Welcome to the first edition of MCP for Business Weekly. Every week we round up what happened in the Model Context Protocol ecosystem and the surrounding AI-infrastructure world, and translate it into plain terms: what it means for your business, and what your IT or AI team should do about it. This first edition is a catch-up issue covering the biggest story of the summer.
The big story: the 2026-07-28 spec release changes the enterprise math
The MCP project shipped its 2026-07-28 specification, and it is the most business-relevant release in the protocol’s history. Three changes stand out:
1. A stateless protocol core. Earlier MCP deployments held long-lived sessions, which made them awkward to run behind ordinary load balancers and serverless platforms. The new stateless core scales on standard HTTP infrastructure.
For your business: the cost and complexity of running MCP servers in production just dropped. If your platform team previously vetoed MCP pilots on operational grounds (“we would need sticky sessions and special infrastructure”), that objection is now largely obsolete, and it is worth re-opening the conversation.
2. Enterprise-Managed Authorization is now stable. Organizations can centrally manage which MCP servers their users may access, and employees reach all connected servers through a single login. Anthropic, Microsoft and Okta are already on board.
For your business: this is the governance answer many compliance teams have been waiting for. Instead of every employee wiring AI tools to company systems ad hoc, IT can now hold a central allowlist with SSO on top. If shadow AI usage worries you, this extension is the concrete control to evaluate, and the vendors backing it mean it will show up in products you already buy.
3. Extensions for real work: MCP Apps and Tasks. The new extensions framework includes server-rendered interfaces (MCP Apps) and long-running work (Tasks), so an AI assistant can kick off a job that takes minutes or hours and report back.
For your business: Tasks moves MCP from “chat that looks things up” toward genuine back-office automation, the report that compiles itself overnight, the reconciliation that runs after close. Processes you ruled out as too slow for a chat interaction are back on the table.
One number worth quoting to your board from the release notes: the official MCP SDKs now see close to half a billion downloads a month. Whatever else is uncertain in AI, this protocol is not a niche experiment anymore.
Ecosystem moves
GitHub MCP Server 1.9.0 shipped on August 10, continuing a steady release cadence for the most widely deployed first-party corporate MCP server.
For your business: first-party servers from vendors like GitHub are the low-risk way to start with MCP: maintained by the vendor, aligned with their security model, and a useful benchmark to hold third-party servers against.
Migration watch
The new specification is a substantial revision, and teams that deployed MCP servers against the 2025 spec versions have real migration work ahead; community guides are already cataloguing what breaks and how to migrate.
For your business: if you built or bought MCP integrations in 2025, ask your team two questions this quarter: which spec version are we on, and what is our upgrade path? Budget the migration now rather than discovering it during an incident. If you are only starting with MCP, you are lucky: build directly against 2026-07-28.
Worth reading
The New Stack’s look at the MCP roadmap argues the protocol’s biggest production growing pains are on their way to being solved. A balanced read for anyone deciding whether MCP is mature enough to standardize on.
The takeaway
The theme of this issue is maturation: stateless scaling, enterprise SSO, and long-running tasks are exactly the features that move a protocol from developer curiosity to procurement checkbox. The window where “we are waiting for MCP to mature” was a defensible strategy is closing.
Back next Tuesday. If your team is wrestling with a question this digest should cover, tell us and we will dig into it.