What is MCP, and what does it mean for businesses?

01.09.26 08:00 AM

Artificial intelligence has become considerably more capable over the past few years, but there is still a fairly fundamental limitation to the way most businesses use it. An AI assistant might be able to analyse a document, write an email or answer a complicated question, but it usually has very little awareness of what is actually happening across the organisation using it.

The useful information is somewhere else. Customer relationships and sales activity might be held in a CRM, financial information in an accounting platform, ongoing work in a project management system and company knowledge across documents, emails and other applications. Unless that information is deliberately provided to the AI, it has little or no context from which to work.

Model Context Protocol, or MCP, is one of the technologies attempting to solve that problem. It provides a standard way for AI applications to connect to external systems and use the information and capabilities available within them. While the name makes it sound like something primarily of interest to developers, its wider implications are much more relevant to businesses.

MCP could help change AI from a tool that sits alongside business software into something capable of actually working across it.

What is MCP?

MCP is an open standard for connecting AI applications to external data sources and tools. It was originally introduced by Anthropic in 2024 and has subsequently developed into a broader industry standard, with support emerging across many of the companies building AI models, development tools and business applications.

One of the easiest comparisons is USB. Computers can interact with thousands of different devices because manufacturers have agreed on common standards for connecting them. A keyboard manufacturer does not need to design a completely different connection for every make of computer, and computer manufacturers do not need to develop proprietary connections for every possible peripheral.

MCP attempts to introduce a similar principle to AI integrations.

An application can make information and functionality available through an MCP server, while an AI application capable of using MCP can connect to that server and discover what is available. Rather than developing an entirely bespoke connection between every AI product and every business application, MCP provides a common language through which those connections can be made.

It is important not to confuse this with MCP replacing APIs. In many cases, an MCP server will itself use an application's existing API. MCP instead provides a standardised layer that makes those capabilities understandable and usable by AI systems.

How does MCP actually work?

At a basic level, an MCP connection involves an AI application acting as a client and an MCP server exposing information or capabilities that the AI can use. The server effectively tells the AI what it has access to and how those capabilities can be used.

Imagine, for example, that an organisation connects its CRM to an AI assistant through MCP. Rather than exporting sales data into a spreadsheet and uploading it to ChatGPT or another AI tool, someone could simply ask which opportunities have not been contacted during the past fortnight. The AI could retrieve the appropriate records from the CRM and produce an answer based on live information.

The more significant change comes when the AI is allowed to perform actions as well as retrieve information. Having identified those neglected opportunities, the user might ask the AI to create follow-up tasks for each account owner. Provided the relevant tools and permissions have been made available, the AI could carry out the request in the CRM rather than merely explaining how the user should do it.

This distinction between retrieving information and performing actions is central to understanding why MCP is attracting so much attention. Connecting AI to business systems is useful because it gives the model better context, but connecting it to the functions within those systems opens up the possibility of AI becoming an active participant in business processes.

    diagram of how mcp works
    How MCP connects AI with business systems, allowing it to securely access information, use available tools and take authorised actions across different applications.

    From answering questions to completing work

    Most business use of generative AI still revolves around producing something for a person. An employee asks for an email, summary, report, calculation or piece of analysis, receives an answer and then decides what to do with it.

    That model is already useful, but it leaves the employee responsible for moving between the AI and the applications where the work actually happens. If an AI assistant identifies that ten sales opportunities require attention, somebody still has to open the CRM, find those records and create the necessary tasks.

    MCP is part of a broader move towards AI agents, where the objective is not simply to generate an answer but to allow AI systems to use tools in order to complete a task. Once an AI can securely access the systems a business already uses, the range of useful tasks becomes considerably wider.

    Consider a fairly ordinary request such as asking an AI assistant for an update on a particular customer. A useful answer might require information from several places. The CRM contains the customer's sales history and current opportunities, the finance system contains invoices and payment information, the support platform contains outstanding issues and the project management system shows the progress of ongoing work.

    Today, an account manager might open each of those applications and piece together the information manually. With appropriate MCP connections, an AI agent could potentially retrieve the relevant information from each system and produce a single account summary.

