Four separate releases in the past week point at the same thing, and none of them are about embedding quality.
The spec change underneath it
On September 28, the Agentic AI Foundation — the Linux Foundation directed fund that Anthropic donated MCP to, co-founded with Block and OpenAI — shipped what secondary coverage describes as the largest MCP release so far: a finalized stateless architecture, hardened OAuth authorization, and a formal 12-month deprecation policy. The stateless work completes a direction set in the 2026-07-28 revision, which removed the `initialize` handshake and the `Mcp-Session-Id` header.
If you operate connector servers, read this as a deployment change first. No session identity means no sticky routing, no session store to replicate, no reconnect semantics to get subtly wrong — a connector server becomes an ordinary horizontally scaled HTTP service behind a round-robin balancer. The cost is that everything the session used to hold must now be re-established per call or carried in client context. Per-request auth and per-request scoping stop being good hygiene and become the only place state can live, which is why the OAuth hardening shipped alongside rather than after.
The deprecation policy is the duller and more useful half. Connector fleets are the part of a retrieval stack nobody re-tests; a published window lets you schedule migrations instead of discovering them in an on-call page.
Vendors converging on the same seam
Glean's October 1 release (version 559) made Agent Identity generally available, alongside GA for the Platform Skills API and the Fathom, Crayon, and Veeva Vault connectors, plus six more MCP server templates. Treating agent identity as a first-class object is an admission that "the agent searches as the user" breaks once agents run on schedules, span tenants, or call other agents. You need an identity you can scope, audit, and revoke on its own.
Google's Gemini Enterprise notes list managed organization policy constraints for data connectors as GA, plus a federated query mode that queries sources in place. Federation is the sharper architectural tradeoff: you give up index-time ranking signals, inherit the source system's latency, and lose control over recall. In exchange, freshness and permissions are resolved by the system of record at query time rather than by a nightly crawl whose ACL snapshot has already drifted. For regulated corpora that drift is the entire risk; for a 50M-document general index it is usually worth eating.
Anthropic's earlier enterprise-managed auth for Claude's MCP connectors fits the same pattern — admins authorize a connector once and users inherit access through existing IdP groups and roles.
Who this matters to: if you build internal knowledge tools, your differentiator is shifting from retrieval quality to how faithfully you can reproduce someone else's permission model under an agent acting repeatedly and unattended. Budget note if you run Glean on Enterprise Flex: activity-based memory is free only through October 16, then consumes FlexCredits.

