All insights

What is MCP? A plain explanation, and what to demand on security

MCP is the standard that lets AI tools like Claude, ChatGPT and Copilot fetch information from your systems. How it works, and what to demand on security.

Van Gogh-style oil painting: several gravel roads and footpaths meet at an old stone bridge over a calm river in a Swedish valley in afternoon light.

Short answer: MCP, the Model Context Protocol, is an open standard that lets AI tools connect to other systems in a consistent way. With MCP, tools like Claude, ChatGPT and Microsoft Copilot can fetch information from your documents, systems and databases, without every connection being rebuilt for every tool.

Anthropic launched MCP at the end of 2024, and most major AI tools now support it. It sounds technical, but the idea is simple, and it explains why AI tools can suddenly do so much more with a company's own information.

MCP is like USB-C for AI

Think back to before USB-C. Every phone, laptop and camera had its own cable. MCP does for AI what USB-C did for chargers: one shared connector everyone can use.

Before MCP, every AI tool needed its own integration with every system. Five AI tools and ten systems meant fifty connections to build and maintain. With MCP, the connection to a system is built once, and every AI tool that supports the standard can use it.

How does MCP work?

There are three parts to keep track of:

  • The MCP client is the AI tool you use, for example Claude, ChatGPT or Copilot.
  • The MCP server is the connection to a system, for example your documents, your CRM or a knowledge base.
  • The tools are what the server offers, for example searching documents, looking up a customer or creating a ticket.

When you ask a question, the AI tool decides whether it needs to fetch something. Ask "which price list applies to new customers?" and it asks the MCP server, gets the information back and writes an answer. You do not notice the technology. You just get an answer based on your own information.

Which tools support MCP?

Support has grown quickly. Among the most common:

  • Claude, on the web, in Claude Desktop and in Claude Code, through connectors.
  • ChatGPT, where Business and Enterprise can add apps and connections for the whole workspace.
  • Microsoft Copilot Studio, where agents can use MCP servers as tools.
  • Developer tools such as Cursor, VS Code and GitHub Copilot.

Exactly how the connection is made differs between tools and plans. We walk through it for Copilot, ChatGPT and Claude.

What MCP does not do

MCP is a connector, not content. The standard decides how the AI tool fetches information, not which information is right. Connect an MCP server straight to a messy SharePoint and the AI gets access to the mess: old drafts, conflicting versions and folders nobody owns anymore.

The connection is not the knowledge. What the AI fetches is only as good as where it fetches it from.

That is why what sits behind the connection matters. Read more about why the same question can get different answers.

Six things to demand on security

An MCP connection gives the AI tool access to your systems. Ask these questions before you enable one:

  1. Does every person sign in themselves? Permissions should follow the person asking, so nobody sees more through AI than in the source system.
  2. Does the connection get only what it needs? Read access is often enough. Write access should be a deliberate choice.
  3. Who approves the connection? In a company setting, an admin should enable it, not every employee on their own.
  4. Is what gets fetched logged? You should be able to see afterwards which information was used, and by whom.
  5. Where is the data processed and stored? For many European companies, keeping data within the EU is a requirement.
  6. Does the server come from a trusted vendor? An MCP server can influence what the AI does. Only install servers from vendors you trust, as with any other software.

MCP and AI agents

MCP is also the foundation for AI agents, meaning AI that carries out work rather than only answering. An agent handling discount requests can use MCP to fetch the discount policy, check the customer in the CRM and route exceptions to a person. But the agent needs what a new employee needs: the right rules, current procedures and clear limits. Without that, it only automates guesses.

How Company Brain uses MCP

A Company Brain gathers company knowledge from SharePoint, Google Drive and your people, lets an accountable person approve what applies and makes that knowledge available through MCP. It is maintained in one place, and the same verified context is available in Copilot, ChatGPT, Claude and AI agents. Want to see how the tools differ? Read our comparison.

Frequently asked questions

What does MCP stand for?

MCP stands for Model Context Protocol. It is an open standard for how AI models and AI tools fetch context and use tools in other systems.

Do you need to code to use MCP?

No. For the person using the AI tool, it is a matter of enabling a connection, much like installing an app. Building your own MCP server, however, takes development work.

Is MCP secure?

The standard itself is neither secure nor insecure. That depends on how the connection is built: whether each person signs in, what permissions it has, whether usage is logged and where data is processed.

What is the difference between MCP and an API?

An API is a way for two systems to talk, and every API looks different. MCP is a shared format that lets AI tools use many different systems in the same way. Often the MCP server in turn uses the system's API.

What is MCP? Model Context Protocol, plainly explained