Insights

AI & automationJuly 20266 min read

MCP, the standard that plugs AI into your tools

A year ago, plugging an AI into each of your tools meant a custom connection every single time. MCP changed the rule. Here is what a leader needs to understand about it, without a single line of technical detail.

By Nathan · guinat6 min read

You have probably come across the MCP acronym without anyone telling you what it actually changes for you. Here is the version that matters to a business leader, no jargon: what it is, why it lowers the cost when you want to connect AI to your existing tools, why it keeps you from being stuck with one vendor, and the one place where I ask you to stay alert. By the end, you will know exactly which questions to ask anyone who offers you this kind of project.

MCP, what is it, in one image?

Picture a universal socket. Before, every time I wanted an AI to talk to one of your tools, your CRM, your inbox, your accounting software, I had to build a custom cable. Ten tools, ten cables, and ten things to fix the day one of the two ends changes. MCP, for Model Context Protocol, is the standard socket that puts an end to that. It works like USB-C: you plug in once, and it works with whatever device sits at the other end.

In practice: your AI assistant reads a customer record in the CRM, opens a ticket in your support tool, checks a stock level in your inventory system, without anyone reinventing the wheel for each connection. The AI no longer just talks, it acts inside your existing software, with exactly the permissions you grant it, no more and no less.

Why does it lower your integration bill?

Because without a standard, the number of connections explodes. It is not the number of tools, but the number of AIs multiplied by the number of tools. Five tools and three use cases mean fifteen cables to build, test and maintain over time. Each update on one side can break the other. And it is that maintenance cost, not the initial build, that weighs the bill down over the long run.

With a standard like MCP, the logic flips. Each tool connects once, each AI connects once, and everything talks to everything. You move from a number of connections that multiplies to one that adds up. If you want the detail of what separates an MCP socket from a classic integration, I break it down in MCP vs API.

  • Without a standard: 5 tools × 3 AIs = 15 custom connections to maintain.
  • With MCP: 5 + 3 = 8 connections, each reusable by the others.
  • Every new tool adds one socket, not a stack of cables: the cost climbs gently instead of shooting up.

How does it keep you from being a prisoner of one vendor?

When your connections rely on an open standard, switching AI model or provider no longer forces you to redo everything. Your tool keeps its socket, you plug another AI in behind it. I have seen too many companies stuck because everything had been wired to fit one vendor: the day they wanted to leave, the exit cost had become a cage. With a standard, that cost collapses.

Another safeguard against passing fashions: MCP does not bet on a single camp. It is a neutral standard the main providers already follow, and it combines with the other building blocks on the market, such as coordination between several agents, instead of locking you in. The concrete result: you keep the freedom to choose your model on the only criterion that matters, quality at the right price, not because you are held captive.

A fad, or a standard that will last?

Fair question: are you just betting on the flavour of the month? Two facts make me answer no. First, adoption: in less than two years, Anthropic, OpenAI, Google and Microsoft all adopted MCP. When direct competitors converge on the same standard, it is rarely a flash in the pan. Second, governance: the protocol was handed to the Linux Foundation in late 2025, taken out of the hands of a single player to become a shared asset, the way the great web standards were before it. You are not betting on a company, you are adopting a norm.

Should you worry about security?

Yes, and this is the one place where I refuse to sell you a dream. Giving an AI a socket into your tools means giving it hands inside your system. Poorly framed, it is a real risk, and it is today the number one concern among companies, rightly so. Hundreds of these sockets have already been found left open on the internet, without so much as a password. And an open socket is the perfect way in for a prompt injection attack, where a booby-trapped piece of text pulls the AI away from its task.

The good news: these are risks you can control. Not with a miracle tool, with three rules I apply systematically, from the design stage and never after the fact.

  • Least privilege: the AI only accesses what it strictly needs, never the whole system for convenience.
  • A human in the loop on sensitive or irreversible actions: sending money, deleting, writing to a customer, all go through a validation.
  • No rogue socket: no connector plugged in on the side that nobody watches or logs.

How do you check it is done right, without being technical?

You do not need to understand the protocol. You need to ask three questions to anyone who offers to plug AI into your tools. The answers will tell you, in two minutes, whether you are dealing with a healthy project or a time bomb.

  • Does it rely on an open standard, so I am not locked into one vendor?
  • What exact permissions does the AI get, and who checked they are the bare minimum?
  • Which actions go through a human validation before they leave?

If the answers are clear and specific, you have a solid project. If they are vague, evasive, or pushed to later, that is the signal to stop. A good provider has these answers ready, because they are exactly the questions they already asked themselves.

An AI plugged into your tools without guardrails is not a productivity gain. It is an access to your company that nobody is watching.

So the real question is no longer whether to plug AI into your tools, but how to do it properly, with the right guardrails from the start. If you have a project like this in mind, or a connector already in place that you are not sure about, a first conversation is often enough to see clearly, with no commitment: let's talk.

Read next

Contact

Ready to go from demo to production?

Reply within 24 hours · first conversation free, no strings attached.