Fetching from the wire…
Public story · 2026-08-23 · high
MCP's new roadmap and A2A's move under the Agentic AI Foundation both point at the same target next: agent identity for enterprise deployments.
Why now: MCP published its roadmap on August 22, two days after A2A moved under the Agentic AI Foundation on August 20, putting both governance shifts in the same week.
MCP published a new roadmap on August 22. Two days earlier, on August 20, A2A moved under the Agentic AI Foundation. Different protocols, different announcements, same target: agent identity for enterprise deployments.
MCP's roadmap names "agent identity and enterprise security" as a priority area and describes moving away from browser-based authorization, the flow where a human clicks through an OAuth screen. That model doesn't work for a cloud agent running unattended or a server pushing events to an agent without a person in the loop. A2A's new home under AAIF puts it under a platinum-tier roster that includes AWS, Anthropic, Cloudflare, Google, Microsoft, and OpenAI, the same companies that need agents to clear enterprise security review before regulated buyers will deploy them.
That's the part worth sitting with. Two competing protocol efforts converging on the same problem in the same 72 hours isn't a coincidence of timing, it's the same set of vendors hitting the same wall. You can build a working agent integration with API keys and service accounts. What you can't easily do is prove to a bank's security team who authorized what action, on whose behalf, with what audit trail. That's the gap both roadmaps are now aiming at.
If you're building on either protocol, the interesting fight isn't MCP versus A2A anymore. It's whoever ends up owning the identity and audit layer underneath both. Point-solution integration vendors are the ones who lose ground here, since the layer they compete on is getting standardized out from under them. Bedrock's AgentCore Gateway already ships a scoped permission model with per-operation pricing, which is one version of what this identity layer might look like once it's productized. Watch whether MCP's server-initiated events land with an identity model attached, or whether that ships as a separate spec.
Each link below shares sources, entities, or timing with this story.
Same source
Cite the same source (Multiple Sources (MCP Blog Aug 22, Google Developers Blog Aug 20)).
Semantically similar
Covers closely related ground (similarity 0.77).
Covers closely related ground (similarity 0.76).
Covers closely related ground (similarity 0.76).
Same source domain
Reported by the same outlet (blog.modelcontextprotocol.io).
Reported by the same outlet (blog.modelcontextprotocol.io).
Reported by the same outlet (blog.modelcontextprotocol.io).
Reported by the same outlet (blog.modelcontextprotocol.io).