VOOZH about

URL: https://thenewstack.io/mcp-maintainers-enterprise-roadmap/

⇱ MCP maintainers from Anthropic, AWS, Microsoft, and OpenAI lay out enterprise security roadmap at Dev Summit - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2026-04-06 12:25:05
MCP maintainers from Anthropic, AWS, Microsoft, and OpenAI lay out enterprise security roadmap at Dev Summit
sponsor-cncf,
AI Agents / AI Infrastructure / Model Context Protocol (MCP)

MCP maintainers from Anthropic, AWS, Microsoft, and OpenAI lay out enterprise security roadmap at Dev Summit

MCP maintainers from Anthropic, AWS, Microsoft, and OpenAI outline plans for enterprise security, governance, and reliability at the MCP Dev Summit in New York.
Apr 6th, 2026 12:25pm by Eric Newcomer
👁 Featued image for: MCP maintainers from Anthropic, AWS, Microsoft, and OpenAI lay out enterprise security roadmap at Dev Summit
Photo by Adam Szabo on Unsplash
CNCF sponsored this post.

In a roundtable panel at the MCP Dev Summit last week in New York, Model Context Protocol (MCP) maintainers from Anthropic, AWS, Microsoft, and OpenAI reassured us that the MCP spec is in safe hands at the Agentic AI Foundation (AAIF) and will be addressing critical enterprise requirements for security, reliability, and governance.  

Starting in December with contributions of MCP, goose, and AGENTS.md, the AAIF has quickly grown to 170 members. MCP is the most popular project and has become the industry standard for connecting AI agents to data and applications. 

The panel reassured MCP users that little has changed in how the project governs itself (it’s still a bottom-up, open source project). The AAIF provides a connection to enterprise users and their needs, which feeds back into protocol development to address concerns about using MCP in production.

“We see customers excited about the Foundation and about this being a neutral place to work on MCP and related projects,” said maintainer Clare Liguori, Sr Principal Engineer, AWS. “It’s great to be around the community and work within the entire developer ecosystem, and not just within our own companies.”

The broad adoption of MCP has identified significant areas for improvement, they said, especially for enterprise applications requiring strict security, scalability, reliability, and governance.  

“MCP is the seed. The foundation has a broad mandate beyond just MCP … It’s open to new protocols and technologies, just like early Cloud Native Computing Foundation (CNCF) was. But MCP itself should stay narrow: Connecting AI to data sources.” — Nick Cooper, OpenAI

“MCP is the seed,” said maintainer Nick Cooper, Technical Staff, OpenAI. “The foundation has a broad mandate beyond just MCP,” he continued. “It’s open to new protocols and technologies, just like the early Cloud Native Computing Foundation (CNCF) was. But MCP itself should stay narrow: Connecting AI to data sources. Identity, observability, and governance should come in as other projects.”

AAIF is currently soliciting new project proposals related to agentic AI, Cooper added, but we need to be careful that the first accepted projects set the right direction. 

“We see open challenges in security and authorization, and we’re happy to have AAIF bring the industry together and talk about the right solutions,” said maintainer David Soria Para, Technical Staff, Anthropic, and co-creator of MCP.  

Authorization has been one of the most actively changing parts of the MCP spec over the past year, Para added. The maintainers are collaborating with Okta and others on authentication improvements.

But no single protocol will solve all security challenges — the ecosystem (gateways, registries, sandboxing, interceptors) must evolve alongside the protocol, Para said.

Moderator Sephen O’Grady of RedMonk said that MCP is the fastest-growing standard RedMonk has ever tracked. For example, he said, it took Docker about 13 months to get as established as MCP did in about 13 weeks. 

Another proposed standard in the agentic AI space is the Agent2Agent (A2A) protocol, which enables AI agents to connect with one another.  

MCP and A2A are large protocols learning from each other, and not directly competing, the panel noted. Future convergence is possible but not certain — “approaches are slightly different at the moment,” said Para. “But we are open to anything that makes the industry easier to work with through open standards.”

O’Grady referenced a widely debated social media post claiming “MCP is dead” because a command-line interface (CLI) with comparable functionality is available. 

“We ship APIs, we ship SDKs, and we ship CLIs all to interact with Azure for a concrete experience with Microsoft, and that’s because we want to meet developers where there are, and we want to meet them at the scenario that they’re working in,” said maintainer Catie McCaffrey, Partner Software Engineer at Microsoft. “For local development scenarios, having an agent just interact with the Azure CLI or the GitHub CLI is a really wonderful use case.”

“For local development scenarios, having an agent just interact with the Azure CLI or the GitHub CLI is a really wonderful use case … The focus of MCP going forward has to be on its utility in connecting things. MCP can evolve as long as it preserves the utility of what’s important.”

The panel said that both the MCP and CLI mechanisms for interacting with agents are important for different use cases and offer different developer experiences. 

“The focus of MCP going forward has to be on its utility in connecting things. MCP can evolve as long as it preserves the utility of what’s important,” said Cooper. “Where the value lies for me is that there’s real utility in using MCP to connect these different systems. MCP should grow, evolve, and focus on that. And that’s why it’s important to behave neutrally and focus on the utility that MCP is delivering.” 

The panel agreed that the MCP client needs attention and that MCP best practices require better documentation and communication. For example, don’t just wrap 500 API endpoints. That’s the number one anti-pattern. Instead, design the MCP interface for the agent as a new class of consumer (not just another developer). There are big quality differences between carefully designed servers and naive API wrappers.

The Cloud Native Computing Foundation (CNCF) hosts critical components of the global technology infrastructure including Kubernetes, OpenTelemetry, and Argo. CNCF is the neutral home for cloud native collaboration, bringing together the industry’s top developers, end users, and vendors.
Learn More
The latest from CNCF
TRENDING STORIES
Eric Newcomer is CTO at Intellyx. He has served as CTO for leading integration vendors WSO2 and IONA Technologies and as Chief Architect for major enterprises such as Citibank and Credit Suisse. He has created some of the best-known industry...
Read more from Eric Newcomer
CNCF sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: OpenAI, Anthropic, Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.