

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.