The Model Context Protocol has crossed from connectivity layer to competitive terrain. In the last two weeks, five enterprise vendors have shipped MCP-integrated governance products, each staking a different tier of the agent governance stack. The result is not convergence. It is a contest over who controls the protocol’s future.
Two Fortune-100 vendors committed to MCP as a default standard in the same window. Rubrik layered data-security controls on top. Google’s Managed Agent Harness introduced a runtime sandbox with a credentials architecture that keeps tokens out of the model. ServiceNow brought enterprise service management into the loop. Each implementation adds a different type of control to the same protocol, and the sum of those controls is beginning to look less like interoperability and more like platform competition.
The governance stack is formalizing into distinct tiers. At build time, Cisco’s agent SDK embeds constraints before an agent reaches production. At runtime, tools like WSO2 Agent Manager and NVIDIA OpenShell provide control planes and sandboxing. Rubrik occupies a third pillar: data-security enforcement through the protocol layer itself. Google’s Credentials API adds a fourth: a managed harness that proxies authentication so the model never sees raw tokens.
Meta’s MCP integration for WhatsApp Business, announced this week, introduces a fifth dimension: consumer-facing agent identity. An agent that can initiate payments, access calendars, or manage communications through MCP is not just a technical actor. It is a commercial one. The protocol is becoming the interface between agents and the economy, and each vendor is positioning itself to control a different layer of that interface.
The competitive dynamics are already visible. ServiceNow’s AI Gateway v3.4 targets IT operations teams that need policy enforcement inside existing service management workflows. Rubrik’s implementation is security-first, embedding OWASP-aligned guardrails and agent inventory features that aim to eliminate shadow AI. Google’s architecture is developer-first, with ephemeral sandboxes and a file system abstraction that treats agents as untrusted by default. Each approach reflects a different theory of where the risk sits, and each theory implies a different point of control.
The open question is whether MCP’s loose specification can support all five governance tiers simultaneously, or whether the protocol will fragment into platform-specific dialects. If each vendor’s governance layer requires its own runtime, its own identity model, and its own policy language, the protocol’s promise of interoperability becomes a thin veneer over platform lock-in. The next six months will reveal whether these implementations converge on shared standards or harden into competing ecosystems.