The most important thing that happened to the Model Context Protocol this year was not another AI app adding support for it. It was Anthropic giving up control of it. On December 9, 2025, the company that invented MCP handed it to a new, vendor-neutral body called the Agentic AI Foundation, co-founded with OpenAI and Block and backed by Google, Microsoft, Amazon Web Services, Cloudflare and Bloomberg, according to Anthropic's own announcement and a matching press release from the Linux Foundation. A protocol built by one AI lab is now jointly stewarded by its biggest rivals. That is the real story, because it answers the question every engineering team actually has: is this thing safe to build on for the next five years, or will it get pulled out from under us?
Key takeaways
- Anthropic donated MCP to the new Agentic AI Foundation (AAIF) under the Linux Foundation on December 9, 2025, co-founded with OpenAI and Block, with Google, Microsoft, AWS, Cloudflare and Bloomberg as platinum members.
- MCP now sees more than 97 million monthly SDK downloads and powers over 10,000 active public servers, according to Anthropic's own figures.
- An academic benchmark called MCPTox (arXiv, August 2025) found attackers could hijack MCP tool calls in 36.5% of test cases on average, and 72.8% of the time against OpenAI's o1-mini, through hidden instructions in tool descriptions.
- Build an MCP server if you already run a public API that AI agents plausibly need to call; skip it if you have one internal workflow and no plan to expose it to outside AI clients.
MCP Solves the M-by-N Integration Problem, Not Just a Branding Exercise
Before MCP, connecting M different AI applications to N different tools meant writing and maintaining roughly M multiplied by N custom integrations, one for every pairing. Anthropic engineers David Soria Parra and Justin Spahr-Summers designed MCP specifically to collapse that math when Anthropic introduced the protocol on November 25, 2024, according to Anthropic's original announcement and independent reporting that followed it.
Technically, MCP defines a client-server architecture, documented at modelcontextprotocol.io. An "MCP host" is the AI application itself, such as Claude Desktop, Cursor or Visual Studio Code. It creates an "MCP client" for each "MCP server" it connects to, and every exchange runs over JSON-RPC 2.0, a lightweight remote-procedure-call format. A server can expose three things: tools (actions the AI can invoke), resources (data it can read) and prompts (reusable templates). Any MCP-compliant client can discover and call them the same way, regardless of which company built the client or the server. That is the entire point: one shared interface instead of a proprietary plug for every platform.
The Adoption Numbers Are Real, Not Just Conference-Keynote Hype
Protocols get announced constantly; few get used. MCP's usage figures, published by Anthropic alongside the Linux Foundation donation, suggest this one crossed into default infrastructure territory within about thirteen months.
| Metric | Figure (as of December 2025) |
|---|---|
| Monthly SDK downloads (Python and TypeScript combined) | 97 million+ |
| Active public MCP servers | 10,000+ |
| Time from launch to Linux Foundation donation | About 13 months |
| Platforms with native support | ChatGPT, Claude, Gemini, Microsoft Copilot, VS Code, Cursor |
"A year later, it's become the industry standard for connecting AI systems to data and tools," Anthropic chief product officer Mike Krieger said in the donation announcement. OpenAI added MCP support to its own Agents SDK in March 2025 and joined the protocol's steering committee, a move independent developer Simon Willison covered in detail at the time, while Google later folded MCP into its Gemini agent stack. Coding tools built around this same wave of AI-agent adoption, including the ones compared in our Cursor vs Windsurf vs GitHub Copilot guide, now lean on MCP to reach outside data sources rather than shipping their own bespoke plugin formats.
Handing MCP to the Linux Foundation Is About Trust, Not Charity
Companies do not usually give away control of infrastructure that has just become "the industry standard." They do it when the alternative costs them more. No competitor wants to build mission-critical AI plumbing on a rival's roadmap, one that could change pricing, licensing or direction unilaterally. Moving MCP into the AAIF, alongside Block's goose and OpenAI's AGENTS.md as founding projects, removes that risk for everyone at once.

