MCP was always a bad idea?
Reframes MCP not as outdated but as strategically refocused toward governance, safety, and operational control — positioning its continued relevance as a responsible evolution rather than a defensive holdover.
View original on simonwillison.netOverview
The article defends the Model Context Protocol (MCP) as a valuable architectural layer for controlling, securing, and auditing AI agent interactions with external services — countering claims that it is obsolete in light of advanced terminal agents.
TL;DR
- MCP is positioned not as obsolete but as essential for constrained, auditable, and secure agent deployments.
- It enables fine-grained service access control, API key isolation, user-facing auth UIs, and audit logging — capabilities full terminal agents bypass.
- The argument distinguishes between 'YOLO' internet-enabled coding agents and production-grade, governed agent systems where MCP adds critical guardrails.
Key Stats
N/A
adoption metrics
No usage numbers, deployment scale, or adoption data provided
Questions Answered
Narrative Frame
strategic reset
Spin Score
65%
Emphasizes MCP’s utility in constrained environments while minimizing evidence of actual adoption, standardization progress, or integration maturity; minimizes trade-offs like added latency, fragmentation risk, or developer overhead.
What the story wants you to believe
That MCP is not obsolete but is instead the appropriate, responsible foundation for building secure, controllable, and auditable AI agent systems — especially outside experimental terminal contexts.
What it makes harder to question
Whether MCP’s design actually delivers on its governance promises in practice, or whether it introduces new complexity without commensurate security or operational benefits.
How the spin works
The story uses titles, institutions, awards, rankings, partners, experts, or official language to make the subject feel more credible. Watch for loaded terms such as YOLO, less YOLO, sensible UI, strong audit logging. The distribution reads as editorial reporting. A pressure point: No mention of competing standards (e.g., LangChain Tools, OpenAPI-based agent interfaces), no reference to implementation complexity or runtime overhead, no discussion of vendor lock-in concerns.
Who Benefits If This Frame Spreads
MCP specification authors
Enhanced credibility and perceived necessity in developer tooling conversations
Framing MCP as indispensable for security and governance makes its continued development appear mission-critical rather than optional
The Frame
MCP as an enabling infrastructure for responsible, enterprise-ready AI agent deployment.
Missing Context
- No mention of competing standards (e.g., LangChain Tools, OpenAPI-based agent interfaces), no reference to implementation complexity or runtime overhead, no discussion of vendor lock-in concerns
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article treats MCP not as a fading idea but as a mature response to real-world needs — reframing criticism as missing the point rather than identifying a flaw. It positions MCP’s value as self
- Claim
MCP makes it easier to provide control over which external
MCP makes it easier to provide control over which external services an AI agent can access, handle authentication without exposing API keys, offer a sensible UI for user service connections, and enable strong audit logging.
- Frame
MCP as an enabling infrastructure for responsible
MCP as an enabling infrastructure for responsible, enterprise-ready AI agent deployment.
- Beneficiary
Enhanced credibility and perceived necessity in developer tooling conversations
MCP specification authors — Enhanced credibility and perceived necessity in developer tooling conversations
- Gap
No mention of competing standards (e.g., LangChain Tools, OpenAPI-based agent
No mention of competing standards (e.g., LangChain Tools, OpenAPI-based agent interfaces), no reference to implementation complexity or runtime overhead, no discussion of vendor lock-in concerns
- AI Risk
AI may repeat the headline as fact
MCP remains valuable for secure, auditable AI agent deployments — especially where direct API access is too risky.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| MCP makes it easier to provide control over which external services an AI agent can access, handle authentication without exposing API keys, offer a sensible UI for user service connections, and enable strong audit logging. | Conceptual justification only — no code examples, architecture diagrams, or integration case studies. | Claim Present in Source | Moderate | Publicly documented deployments using MCP for auth isolation; Benchmark comparing audit log fidelity with vs. without MCP; UI component libraries built on MCP |
MCP makes it easier to provide control over which external services an AI agent can access, handle authentication without exposing API keys, offer a sensible UI for user service connections, and enable strong audit logging.
evidence: Conceptual justification only — no code examples, architecture diagrams, or integration case studies.
"MCP makes all of that so much easier to provide. Thinking MCP is obsolete because full coding agents don't need it misses out on all of the other things we might want to build."
Evidence Gaps
- Publicly documented deployments using MCP for auth isolation
- Benchmark comparing audit log fidelity with vs. without MCP
- UI component libraries built on MCP
Fact Check Signals
0 of 1 claim matched · confidence: low · checked September 22, 2026
MCP makes it easier to provide control over which external services an AI agent can access, handle authentication without exposing API keys, offer a sensible UI for user service connections, and enable strong audit logging.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
MCP was always a bad idea?
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
Simon Willison's Weblog · Analyst
Counter-Frames
Brand Frame
MCP as an enabling infrastructure for responsible, enterprise-ready AI agent deployment.
Media / Reader Counter-Frame
Portrays MCP as a fragmented, under-specified protocol gaining traction only among niche advocates — not a de facto standard.
Regulatory Counter-Frame
Highlights absence of formal security validation, third-party audits, or alignment with NIST AI RMF controls — questioning whether MCP meaningfully reduces attack surface.
AI Summary Frame
Omits context that most production agents today use custom wrappers or lightweight adapters, making MCP’s abstraction layer redundant for many use cases.
Missing Voices
Questions Not Answered
- Which real-world systems currently implement MCP in production?
- What measurable security or operational improvements have been observed with MCP vs. ad-hoc integrations?
- Are there interoperability benchmarks or compatibility tests across major agent frameworks?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
38
Trigger score 15
Triggered by: Major AI entity
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"MCP remains valuable for secure, auditable AI agent deployments — especially where direct API access is too risky."
Concern: AI may drop the crucial nuance that this is a contested, unproven architectural stance — presenting MCP’s value as settled fact rather than a reasoned but unvalidated position.
-
Published
Sep 20, 2026
-
Ingested
Sep 22, 2026
-
SpinGraph Created
Sep 22, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_mcp_was_always_a_bad_idea_muc9weq8
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from Simon Willison's Weblog
View all →Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO