Model Context Protocol (MCP)
An open protocol for connecting AI systems to external data sources and tools through a client–server interface. A host application runs clients; each client connects to a server that exposes a declared set of resources, tools and prompts.
Why it matters for autonomous finance
MCP is the first widely adopted place where an agent's reach is declared rather than assumed. A server exposes an explicit tool surface, which means the question 'what is this agent permitted to touch' has a machine-readable answer for the first time. For governance purposes that server manifest is an authority grant, and it should be treated as a controlled document — versioned, reviewed, and diffed on change.
What it does not cover
MCP describes capability, not permission. It says what an agent can reach; it does not say what it may commit, under whose authority, or up to what limit. Reading a tool manifest as an authorisation boundary is the most likely governance mistake of the next two years — the protocol was never designed to carry that weight.
Says nothing about oversight intervals, drift, or accountability. Every entry in this register carries this section. A standard read past its scope is worse than no standard, because it produces confidence without coverage.