The agentic stack is now real enough to be attacked, exploited, and litigated — and that is the most important sentence I’ve written in this column. The stories that matter this week aren’t about what agents can do; they’re about what happens when the infrastructure underneath them is treated like a developer convenience instead of a critical execution layer. The railroad companies aren’t just charging tolls anymore — one of them just got caught trying to lock the gate.
MCP Is Looking Less Like Plumbing and More Like the Next Enterprise Security Headache
If you’re a business owner and you don’t know what MCP is, that’s understandable. If your team is deploying agentic systems and still treating MCP like harmless middleware, that’s a problem.
In the last month, we didn’t get one isolated bug. We got a pattern. A calculation server passing user input straight into Python eval with unauthenticated remote code execution potential. A protocol-level DNS rebinding issue before spec version 0.25. Official Python and Go SDKs that shipped without DNS rebinding protection enabled by default for HTTP transports. Anthropic’s own Git MCP server exposing a chain where a poisoned README — exactly the kind of file an autonomous assistant might read without drama — could become the start of file access and code execution. OX Security’s advisory goes even broader, estimating STDIO command injection patterns across popular projects totaling more than 150 million downloads.
That’s why the Log4Shell analogy works. Not because the bugs are identical, but because the structure is. In both cases, developers treated a convenience layer as low-risk glue, when in fact it was a direct path from untrusted input to privileged execution. And in the agentic world, the trust boundary is even more fragile. Your agent reads webpages, docs, tickets, READMEs, emails, internal records. If “what it reads” can collapse into “what it executes,” then we have not built useful extensions of people. We’ve built attack surface with a personality layer on top.
I’m not backing away from my thesis that agents will become extensions of people. I’m saying the infrastructure has to earn that trust. Right now, too many vendors are selling “connect your agent to everything” as if connectivity itself were maturity. It isn’t. It’s exposure. And when SAP is simultaneously mandating MCP as a secure enterprise routing standard while the broader MCP ecosystem is still dealing with basic execution-boundary failures, business leaders should hear alarm bells — not marketing copy.
My call: the next 30 days are going to produce a governance tooling race around MCP. Noma and Detectify already moved. More will follow. The real question is whether a standard emerges quickly, or whether we get the usual fragmented mess where every vendor claims visibility and nobody owns the control plane.
Read the SentinelOne CVE entry on MCP Calculate Server RCE →SAP’s AI Strategy Looks a Lot Like a Gatekeeping Strategy — and a Judge Just Noticed
This is the railroad company play in enterprise software, and I don’t think SAP deserves the benefit of the doubt here.
On June 9, SAP’s technical enforcement around ODP-RFC blocking went live. In plain English: a security patch now validates callers and aborts replication flows that a whole third-party ecosystem depended on. Microsoft’s Azure Data Factory SAP CDC connector. Qlik. Theobald. Specialist integrators whose entire value proposition was helping enterprises get SAP data where it needed to go. SAP gave customers a revert switch until December 2026, which tells you everything you need to know: this is disruptive enough that they needed a pressure-release valve.
Forrester didn’t dance around it. Their framing was blunt: SAP is attempting to become the gatekeeper of enterprise AI, and CIOs should push back. Fivetran made the same broader point from the integration side: your AI strategy now depends on whether your ERP vendor decides data access is a privilege instead of an expectation. Then a US judge issued a split antitrust decision in the case against SAP. That matters. A split decision is not final defeat for SAP, and it is definitely not vindication.
What I’m watching is the silence. We have not yet seen the wave of named enterprise disclosures saying pipelines broke and operations were disrupted. Some people will read that as overreaction. I read it differently. Large enterprises manage pain quietly for as long as they can. They open support tickets. They use temporary switches. They renegotiate contracts behind closed doors. Deferred pain is still pain.
Here’s why this advances my thesis instead of weakening it: if agents are going to become real business extensions, access to core operational data becomes the whole game. SAP appears to understand that perfectly well. It wants to control what data leaves SAP systems and, through MCP, increasingly how agents are allowed to touch those systems. That is not just a product strategy. It is a power strategy.
If you run SAP, ask your integration vendor a direct question this week: what breaks, what gets more expensive, and what becomes contractually dependent on SAP after December 2026? If nobody around the table has a crisp answer, you are negotiating your AI future from inside a locked room.
Read Forrester’s analysis on SAP’s gatekeeper strategy →The 75% DIY Failure Rate Should End the Romance of Building Agents From Scratch
Back in February, I said the agentic development camp debate would be mainstream by Q2 2026. That call has aged well. But the evidence is forcing a refinement I need to make in public: “start simple” does not mean “build it yourself.”
Forrester says three-quarters of organizations trying to build AI agents fully in-house will fail. Gartner says 40% of agentic AI projects will be cancelled by 2027 because of cost, unclear value, or weak risk controls. McKinsey’s survey picture is exactly what you’d expect in that environment: lots of experimentation, much less real scaling. Meanwhile, the places where agents are actually sticking in production — healthcare, supply chain, ERP-heavy workflows — are not being won by custom science projects. They’re being won by vertical products and platform-based deployments with bounded autonomy and humans still firmly in the loop.
