The most consequential thing to land for anyone shipping connectors is the new Model Context Protocol specification revision dated 2026-07-28, which went out after a public release candidate on the MCP blog. Coverage in the run-up was blunt about the theme: InfoWorld framed it as the protocol "going stateless to make scaling simpler," and The Register described MCP as preparing to break with its stateful past. The Agentic AI Foundation's writeup put the shift as MCP moving from a local tool protocol to a distributed one. The changelog for the revision is published alongside the spec and is still being touched, so if you maintain a server, read that page rather than secondhand summaries.
Why this matters for retrieval people specifically: a lot of MCP servers in production are thin wrappers over a search index, and they quietly cheat by keeping things in the session. Pagination cursors. A cached rerank pass over the last result set. Resolved tenant and ACL context from the initial handshake. A warm connection pool keyed to the caller. Once the transport no longer guarantees you'll see the same client on the same process, all of that has to move — either into the request itself, or into an external store you now have to operate.
The tradeoff is real and it isn't free. Session-scoped state was doing useful work: it kept per-request payloads small and let you amortize expensive setup like permission resolution across a multi-turn retrieval loop. Externalizing it to Redis or Postgres buys you horizontal scaling without sticky routing, but adds a round trip on the hot path of every tool call, and it forces you to define TTLs and invalidation for things that previously died with the connection. Pushing state to the client instead is cheaper to operate but inflates token cost and turns your cursor format into a public API contract you can't change quietly.
The upside is the part worth planning around. Stateless request handling is what lets a connector fleet sit behind an ordinary load balancer, scale to zero, run on serverless, and be deployed blue-green without draining sessions. For enterprise search, it also puts authorization where it belongs — evaluated per request, against current group membership, rather than snapshotted at session start. Anyone who has shipped a document ACL bug knows why that's the better default.
The memory-layer side of this is worth watching for the same reason. Capital kept flowing into agent memory infrastructure through the year — Cognee raised a $7.5M seed in February, Interloom $16.5M in March — and the research is moving past treating memory as plain vector similarity, as in the recent arXiv work on retrieval for agent memory by decoupling and aggregation. If memory becomes something you consume over MCP rather than embed in your process, then the question of where memory state physically lives stops being an implementation detail and becomes a protocol-level design decision.
If you own a connector, the near-term work is auditing what your handlers assume about session identity. That audit is cheaper now than after a scaling event forces it.

