Insights

MCP Ecosystem in 2026: How the Protocol Moved to Shared Industry Infrastructure

6 min read#mcp#model-context-protocol#a2a#agentic-ai#linux-foundation#ai-agents

Who this is forDevelopers, architects, and content creators who need an accurate picture of how MCP and A2A relate and how far the adoption and security claims can be trusted.

Introduction

The Model Context Protocol (MCP) went from a single-vendor specification to shared industry infrastructure in less than a year. That change matters for anyone choosing an agent stack, writing about it, or deciding how much to trust the adoption numbers that circulate. Readers searching for “MCP vs A2A” or “is MCP a standard” often get a framing of rival protocols that the evidence no longer supports. This article reconstructs the state of the MCP ecosystem as of May 2026: how governance changed, how the protocol relates to Google’s Agent2Agent (A2A) protocol, which adoption figures are self-reported, and what the specification does and does not guarantee about security. You will get a summary you can cite accurately, with sources listed at the end.

Summary

MCP moved between mid-2025 and May 2026 from an Anthropic-led single-vendor standard to a vendor-neutral infrastructure project under the Linux Foundation. During the same period, the industry consensus around Google’s A2A settled on complementarity rather than competition: MCP handles vertical agent-to-tool connections, and A2A handles horizontal agent-to-agent connections.

Architecture Overview

The relationship between the two protocols is easiest to see as layers. MCP sits vertically, connecting an agent to tools and context. A2A sits horizontally, letting agents discover and collaborate with other agents through Agent Cards. Both are now governed under the Linux Foundation, which is the main reason the “protocol war” framing no longer fits.

MCP vertical and A2A horizontal complementary structure, with Linux Foundation governance

Key Data

1. Adoption Scale (as of December 2025)

  • More than 10,000 active public MCP servers and more than 97 million monthly SDK downloads. Source: official announcements from Anthropic and the MCP project. These are vendor self-reported figures with no third-party audit.
  • MCP Registry (registry.modelcontextprotocol.io): launched as a preview on September 8, 2025, with roughly 2,000 entries by November. The “407% growth” figure is measured from the initial batch onboarded in September, not from the September announcement date.
  • First-class client support in major platforms: ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and VS Code.

2. Vendor Adoption (executive statements cross-checked against vendor documentation)

Vendor MCP-enabled products
OpenAI ChatGPT (Developer Mode, Apps SDK), Responses API, Agents SDK, Codex
Google Gemini models, Gemini CLI, open-source MCP servers for Google Maps and Cloud databases
AWS Bedrock, AgentCore, Kiro, Strands, Quick Suite
Microsoft Copilot Studio (MCP generally available)

3. Standardization and Governance

  • December 9, 2025: Anthropic donated MCP to the Agentic AI Foundation (AAIF), a new directed fund under the Linux Foundation. Anthropic, Block, and OpenAI co-founded AAIF. The eight Platinum members are AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI.
  • MCP Registry governance: a registry working group that includes Anthropic, PulseMCP, GitHub, and Stacklok, with at least 16 contributors from nine or more companies.
  • GitHub frames the move as joining “established open infrastructure” alongside Kubernetes, SPDX, GraphQL, and CNCF. This is GitHub’s framing, not an objective claim of equivalence.

4. Competing and Complementary Protocols: A2A

  • April 2025: Google first announced Agent2Agent (A2A). June 23, 2025 (Open Source Summit North America): Google donated the specification, SDKs, and tooling to the Linux Foundation, launching the Agent2Agent project.
  • A2A participants include AWS, Cisco (Outshift), Salesforce, SAP, Microsoft, and ServiceNow, plus more than 100 other companies that later grew to more than 150.
  • Positioning: A2A is horizontal (agent-to-agent discovery and collaboration via Agent Cards), and MCP is vertical (agent-to-tool and agent-to-context). Google’s official documentation states that “A2A complements Anthropic’s MCP.” The Agent Communication Protocol (ACP) merged into A2A in September 2025. Even articles titled “Protocol Wars” conclude that the two are complementary.

5. Security (confidence: medium)

  • The MCP specification (2025-11-25) has a “Tool Safety” section. It states that tools can perform arbitrary code execution and that tool descriptions and annotations should be treated as untrusted unless they come from a trusted server. This directly acknowledges the attack surface for tool poisoning and similar attacks.
  • However, the specification also states that MCP cannot enforce these security principles at the protocol level. The acknowledgment is a recommendation, not a defense mechanism. Trusted-server rug pulls, such as the runtime trust gap illustrated by CVE-2025-54136, are not covered.

Insights

  1. The “standards war” framing is wrong. As of May 2026, the industry consensus is that MCP (vertical) and A2A (horizontal) are complementary layers that operate at different levels. Both went to the Linux Foundation, MCP through AAIF in December 2025 and A2A in June 2025, and competing vendors such as Google, OpenAI, AWS, and Microsoft participate in both governance bodies. Content asking “which of MCP and A2A wins” is working from an outdated angle.

  2. The shift from single vendor to neutral infrastructure is the key event. Anthropic handed its own invention to the Linux Foundation. This resembles giving up control in exchange for trust in the standard, but the project keeps its governance autonomy; it was not abandoned. The pattern resembles the path Kubernetes took from Google to CNCF.

  3. Always flag adoption metrics as self-reported. The 10,000 servers and 97 million downloads come from the foundation and vendor themselves. When you cite them, state that they are based on official announcements so that readers can judge the data for themselves.

  4. MCP security rests on the fact that the protocol does not block attacks. The specification acknowledges the risks but does not enforce them, so responsibility for security shifts to the implementation layer, such as gateways and runtime trust verification. The answer to “Is MCP safe to use?” is that the protocol does not guarantee safety.

Rejected Claims (failed verification; do not cite)

Two claims were rejected during adversarial verification in the deep-research process. They are recorded here so they are not repeated.

  • “MCP architecture amplifies attack success by 23 to 41% (ASR 26.4% to 52.8%, 847 scenarios)”: rejected unanimously, with a vote of 0-3. The source (arXiv 2601.17549) was judged untrustworthy during verification. The figures are sensational but must not be used.
  • “MCP has IETF-style formal standardization, including RFC 2119 normative keywords”: rejected with a vote of 1-2. This overstates the level of standardization.

Sources

Accessed May 29, 2026. Based on output from the deep-research harness: 103 agents, 21 sources fetched, 102 claims extracted, 25 verified, and 23 confirmed.

Primary sources (vendor announcements and specifications)

Secondary sources (reference and cross-checking)

Untrustworthy source (rejected; do not cite)

Bottom line

The evidence supports a clear conclusion: MCP is now vendor-neutral infrastructure under the Linux Foundation, and A2A occupies a different layer, so the two protocols complement rather than compete. The adoption figures are real public claims but come from the vendors and foundation themselves, so they should be cited as official announcements, not independently audited data. On security, the specification openly acknowledges tool-poisoning risks but cannot enforce defenses at the protocol level. Anyone asking whether MCP is safe should be told that protection has to come from the implementation: gateways, runtime trust checks, and careful review of tool descriptions.

Frequently asked questions

Do MCP and A2A compete with each other?
No. The 2026 industry consensus treats them as complementary layers: MCP connects an agent to tools and context (vertical), while A2A connects agents to each other (horizontal). Both moved to Linux Foundation governance.
Does using MCP make an AI agent secure?
No. The MCP specification (2025-11-25) acknowledges that tools can execute arbitrary code and that tool descriptions should be untrusted unless they come from a trusted server, but it states that MCP cannot enforce these principles at the protocol level. Security must come from the implementation.