The MAP study may be the most useful reality check in the pile. Most production agents run short. Most rely on off-the-shelf models and prompting. Most are evaluated by humans, not fantasy benchmarks. That’s not disappointing to me. That’s what maturing infrastructure looks like. Boring wins first.
MIT Technology Review’s healthcare reporting reinforces the point. If 68% of providers have incorporated AI agents into teams, and those deployments are largely managed systems integrated into EHR and billing workflows, then the business lesson is not “everyone should become an agent framework company.” It’s the opposite. Use what is already engineered for governance, data access, and accountability when you can.
So yes, I still believe simple architectures are winning. But I’m drawing a harder line now: simple for the operator is what matters, not simple in the abstract for the builder. A deeply integrated managed product can be operationally simpler — and strategically smarter — than a homegrown stack your team barely has time to secure.
Read CIO’s roundup on why agentic AI is still mixed, not mainstream →Okta Shipped Agent Identity for Real — and the Rest of IAM Is Now on the Clock
Prediction 3 is paying off earlier than even I expected.
I said in February that once agents start acting on behalf of people and organizations, the question “who authorized this agent to do that?” becomes urgent. This month, that urgency stopped being theoretical. Okta pushed new non-human identity capabilities into general availability, covering AI agents, service accounts, API keys, shared accounts, and automation tools through governance, posture management, privileged access, and separation-of-duty controls.
That distinction matters. Roadmaps are cheap. GA is expensive. SailPoint and CyberArk have talked about the space, but Okta is the first major IAM vendor in this window to move from “we see the trend” to “here is the product.”
And the timing is perfect, because the surrounding news made the use case obvious. MCP vulnerabilities raise the cost of anonymous execution. SAP’s lockdown fight raises the stakes around who gets to access enterprise data. The more agents act like workers, the less acceptable it becomes for them to operate like orphaned scripts with hardcoded credentials and no audit trail.
If agents are extensions of people, they need identity the way people do: permissions, logs, role boundaries, separation of duties, and a way to turn them off cleanly when the relationship ends. That’s not red tape. That’s what trust looks like at scale.
My call: CyberArk and SailPoint have about 60 days before this turns from first-mover advantage into procurement narrative. Once “agent identity” lands on security and compliance checklists, this stops being a category story and becomes a budget line.
Read Okta’s announcement on extending identity to non-human actors →Microsoft Just Put a Dollar Figure on the Complexity Moat — and It’s 45%
A 45% reduction in Azure OpenAI spend from one architectural change is not a technical footnote. That is a procurement event.
The significance of LazyGraphRAG is not that it sounds clever. It’s that it challenges one of the quiet assumptions enterprise AI vendors have been making money from: that high-quality graph-based retrieval requires massive upfront indexing, expensive implementation work, and therefore a tolerance for enterprise-scale waste. If Gartner’s enterprise-focused study is right, and independent benchmarks are directionally aligned, then that assumption just got weaker in a hurry.
LazyGraphRAG defers expensive work until query time instead of charging you upfront for the full graph universe before anyone asks a useful question. And if answer quality stays within 1% of traditional GraphRAG while indexing and query costs drop dramatically, then a lot of “you need our complex pipeline” pitches suddenly sound like legacy pricing strategy disguised as architecture.
This is exactly the kind of constraint removal I track every week. Not a shiny demo. A meaningful disappearance of cost that widens who gets to play. If you’ve been told that serious enterprise document intelligence requires six figures of indexing infrastructure before value can even be tested, get a second quote. Immediately.
Read The Stack’s report on Microsoft’s lower-cost LazyGraphRAG →Clark's Corner
My honest take this week is that a lot of people still think “transition” means consensus. It doesn’t. It means conflict. It means the stack gets exploited in real time because it matters now. It means incumbents try to lock access the moment they realize open connectivity threatens the tollbooth. It means production wins show up at the same exact moment the security debt comes due.
That’s where we are.
The MCP vulnerabilities don’t scare me out of the thesis. They confirm that the thesis has entered the adult phase. Nobody attacks toys like this. They attack infrastructure. The SAP fight doesn’t make me pessimistic either. It makes me more certain that open, composable, vendor-agnostic foundations are the right long-term bet for any business that wants leverage instead of dependency.
The railroad companies always move to lock the gates when they realize the planes are coming. SAP trying to become the AI gatekeeper is not evidence that the future belongs to gatekeepers. It’s evidence that they know the future is arriving fast enough to threaten them.
If I’m a business owner right now, I’m doing three things: auditing every agent connection as if it were privileged code, forcing a serious conversation about data portability with any core enterprise vendor, and refusing to confuse architectural complexity with business maturity. That last mistake is still costing people a fortune.