Artificial Intelligence

MCP: How AI starts talking to your company’s data

AI assistant connected to multiple enterprise data sources through Model Context Protocol (MCP), including databases, analytics dashboards, customer service systems, social media, documents, and cloud platforms.

Learn how Model Context Protocol, or MCP, connects generative AI to enterprise data, improves access to business insights, and introduces new governance and security considerations.

An open standard designed to connect generative AI to enterprise systems is changing who within companies can ask questions of their data and how quickly they can get answers.

It is Monday at 9 a.m. The marketing director wants to understand whether the rise in complaints about the company’s app on social media coincides with a decline in customer service ratings. The social monitoring platform shows one part of the story, while the customer service system shows another. Connecting the two usually means submitting a request to the data team, waiting in a queue, and receiving a report days later. Sometimes, by the time it arrives, the urgent meeting that needed the information has already happened.

That gap between a question and an answer is one of the less visible costs of data driven management. And it is precisely the kind of gap that a technical standard still relatively unknown outside technology teams can help reduce: MCP, short for Model Context Protocol.

A company installs an MCP server that exposes data and system actions in a standardized way. An AI assistant connects to that server and, when connected to multiple servers at the same time, can query different sources and combine the information within the conversation itself.

A common standard for connecting generative AI to business systems

Launched by Anthropic in November 2024, MCP is an open protocol that defines a standardized way to connect AI models to external systems such as databases, marketing platforms, and internal business applications. Before MCP, each integration was essentially a custom project.

Anthropic itself compares MCP to USB C. In the past, every device had its own charger. Today, a single cable can work across phones, laptops, and headphones.

For Brazilian readers, there is an even more familiar comparison: Pix. Before Pix, transferring money between banks involved different rules, processing times, and fees. With a common standard, any application could communicate with any participating bank almost instantly. MCP does something similar for AI, with one important distinction. Pix has a regulator that mandates and certifies participation. MCP, by contrast, is an open specification adopted voluntarily, and each tool may implement different parts of it using its own authentication models. The benefit, therefore, is not the elimination of integration work, but a significant reduction in duplicated effort.

According to Anthropic, adoption has been rapid. By December 2025, the ecosystem already included more than 10,000 active public MCP servers, and the protocol had been adopted by products including ChatGPT, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code.

In December of that year, Anthropic donated MCP to the Agentic AI Foundation, an initiative associated with the Linux Foundation and co founded by Anthropic, Block, and OpenAI, with support from Google, Microsoft, AWS, Cloudflare, and Bloomberg.

For technology decision makers, that shift matters. The standard is no longer controlled by a single vendor.

What MCP changes for businesses

The first impact is greater autonomy.

With MCP servers exposing data from a social listening platform and a customer service system, the marketing director from our example can ask the AI assistant directly whether the increase in complaints about the app coincides with a decline in customer service ratings.

The AI can query both sources, combine the information, and provide an answer in natural language. The director can then ask for a chart or an executive summary for senior leadership within the same conversation.

The second impact is greater efficiency for technical teams.

Data teams may spend less time responding to repetitive reporting requests and more time building and maintaining connections, defining what information can be accessed and determining who can access it.

The work shifts from repeatedly extracting reports to managing and curating access.

The third impact is strategic: less vendor dependence.

An integration built around an open standard does not necessarily need to be rebuilt if the company switches AI tools, as long as the new tool also supports MCP. In a market where AI models can change every few months, that flexibility can help protect technology investments.

What MCP does not do

There is, however, one expectation that needs to be corrected.

MCP does not discover data on its own, nor does it create integrations automatically. Someone with technical expertise still needs to build each connection and decide what the AI can access and which actions it is allowed to perform.

But the real limit is not only defined by the functions made available. It also depends on the credentials the server uses to access each system. A server with broad permissions serving a user who would not normally have those permissions represents a classic security risk.

That makes MCP a governance issue, not just a technology issue.

Four areas deserve particular attention from leadership:

  • Accuracy. AI interprets data and can still make mistakes or generate inaccurate information. Figures used to support important business decisions should be carefully verified.
  • Privacy and compliance. Depending on how an AI tool is purchased and configured, strategic company information may pass through external services. These data flows must comply with internal policies and applicable regulations, including Brazil’s General Data Protection Law, known as LGPD, particularly in highly regulated industries such as financial services.
  • Untrusted content. When AI consumes external data, such as social media posts, it may encounter malicious instructions designed to manipulate its behavior. This technique, known as indirect prompt injection, makes it especially important to configure integrations according to the principle of least privilege.
  • Server provenance. An MCP server operates with a high level of trust within an AI workflow, so installing one is similar to granting access to an internal system. In September 2025, a malicious package impersonating the official library of the email service Postmark reportedly began secretly copying messages sent by AI assistants that used it. The lesson is straightforward: the same thousands of public servers that demonstrate adoption also create a broader attack surface. Every MCP server should be evaluated with the same scrutiny applied to any other software vendor.

The right question

For years, the promise of “democratizing data” faced a practical barrier: to communicate with data, people first had to understand the language of the systems that stored it.

MCP removes much of that barrier, but it does not solve the other half of the problem. If terms such as “active customer” or “complaint” mean different things across different systems, AI may provide answers quickly and confidently while two people still receive different answers to the same question.

Standardizing the connection is the easier part. Standardizing meaning remains a human responsibility.

For companies, the question is no longer whether AI will access their systems. The more important questions are which data it should be able to reach, what rules should govern that access, and who should be responsible for it.

Companies that answer those questions well can significantly shorten the distance between uncertainty and decision making.


Read more about AI:

How AI agents and protocols like MCP, ACP, A2A and AP2Are building the agentic web

Agent Communication Protocol (ACP) and Agent-to-Agent (A2A): The New Communication Language for AI Agents

Join our newsletter

Get marketing tips & news directly to your inbox.

Follow us

Stay connected and follow our latest insights, updates, and industry trends.

Ready to make intelligence strategic?

See how Loxias AI works for organizations like yours.