MCP servers, explained
The standard plug that lets any AI assistant reach your files, tools and data, and what you're trusting when you use one.
Jamie Owen Updated 26 Sept 2026 fast-moving: check a current source
Written against MCP protocol version 2026-07-28. Primitives have been deprecated between versions.
An MCP server is a small program that exposes something useful (your files, a database, an issue tracker) in a format any AI assistant can understand. The Model Context Protocol is the agreed format. Anthropic published it in November 2024 and handed it to the Linux Foundation’s Agentic AI Foundation in December 2025, and it lists ChatGPT, Gemini and Microsoft Copilot among the products that have adopted it.
Think of it as a USB-C port for AI applications: one shape of plug, many devices on either side. The current version of the specification is dated 28 July 2026, and as of 26 September nothing newer has replaced it.
The problem it solves
Before a shared protocol, every pairing of assistant and tool needed its own integration. Ten assistants and ten tools meant a hundred separate pieces of plumbing, each maintained by someone. A standard turns that multiplication into addition: write one server, and every assistant that speaks the protocol can use it.
What actually happens
Three parts, and the naming trips people up. The host is the application you actually use: Claude Desktop, VS Code, ChatGPT. The client is a connection the host creates, one per server, and you never touch it directly. The server is the program exposing the capability, and despite the name it usually runs on your own machine rather than somewhere remote.
A server can offer three kinds of thing. Tools are functions the model can call, like querying a database or filing a ticket. Resources are data it can read, like file contents. Prompts are reusable templates for common requests.
Local servers communicate over standard input and output; remote ones over HTTP, with OAuth for authorisation. The messages are JSON-RPC 2.0. When you connect one, the assistant asks what it offers, then decides for itself when something is relevant to what you asked.
What you are actually trusting
Every server you connect is code with real access, and a new route for prompt injection into whatever it can reach.
OWASP tracks a specific version of this called tool poisoning, and the gap it exploits is worth understanding. A server’s tool descriptions get inspected when you first connect. The responses those tools return go straight into the model’s context with no equivalent check. So a server can present harmlessly at setup and return hidden instructions later, once nobody is looking.
Connecting an MCP server is closer to installing a browser extension that can read your email than to adding a bookmark. Judge it on that basis.
The mitigations OWASP recommends are unglamorous and effective: connect only servers you have vetted, keep high-privilege tools out of reach of external ones, and require explicit confirmation before anything sensitive happens.
The protocol’s own maintainers are working on the identity side. Their August 2026 roadmap puts agent identity near the top, so that an agent can prove who it is “rather than pasted API keys and long-lived tokens”. Until that lands, a leaked key is as good as the agent it belonged to.
Where this leaves you
If you use an assistant that supports MCP, you probably already have servers connected. The useful first step is to find out which, and what each can reach. At work it may be arriving through Copilot: Copilot Studio lets colleagues add MCP servers to the agents they build, and since September 2026 Microsoft has offered to certify servers against its own checks for security and reliability, which is worth asking about before one is approved. For the wider picture of what happens once an assistant can act rather than answer, start with what people mean by AI agents.
Sources
Everything above was checked against these on 26 Sept 2026. Providers change things without notice. If a detail matters to a decision, follow the link.
- The 2026-07-28 Specification
- The New MCP Roadmap
- Model Context Protocol specification releases
- Introducing the Model Context Protocol
- Donating the Model Context Protocol and establishing the Agentic AI Foundation
- MCP tool poisoning
- New and improved: GitHub Copilot harness, agent skills, and richer context