Machine intelligence · Agentic AI · Governed swarm management

Machine Intelligence Field Note

MCP Is Not an Agentic Control Plane

MCP is an important interoperability protocol. Calling it the entire agentic control plane hides the responsibilities that determine whether connected tools can be used safely, economically, accountably, and recoverably.

EnterpriseGovernmentPartners

Published Updated Reviewed By LongTermIntelligence.com

Direct answer

Why is MCP not a complete agentic control plane?

#

MCP standardizes communication between model applications and contextual servers. A control plane must additionally govern identity, authorization, tool policy, budgets, model routing, state, evaluation, human authority, telemetry, incidents, recovery, and change. MCP can carry some relevant interactions, but it does not make those organizational and architectural decisions.

  • Keep protocol and policy responsibilities separate.
  • Treat every MCP server as a dependency and trust boundary.
  • Do not infer safe execution from a successful protocol exchange.

Source basis: reviewed official references are listed on this page and in the source ledger. Interpretation and implementation guidance retain the stated assurance boundary.

Page role

Use this Field Note for the architecture decision

This article is an editorial thesis about responsibility boundaries. It assumes MCP can work correctly and then asks which identity, policy, authority, evaluation, cost, state, incident, and recovery decisions still need a control plane.

  • Use it to challenge an architecture that equates connectivity with governance.
  • Send specification and implementation questions to the standards guide.
  • Record each remaining responsibility in an architecture decision record.

Editorial thesis

Interoperability is necessary—and insufficient

An enterprise agent needs a stable way to discover context and capabilities. MCP is valuable because it reduces bespoke connection logic and gives hosts, clients, and servers a shared contract.

The protocol cannot decide whether a payment should be made, which model may see regulated data, whether a tool call exceeds delegated authority, whether a trace should retain content, or when an incident requires shutdown. Those decisions belong to the operating architecture and accountable organization.

The design test is straightforward: if every MCP connection succeeds exactly as specified, can the system still overspend, leak data, misuse a legitimate tool, poison memory, mislead a reviewer, or cascade a false assumption? If yes, the missing controls sit outside protocol correctness.

Boundary test

What remains after MCP works correctly

Successful messages are not the same as authorized, correct, or valuable outcomes.

ResponsibilityRequired decision
IdentityWhich agent, person, task, tenant, and environment is acting?
AuthorizationWhich resource or tool is allowed for this exact task and consequence?
AuthorityWhich actions may execute automatically, and which require named human approval?
EvaluationWhat evidence shows the proposed output or action meets task, safety, and policy thresholds?
CostWhat budgets, rate limits, model routing, and loop controls apply?
State and memoryWhat may persist, who may read or write it, and how is provenance preserved?
ObservabilityWhich events, decisions, versions, and content may be captured and retained?
RecoveryHow are retries, duplicates, partial side effects, rollback, isolation, and shutdown handled?

Primary-source basis

Official source ledger

Each record includes publisher, source type, status, reviewed date, summary, and use boundary.

Model Context Protocol · Official Protocol Specification

Model Context Protocol Specification — 2026-07-28

The reviewed MCP specification defines an open protocol for connecting language-model applications with contextual resources, prompts, and tools through host, client, and server roles.

Status
Current Reviewed Version
Published
2026-07-28
Reviewed
2026-08-01

Use boundary: MCP is an interoperability protocol, not a complete agentic control plane, governance program, or security guarantee.

Open official source

Model Context Protocol · Official Protocol Guide

Model Context Protocol architecture

Official architectural orientation for MCP components and message flows.

Status
Current
Reviewed
2026-08-01

Use boundary: Treat implementation and security controls as separate design responsibilities.

Open official source

OWASP GenAI Security Project · Official Security Taxonomy

OWASP Top 10 for Agentic Applications

A community-developed taxonomy covering ten major agentic application risk areas, from goal hijacking and tool misuse through memory poisoning, cascading failures, and rogue agents.

Status
Current
Published
2025-12-09
Reviewed
2026-08-01

Use boundary: Use as a threat-oriented taxonomy and mitigation aid, not as a certification or guarantee of security.

Open official source

Official-source citations establish provenance and scope. They do not establish LongTermIntelligence.com certification, endorsement, legal advice, client outcomes, or a guarantee that a control is effective.

Architecture review

Separate protocol success from operating assurance

Bring one MCP connection, tool boundary, identity design, or authority decision to a focused architecture review.

Private local search

Find machine intelligence, agentic AI, swarm management, services, industries, use cases, definitions, or research

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.