MCP (Model Context Protocol)
The protocol through which an agent reaches external tools, servers, and data beyond its own reasoning. GovTech's phase one excluded MCP access entirely, restricting the agent to built-in reasoning inside its own sandboxed environment; phase two reintroduces it through a governed, sandboxed mechanism rather than an open connection.
Defined in 3 GAGE programs, which carry 10 distinct definitions of it. The wording above is taught in Agentic AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A named protocol, cited in the MGF's agentic value chain as an example of a tooling-provider offering, that lets an agent connect to external tools and data sources in a standardized way. Named here as a value-chain example; its own protocol-layer threats are developed in full in this program's control-and-threat module (see Topic 5.6).
An emerging open standard, still maturing as of August 2026, for connecting AI agents to external tools and data sources in a structured, interoperable way; several identity platforms, including Auth0, now treat MCP servers as first-class identities subject to their own authorization and logging controls.
A common standard for connecting AI agents to external tools and data. Notable here because its open-by-default tooling can over-expose access unless scoped, the condition the Invariant Labs GitHub incident exploited.
The named standard for agent-to-tool communication, introduced by Anthropic in November 2024 to let an AI agent connect to external tools and data sources without custom integration code for each one; adoption has moved fast, which is also why a flaw in its trust model can affect many implementations at once.
A named communication protocol for connecting an AI agent to external tools and data sources, referenced by the WEF paper's protocol-layer treatment; full technical treatment is out of scope for this topic. (see Topic 1.2)
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Securing Agent Permissions and Access Boundaries · AI Security Fundamentals, AI Literacy & Professional Conduct
- The Parts That Make an Agent Act · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- Why Singapore's Framework in Ohio · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- The Whole Framework, Worked · The Agent, Deconstructed, Agentic AI Governance: Applied Mastery
- Action-Space · Capability and Autonomy, Agentic AI Governance: Applied Mastery
- Agent Identity · Bounding by Design, Agentic AI Governance: Applied Mastery
- The Agentic Value Chain · Meaningful Human Accountability, Agentic AI Governance: Applied Mastery
- Protocol-Layer Threats · Technical Controls and Threat Modeling, Agentic AI Governance: Applied Mastery
- Ship the Agent in Stages, Never All at Once · Rollout, Monitoring, and Incident Response, Agentic AI Governance: Applied Mastery
- The agent's trail: who acted, on whose authority, using what, and why, recorded for every autonomous touch of your estate · Access and the Keys, AI Data Governance: The Data Chair
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.