    The employee could then ask it to create a task for an overdue sales follow-up, prepare an email regarding an outstanding invoice or summarise an unresolved support issue. Rather than AI being another application that needs to be checked, it starts to become a way of interacting with the applications the business already has.

    But haven't we been connecting applications for years?

    None of this means that integrations are new. Businesses have been connecting applications through APIs, webhooks and integration platforms for a long time, and those technologies will continue to be important.

    The difference is largely in how the integration is used.

    A traditional automation is normally designed around a predefined process. When an opportunity reaches a particular stage in the CRM, create a project. When an invoice is paid, update another record. When a form is submitted, send the information to another application. The trigger, action and expected outcome are defined in advance.

    An AI agent can be much less rigid. A person can describe an objective in normal language, after which the AI can determine which available tools it needs in order to complete the request. Depending on the task, that might involve retrieving information from one system, comparing it with information from another and then performing an action somewhere else.

    MCP helps make this possible by giving the AI a consistent way to discover what tools and information are available. It does not eliminate the underlying integrations, but it can make them accessible to AI in a much more flexible way.

    diagram of legacy integrations vs mcp
    Traditional integrations require separate connections between AI applications and business systems, increasing development and maintenance costs as the environment grows. MCP provides a common integration standard, making it easier and potentially cheaper to connect multiple AI applications with the same business systems.

    Why does having a standard matter?

    Without a common standard, connecting AI applications to business software quickly becomes complicated. An integration built between one AI assistant and a CRM might be completely different from the integration required by another AI assistant. Multiply that across accounting, support, project management, document storage and internal systems, and organisations end up maintaining a growing collection of proprietary connections.

    A widely adopted protocol changes that model. Software providers and developers can expose capabilities through MCP, while AI applications can implement support for the same protocol. It does not mean that every AI application automatically gains access to every business system, nor does it remove the need for authentication and configuration, but it provides a common foundation on which those connections can be built.

    This is arguably one of the reasons MCP matters more than many of the individual AI features being released at the moment. Features come and go relatively quickly, whereas standards can become part of the underlying infrastructure that allows an ecosystem to develop.

    What could MCP actually mean for a business?

    The immediate opportunity is better access to information. AI is considerably more useful when it can work with accurate organisational context rather than relying entirely on information pasted into a conversation.

    A sales manager could ask questions about the live pipeline without first preparing a report. A finance team could investigate transactions without exporting data into spreadsheets. A project manager could ask which projects are at risk based on deadlines, tasks and recent activity. A support manager could identify recurring customer issues by allowing an AI system to analyse ticket information directly.

    However, the larger opportunity is the ability to act on what the AI discovers. Depending on the systems connected and the permissions granted, an agent could create or update CRM records, generate tasks, prepare documents, organise information, update projects or initiate established business processes.

    That does not necessarily mean handing entire departments over to autonomous agents. In many businesses, the most useful applications are likely to be much less dramatic. Removing ten minutes of repetitive administration from a process that happens hundreds of times a month can have considerably more practical value than building an impressive AI demonstration that nobody trusts enough to use.

    diagram of real world example connection
    A practical example of MCP in action: an AI agent securely retrieves information from multiple business systems, combines it into useful context and can then carry out authorised actions, all from a single request.

    AI could change how we interact with business software

    There is also a longer-term implication that is easy to overlook. For decades, software has largely been designed around graphical interfaces. If somebody wants to update an opportunity, they log into the CRM, navigate to the appropriate record, find the correct field, make the change and save it.

    An AI agent with access to the same system introduces another interface. Instead of navigating through the application, someone might ask it to move an opportunity to the negotiation stage, add a note explaining that legal approval is outstanding and create a reminder to follow up next Tuesday.

    The CRM has not disappeared. It still stores the information, controls the business logic and provides the underlying functionality. What has changed is the way the employee interacts with it.

