MCP Ecosystem in 2026: How the Protocol Moved to Shared Industry Infrastructure
Who this is forDevelopers, architects, and content creators who need an accurate picture of how MCP and A2A relate and how far the adoption and security claims can be trusted.
Introduction
The Model Context Protocol (MCP) went from a single-vendor specification to shared industry infrastructure in less than a year. That change matters for anyone choosing an agent stack, writing about it, or deciding how much to trust the adoption numbers that circulate. Readers searching for “MCP vs A2A” or “is MCP a standard” often get a framing of rival protocols that the evidence no longer supports. This article reconstructs the state of the MCP ecosystem as of May 2026: how governance changed, how the protocol relates to Google’s Agent2Agent (A2A) protocol, which adoption figures are self-reported, and what the specification does and does not guarantee about security. You will get a summary you can cite accurately, with sources listed at the end.
Summary
MCP moved between mid-2025 and May 2026 from an Anthropic-led single-vendor standard to a vendor-neutral infrastructure project under the Linux Foundation. During the same period, the industry consensus around Google’s A2A settled on complementarity rather than competition: MCP handles vertical agent-to-tool connections, and A2A handles horizontal agent-to-agent connections.
Architecture Overview
The relationship between the two protocols is easiest to see as layers. MCP sits vertically, connecting an agent to tools and context. A2A sits horizontally, letting agents discover and collaborate with other agents through Agent Cards. Both are now governed under the Linux Foundation, which is the main reason the “protocol war” framing no longer fits.

Key Data
1. Adoption Scale (as of December 2025)
- More than 10,000 active public MCP servers and more than 97 million monthly SDK downloads. Source: official announcements from Anthropic and the MCP project. These are vendor self-reported figures with no third-party audit.
- MCP Registry (registry.modelcontextprotocol.io): launched as a preview on September 8, 2025, with roughly 2,000 entries by November. The “407% growth” figure is measured from the initial batch onboarded in September, not from the September announcement date.
- First-class client support in major platforms: ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and VS Code.
2. Vendor Adoption (executive statements cross-checked against vendor documentation)
| Vendor | MCP-enabled products |
|---|---|
| OpenAI | ChatGPT (Developer Mode, Apps SDK), Responses API, Agents SDK, Codex |
| Gemini models, Gemini CLI, open-source MCP servers for Google Maps and Cloud databases | |
| AWS | Bedrock, AgentCore, Kiro, Strands, Quick Suite |
| Microsoft | Copilot Studio (MCP generally available) |
3. Standardization and Governance
- December 9, 2025: Anthropic donated MCP to the Agentic AI Foundation (AAIF), a new directed fund under the Linux Foundation. Anthropic, Block, and OpenAI co-founded AAIF. The eight Platinum members are AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI.
- MCP Registry governance: a registry working group that includes Anthropic, PulseMCP, GitHub, and Stacklok, with at least 16 contributors from nine or more companies.
- GitHub frames the move as joining “established open infrastructure” alongside Kubernetes, SPDX, GraphQL, and CNCF. This is GitHub’s framing, not an objective claim of equivalence.
4. Competing and Complementary Protocols: A2A
- April 2025: Google first announced Agent2Agent (A2A). June 23, 2025 (Open Source Summit North America): Google donated the specification, SDKs, and tooling to the Linux Foundation, launching the Agent2Agent project.
- A2A participants include AWS, Cisco (Outshift), Salesforce, SAP, Microsoft, and ServiceNow, plus more than 100 other companies that later grew to more than 150.
- Positioning: A2A is horizontal (agent-to-agent discovery and collaboration via Agent Cards), and MCP is vertical (agent-to-tool and agent-to-context). Google’s official documentation states that “A2A complements Anthropic’s MCP.” The Agent Communication Protocol (ACP) merged into A2A in September 2025. Even articles titled “Protocol Wars” conclude that the two are complementary.
5. Security (confidence: medium)
- The MCP specification (2025-11-25) has a “Tool Safety” section. It states that tools can perform arbitrary code execution and that tool descriptions and annotations should be treated as untrusted unless they come from a trusted server. This directly acknowledges the attack surface for tool poisoning and similar attacks.
- However, the specification also states that MCP cannot enforce these security principles at the protocol level. The acknowledgment is a recommendation, not a defense mechanism. Trusted-server rug pulls, such as the runtime trust gap illustrated by CVE-2025-54136, are not covered.
Insights
-
The “standards war” framing is wrong. As of May 2026, the industry consensus is that MCP (vertical) and A2A (horizontal) are complementary layers that operate at different levels. Both went to the Linux Foundation, MCP through AAIF in December 2025 and A2A in June 2025, and competing vendors such as Google, OpenAI, AWS, and Microsoft participate in both governance bodies. Content asking “which of MCP and A2A wins” is working from an outdated angle.