"The protocols will grow with the transparency and stability that only open governance provides," Linux Foundation executive director Jim Zemlin said in the foundation's announcement. Block's head of open source, Manik Surtani, framed the stakes more bluntly in the same release: agentic AI's connective tissue "can either remain closed and proprietary or be driven by open standards." Practically, little changes day to day. MCP's existing steering process continues; what changes is who ultimately has authority over it, and that authority is no longer Anthropic's alone. It is the same logic behind treating underlying AI models as interchangeable parts rather than a single vendor's lock-in, a shift we detailed in our coverage of GitHub Copilot's multi-model architecture.
Who Should Build an MCP Server Now, and Who Can Wait
Not every team needs to act on this immediately. Use this as a rough filter before you spend engineering time on it.

- Build one if you already maintain a public API or SaaS product that AI agents plausibly need to call. OpenAI's own Agents SDK documentation already lists Cloudflare, HubSpot, Intercom, PayPal, Plaid, Shopify, Stripe, Square, Twilio and Zapier among services developers can reach through MCP-compliant servers, which shows what "plausibly needed" looks like in practice.
- Skip it for now if you have a single internal AI workflow talking to a single internal tool. A direct API call is simpler to secure and maintain than standing up and patching a full MCP server for one caller.
- This matters most to backend and platform engineers deciding how to expose internal systems to AI agents, and engineering leads choosing between MCP and a proprietary plugin format for a new product.
- This can wait for teams not yet building or integrating AI agents at all, and for non-technical end users, since MCP is developer-facing infrastructure rather than a feature anyone clicks on directly.
If you are weighing whether AI-assisted development changes this calculus at all, it is worth reading how much of the actual coding work is shifting, a trend we covered in our look at vibe coding's rise in software development.
Never miss a story
Tools, tutorials and AI deep-dives - straight to your inbox, every week.
The Uncomfortable Part: An Open Standard Is Not the Same as a Safe One
The strongest counterargument to worrying about MCP's security is the adoption story itself: if 10,000-plus servers and every major AI lab are already running on it, the thinking goes, the protocol must be robust enough for production use, and open governance under the Linux Foundation should only increase scrutiny of it over time. That is a fair point, and it will likely hold up as tooling matures.
It does not hold up yet at the server level. A benchmark called MCPTox, published on arXiv in August 2025, tested 45 live MCP servers and 353 real tools and measured "tool poisoning" attacks, malicious instructions hidden inside a tool's description that are invisible to the user but readable by the AI model. Across 20 language models, the average attack succeeded 36.5% of the time, and against OpenAI's o1-mini specifically, it succeeded 72.8% of the time. The researchers found that more capable models were often more vulnerable, not less, because they follow embedded instructions more faithfully than weaker ones do.

The AAIF's donation governs the MCP specification. It does not vet, audit or certify the thousands of individual third-party servers built on top of it.
That distinction matters. Open governance of the protocol is a real improvement for long-term stability. It is not a security guarantee for any specific server your AI agent connects to. Treat an unfamiliar MCP server the way you would treat any other unaudited dependency: read what tools it exposes, pin versions, and do not connect an agent to a server it does not actually need.
Do You Need to Care About MCP If You Do Not Build AI Agents?
No, not directly. MCP is plumbing for AI applications and developer tools, not a feature end users interact with by name. But if a product you already use, a code editor or a support desk, advertises "AI agent" or "MCP" support, that label increasingly means it can read your data and act through this exact protocol, worth knowing before you grant access.

Is MCP the same thing as an API? Not quite. MCP standardizes how an AI application discovers and calls tools across many different servers using one JSON-RPC-based format, while a typical API is a one-off interface built for a single service.
Do you need Anthropic's permission to build an MCP server? No. MCP has been an open specification since its November 2024 release, and governance now sits with the vendor-neutral Agentic AI Foundation rather than with Anthropic alone, per the Linux Foundation's announcement.
The practical takeaway: treat MCP support as a checklist item when evaluating any AI tool or agent framework in 2026, since it is now the default rather than a differentiator. Just do not mistake "governed by a neutral foundation" for "safe by default" when you decide which specific servers your agents are allowed to talk to.
Sources
- Anthropic: Donating the Model Context Protocol and establishing the Agentic AI Foundation
- Linux Foundation: Announcing the formation of the Agentic AI Foundation
- Model Context Protocol: Architecture overview
- Simon Willison: MCP and the OpenAI Agents SDK
- MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers (arXiv)