    If that becomes commonplace, the characteristics businesses value in software may also begin to change. A polished user interface will remain important, but so will the accessibility and structure of the data underneath it. Applications with comprehensive APIs, well-designed permissions and good interoperability become particularly valuable when people are no longer the only users interacting with them directly.

    In that environment, the quality of a company's underlying systems may matter more than the particular AI model it chooses to put in front of them.

    Security and permissions become much more important

    There is an obvious consequence to giving AI systems access to business applications. An AI that can retrieve information from a CRM represents one level of risk; an AI that can modify or delete information represents another.

    MCP does not remove the need for conventional security controls. Organisations still need to consider authentication, permissions, data access, audit logs and which actions should require approval. The fact that an AI agent is performing an action rather than an employee does not make those controls any less important.

    In practice, businesses are likely to adopt these capabilities gradually. An AI system might initially receive read-only access to particular information, followed by permission to perform a limited set of low-risk actions. More consequential changes could continue to require explicit human approval.

    The objective should not be to give an AI access to everything simply because it is technically possible. It should be to give it the minimum information and functionality required to perform a useful task safely.

    AI won't fix poor systems

    MCP also highlights something that is sometimes lost in discussions about AI transformation: connecting an intelligent model to poor-quality business data does not suddenly produce a good business system.

    If a CRM contains duplicate records, inconsistent information and badly designed processes, an AI agent will have to work with those same problems. If nobody knows which system contains the authoritative version of a customer's information, providing an AI with access to all of them may create more ambiguity rather than less.

    Businesses that have invested in structured data, documented processes, sensible permissions and properly connected systems are therefore likely to be in a much better position to benefit from AI agents.

    This is one reason we think the discussion around AI needs to extend beyond simply choosing an AI product. The underlying systems still matter. In fact, as AI becomes capable of doing more with them, they may matter even more.

    diagram of data quality differences when it comes to using mcp
    MCP can give AI access to your business systems, but the quality of its output still depends on the quality of the data it finds. Clean, consistent and well-structured data leads to more reliable insights, better decisions and safer automation.

    What should businesses be doing about MCP now?

    For most businesses, the answer is not to start building MCP servers for every application tomorrow. The technology and the wider ecosystem are still developing quickly, and there is little value in adopting a protocol simply for the sake of being early.

    There is, however, a good reason to start considering how ready your organisation is for this type of technology.

    When evaluating software, businesses should increasingly consider how accessible their data is, whether the application has a comprehensive API, how granular its permissions are and how easily it can interact with other systems. Internally, it is worth identifying processes that involve employees repeatedly finding information, copying it between applications or carrying out predictable administrative actions.

    Those processes are likely to be some of the strongest candidates for useful AI automation as the technology matures.

    More importantly, businesses should continue improving the quality and structure of their underlying systems. Whether MCP ultimately becomes the dominant standard or is eventually replaced by something else, AI systems are clearly moving towards greater access to external tools and organisational data. Businesses with well-organised systems will be in a much stronger position to take advantage of that change.

    The important part isn't really MCP

    MCP is ultimately a technical standard, and most employees will probably never need to know whether they are using it. In much the same way that somebody does not need to understand the protocols behind the web to use a website, the technical details should eventually disappear behind the applications people use every day.

    What matters is the change it represents.

    Until now, much of the value of generative AI has come from what a model already knows and whatever information a user provides during a conversation. The next stage is increasingly about giving AI controlled access to the information and tools that already exist within organisations.

    If that develops in the way many technology companies expect, the role of AI within businesses could change substantially. Rather than being another piece of software employees open when they need help writing or analysing something, AI could become a layer through which employees interact with much of their existing technology.

    At that point, the most important question for a business will no longer be simply which AI model it wants to use. It will be whether its systems, data and processes are in good enough shape for AI to work with them.

    Contact

    Get in touch with the team to discuss how we support your business with practical, people-first technology and long-term solutions.

    About

    Learn who we are, what we stand for, and how Ostratto helps businesses make their work, less work through practical technology solutions.

    Our Approach

    Discover how we partner with you - focusing on strategy, simplicity and long-term value to deliver technology that truly supports your business.