-
The shift from single vendor to neutral infrastructure is the key event. Anthropic handed its own invention to the Linux Foundation. This resembles giving up control in exchange for trust in the standard, but the project keeps its governance autonomy; it was not abandoned. The pattern resembles the path Kubernetes took from Google to CNCF.
-
Always flag adoption metrics as self-reported. The 10,000 servers and 97 million downloads come from the foundation and vendor themselves. When you cite them, state that they are based on official announcements so that readers can judge the data for themselves.
-
MCP security rests on the fact that the protocol does not block attacks. The specification acknowledges the risks but does not enforce them, so responsibility for security shifts to the implementation layer, such as gateways and runtime trust verification. The answer to “Is MCP safe to use?” is that the protocol does not guarantee safety.
Rejected Claims (failed verification; do not cite)
Two claims were rejected during adversarial verification in the deep-research process. They are recorded here so they are not repeated.
- “MCP architecture amplifies attack success by 23 to 41% (ASR 26.4% to 52.8%, 847 scenarios)”: rejected unanimously, with a vote of 0-3. The source (arXiv 2601.17549) was judged untrustworthy during verification. The figures are sensational but must not be used.
- “MCP has IETF-style formal standardization, including RFC 2119 normative keywords”: rejected with a vote of 1-2. This overstates the level of standardization.
Sources
Accessed May 29, 2026. Based on output from the deep-research harness: 103 agents, 21 sources fetched, 102 claims extracted, 25 verified, and 23 confirmed.
Primary sources (vendor announcements and specifications)
- Anthropic, Donating MCP and establishing AAIF (December 9, 2025): https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation
- MCP official blog, MCP joins AAIF (December 9, 2025): https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/
- MCP official blog, First MCP Anniversary (November 25, 2025): https://blog.modelcontextprotocol.io/posts/2025-11-25-first-mcp-anniversary/
- MCP official blog, Registry Preview (September 8, 2025): https://blog.modelcontextprotocol.io/posts/2025-09-08-mcp-registry-preview/
- MCP specification (2025-11-25): https://modelcontextprotocol.io/specification/2025-11-25
- OpenAI, Agentic AI Foundation: https://openai.com/index/agentic-ai-foundation/
- OpenAI Developer Docs, MCP: https://developers.openai.com/api/docs/mcp
- Google Developers Blog, A2A: a new era of agent interoperability (April 9, 2025): https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/
- Google Developers Blog, Google Cloud donates A2A to Linux Foundation (June 23, 2025): https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/
- Linux Foundation, AAIF formation press release: https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation
- Linux Foundation, A2A Protocol Project launch press release: https://www.linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents
- GitHub Blog, MCP joins the Linux Foundation: https://github.blog/open-source/maintainers/mcp-joins-the-linux-foundation-what-this-means-for-developers-building-the-next-era-of-ai-tools-and-agents/
- AWS Docs, Bedrock AgentCore Runtime MCP: https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-mcp.html
- AWS Docs, Quick Suite MCP integration: https://docs.aws.amazon.com/quicksuite/latest/userguide/mcp-integration.html
- Google Gemini CLI, MCP server docs: https://github.com/google-gemini/gemini-cli/blob/main/docs/tools/mcp-server.md
- MCP Registry GitHub: https://github.com/modelcontextprotocol/registry
- A2A and MCP relationship, official documentation: https://a2a-protocol.org/latest/topics/a2a-and-mcp/
Secondary sources (reference and cross-checking)
- Wikipedia, Model Context Protocol: https://en.wikipedia.org/wiki/Model_Context_Protocol
- arXiv 2505.02279 (survey of agent protocols): https://arxiv.org/abs/2505.02279
Untrustworthy source (rejected; do not cite)
- arXiv 2601.17549 (claim of 23 to 41% amplification of MCP attack success): judged untrustworthy during verification: https://arxiv.org/pdf/2601.17549
Bottom line
The evidence supports a clear conclusion: MCP is now vendor-neutral infrastructure under the Linux Foundation, and A2A occupies a different layer, so the two protocols complement rather than compete. The adoption figures are real public claims but come from the vendors and foundation themselves, so they should be cited as official announcements, not independently audited data. On security, the specification openly acknowledges tool-poisoning risks but cannot enforce defenses at the protocol level. Anyone asking whether MCP is safe should be told that protection has to come from the implementation: gateways, runtime trust checks, and careful review of tool descriptions.
Frequently asked questions
- Do MCP and A2A compete with each other?
- No. The 2026 industry consensus treats them as complementary layers: MCP connects an agent to tools and context (vertical), while A2A connects agents to each other (horizontal). Both moved to Linux Foundation governance.
- Does using MCP make an AI agent secure?
- No. The MCP specification (2025-11-25) acknowledges that tools can execute arbitrary code and that tool descriptions should be untrusted unless they come from a trusted server, but it states that MCP cannot enforce these principles at the protocol level. Security must come from the implementation.
BuildnWrite helps teams build AI agents that keep running. About BuildnWrite ›