Featured News

MCP Spec Update: How It Strengthens Security for Scalable Infrastructure

2026-09-19 by AICC
MCP Spec Update Enterprise AI Infrastructure

The latest MCP spec update fortifies enterprise infrastructure with tighter security controls, moving AI agents from pilot mode into full production environments.

Marking its first year, the Anthropic-created open-source project released a revised specification this week — aimed squarely at the operational headaches keeping generative AI agents stuck in pilot mode. Backed by Amazon Web Services (AWS), Microsoft, and Google Cloud, the update adds support for long-running workflows and significantly tighter security controls.

The market is drifting away from fragile, bespoke integrations. For enterprises, this is a critical opportunity to deploy agentic AI that can read and write to corporate data stores — without incurring massive technical debt.


🔧 MCP Advances From 'Developer Curiosity' to Practical Infrastructure

The narrative has shifted from experimental chatbots to structural integration. Since September, the MCP server registry has expanded by 407 percent, now housing nearly two thousand servers.

“A year on from Anthropic's launch of the Model Context Protocol, MCP has gone from a developer curiosity to a practical way to connect AI to the systems where work and data live.”
— Satyajith Mundakkal, Global CTO at Hexaware

Microsoft has already "signaled the shift by adding native MCP support to Windows 11," effectively moving the standard directly into the operating system layer.

This software standardisation arrives alongside an aggressive hardware scale-up. Mundakkal highlights the "unprecedented infrastructure build-out," citing OpenAI's multi-gigawatt 'Stargate' programme as a clear signal that AI capabilities — and the data they depend on — are scaling fast.

“AI is only as good as the data it can reach safely.”
— Satyajith Mundakkal, Global CTO at Hexaware

⚙️ Long-Running Workflows: The New 'Tasks' Feature

Until now, hooking a large language model into a database was mostly synchronous. That works for a chatbot checking the weather — but it fails entirely when migrating a codebase or analysing complex healthcare records.

The new 'Tasks' feature (SEP-1686) changes this fundamentally. It gives servers a standard way to track work, allowing clients to poll for status or cancel jobs if things go sideways. Key supported states include:

  • ●  working — agent is actively processing
  • ●  input_required — agent awaits additional input

Ops teams automating infrastructure migration need agents that can run for hours without timing out. This update finally brings the resilience required for real-world agentic workflows.


🔒 MCP Spec Update Improves Security

For CISOs especially, AI agents often represent a massive and uncontrolled attack surface. The risks are already visible:

“Security researchers found approximately 1,800 MCP servers exposed on the public internet by mid-2025 — implying that private infrastructure adoption is significantly wider.”
“Done poorly, MCP becomes integration sprawl and a bigger attack surface.”
— Satyajith Mundakkal, Global CTO at Hexaware

To address these concerns, the maintainers tackled the friction of Dynamic Client Registration (DCR). The fix is URL-based client registration (SEP-991), where clients provide a unique ID pointing to a self-managed metadata document — cutting the admin bottleneck significantly.

Then there's 'URL Mode Elicitation' (SEP-1036). It allows a server — handling payments, for instance — to redirect a user to a secure browser window for credential entry. The agent never sees the password; it only receives the token. This keeps core credentials fully isolated — a non-negotiable requirement for PCI compliance.

“This brings the necessary oversight and access control to build a secure and open AI ecosystem.”
— Harish Peri, SVP at Okta

🧠 Under the Radar: Sampling With Tools (SEP-1577)

One feature in this MCP spec update has somewhat flown under the radar: 'Sampling with Tools' (SEP-1577). Servers were previously passive data fetchers — now they can run their own reasoning loops using the client's tokens.

Imagine a "research server" spawning sub-agents to scour documents and synthesise a full report — no custom client code required. It simply moves the reasoning closer to the data, unlocking a new tier of autonomous capability.


📊 Visibility Is the Next Hurdle

Wiring these connections is only step one. Mayur Upadhyaya, CEO at APIContext, argues that:

“The first year of MCP adoption has shown that enterprise AI doesn't begin with rewrites — it begins with exposure.”
“The next wave will be about visibility: enterprises will need to monitor MCP uptime and validate authentication flows just as rigorously as they monitor APIs today.”
— Mayur Upadhyaya, CEO at APIContext

MCP's roadmap reflects this reality, with updates targeting better "reliability and observability" for debugging. Treating MCP servers as "set and forget" is a recipe for failure. As Mundakkal notes, the lesson from year one is clear:

“Pair MCP with strong identity, RBAC, and observability from day one.”
— Satyajith Mundakkal, Global CTO at Hexaware

🌐 Star-Studded Industry Line-Up Adopting MCP for Infrastructure

A protocol is only as good as who uses it. In the year since the original spec's release, MCP has hit nearly two thousand servers. Here's how the major players are deploying it:

Platform MCP Integration
Microsoft Bridges GitHub, Azure, and M365; native Windows 11 support
AWS Baked into Amazon Bedrock
Google Cloud Supported across the Gemini ecosystem

This broad adoption reduces vendor lock-in. A Postgres connector built for MCP should theoretically work across Gemini, ChatGPT, or an internal Anthropic agent — without a rewrite.


✅ What Technology Leaders Should Do Now

The "plumbing" phase of Generative AI is settling down, and open standards are winning the debate on connectivity. Here's what enterprise technology leaders should prioritise:

  • ✅  Audit internal APIs for MCP readiness — focus on exposure, not rewrites
  • ✅  Verify that URL-based registration fits current IAM frameworks
  • ✅  Establish monitoring protocols immediately — treat MCP servers like production APIs
  • ✅  Implement RBAC and strong identity controls from day one

While the latest MCP spec update is backward compatible with existing infrastructure, the new features are the only path to bringing AI agents into regulated, mission-critical workflows — and ensuring enterprise-grade security at scale.

300+ AI Models for
OpenClaw & AI Agents

Save 20% on Costs