Is MCP secure by default?
No. MCP provides protocol mechanisms that can support a secure design, including structured capabilities and an authorisation framework. Security still depends on deployment boundaries, identity, credentials, source-system permissions, validation, approval and operations.
Does MCP replace APIs or integration platforms?
No. An MCP server usually sits above APIs, databases or platform services and presents selected capabilities to an AI client. Conventional APIs, events and workflow engines remain appropriate where discovery by AI clients is not the requirement.
Is OAuth authorisation sufficient for a production MCP service?
No. OAuth can establish and constrain access to a protected resource. It does not decide whether a specific invoice, deployment, message or record change is permitted under business policy. That decision must be enforced at the capability and source-system layers.
Can tool annotations be used as a safety control?
Not on their own. The MCP project describes annotations as hints supplied by a server, not a security boundary. Clients may use them to improve handling, but enforcement must rely on trusted policy and the behaviour of the underlying operation.
When should an MCP action require human approval?
Approval is appropriate when a wrong action would create material financial, legal, operational, privacy or external-communication consequences and automated controls cannot reduce that consequence sufficiently. Approval should show the exact action and parameters, not a generic permission prompt.
Should one MCP server expose an entire business system?
Usually not. Boundaries should follow ownership, sensitivity and failure impact. A smaller set of purpose-built capabilities is easier to permission, test, monitor and retire than a generic interface with broad source-system access.
When is MCP the wrong choice?
It may be unnecessary for a stable one-to-one integration, a tightly deterministic workflow or a use case where no AI client needs capability discovery. Protocol adoption should follow an operating requirement, not precede one.
How does MCP relate to AI Adoption, AI Enablement and AI Agents?
AI Adoption selects valuable priorities, decision owners and working rules. AI Enablement prepares identity, data, platforms and controls. AI Agents use governed capabilities to perform work. MCP can be one interface between those agents and enterprise systems; it is not a substitute for any of the three disciplines.