← All writing
AI Jul 30, 2026 6 min read

The most important AI document this week is a deprecation policy

Christopher Dorsey

Christopher Dorsey

AI & MadTech Advisor · Enterprise Sales Leader

TL;DR

The Model Context Protocol published its final 2026-07-28 specification on Tuesday, the largest revision since launch. Every writeup is a migration guide: the initialize handshake is gone, session IDs are gone, Roots and Sampling and Logging are deprecated. Three things in the release have nothing to do with code. A formal deprecation policy gives every feature an Active, Deprecated, Removed lifecycle with at least twelve months between deprecation and any removal. A public conformance suite now gates whether a proposal can reach Final status, and scores official SDKs. And MCP Apps, the flagship new extension, was co-authored by Anthropic, OpenAI and the community MCP-UI maintainers. Anthropic donated MCP to the Linux Foundation in December, where it anchors the Agentic AI Foundation alongside Block's goose and OpenAI's AGENTS.md, backed by Google, Microsoft, AWS, Cloudflare and Bloomberg. I watched advertising do this in 2010 and 2011, when direct competitors agreed on OpenRTB and the IAB adopted it in January 2012. Integration stopped being a reason to pick a vendor, margin compressed on the companies whose product was the connection, and value concentrated with whoever held unique data or real demand. MCP Apps complicates the story I told on July 15: servers can render interactive UI back inside Claude and ChatGPT, but on the host's terms, with templates security-reviewed up front and every action routed through the host's consent path. If you sell software that plugs into an assistant, find out which spec version you conform to and whether you pass the suite, then stop selling the integration. If you buy, the twelve-month deprecation window is a procurement answer you didn't have in April.

The Model Context Protocol published its final 2026-07-28 specification on Tuesday, the largest revision since it launched. Every writeup I could find is a migration guide: what breaks, how to move off sessions, which SDK to upgrade. Fair enough. The release deletes the initialize handshake, removes the session ID header, and deprecates three core features on the way to a stateless protocol.

Three other things shipped that have nothing to do with code.

A formal deprecation policy, giving every feature an Active, Deprecated and Removed lifecycle, with a minimum of twelve months between deprecation and the earliest possible removal. A public conformance suite, which a Standards Track proposal now has to satisfy before it can reach Final status, and which official SDKs get scored against under a new tier system. And MCP Apps, the release’s flagship extension, co-authored by Anthropic, OpenAI and the maintainers of the community MCP-UI project.

Anthropic and OpenAI wrote a standard together, and attached a warranty to it. None of that happened in a vacuum: Anthropic donated MCP to the Linux Foundation last December, where it anchors the new Agentic AI Foundation alongside Block’s goose and OpenAI’s AGENTS.md, with Google, Microsoft, AWS, Cloudflare and Bloomberg signed on. The companies competing hardest in AI have agreed on a plug and handed a standards body the keys.

I watched this happen to advertising

In December 2010, a group of ad tech companies published OpenRTB 1.0. Buy-side firms like DataXu and [X+1] sat down with sell-side companies like Nexage, PubMatic and Smaato, all of them competing for the same dollars, and agreed on what a bid request should look like. Version 2.0 unified display, video and mobile in June 2011. The IAB made it an official standard in January 2012.

I was at Crispin Porter + Bogusky then, and I can tell you precisely how much attention that spec got inside an agency. None. Nobody read it. It was a document for engineers at companies we bought from, filed under things that were not our problem. A couple of years later, the media planners who used to pick sites for a living had different job titles, and a large share of the value in the supply chain had moved somewhere else.

The sequence is worth remembering because it repeats. First, integration stopped being a reason to choose a vendor, because everyone spoke the protocol and buyers could verify it. Then the number of counterparties exploded, since connecting got cheap. Margin compressed hardest on the companies in the middle, the ones whose actual product was the connection. And the money settled at the two ends: whoever held data nobody else had, and whoever controlled real demand.

Standardization also did something the trade press underrated at the time. It made the whole system auditable, and auditability is what let the large, cautious budgets in. That part is coming here too, and it’s mostly good news.

“We have an MCP integration” is about to stop selling

Until this week, an MCP integration was a legitimate differentiator. You’d built one, your competitor hadn’t, and the buyer had no practical way to judge whose was better. A public conformance suite ends that argument. So does an SDK tier system that scores implementations against the same tests. When a buyer can look up whether you conform, conformance becomes a floor.

On July 15 I wrote that ZoomInfo, Clay and Gong had kept their data and given up their interface, and that the renewal argument becomes the quality of what you feed the assistant. This release sharpens that. There are thousands of public MCP servers now. A connection is not scarce. A connection to something nobody else has is the entire remaining case.

So the slide has to change. If your differentiation section still says you integrate with ChatGPT and Claude, you are describing a floor your competitor also meets, in a document your buyer will fact-check against a public test suite. Say what comes through the pipe instead, and why it can’t come through anyone else’s.

MCP Apps hands the interface back, on the host’s terms

Two things can be true, and my July piece needs a correction. MCP Apps lets a server ship interactive HTML that the assistant renders in a sandboxed iframe: charts, forms, dashboards, a real surface inside Claude or ChatGPT. The interface isn’t gone after all. Vendors get one back.

Read the conditions, though. Tools declare their UI templates ahead of time so the host can prefetch, cache and security-review them before anything renders. Every action the rendered UI takes goes back over the same JSON-RPC path as a direct tool call, through the same audit and consent flow. You get a storefront in somebody else’s mall, and the mall reads every receipt.

That is still worth having, and I’d take it. It restores product experience as something you can compete on, which looked dead six weeks ago. What it doesn’t restore is control. Your interface now renders at the discretion of a host that also sells competing capabilities, under a security review you don’t administer. Asana users reportedly move faster on project updates through MCP Apps because they stop switching windows, which is a real gain and also a reminder of whose window they stopped leaving.

Two questions to have answers for

If you sell software that plugs into an assistant, find out today which spec version you target and whether you pass the conformance suite. That is now a question with a checkable answer, and the first time a buyer asks it in a bake-off is a bad time to learn yours. Then take the integration off the differentiation slide and put it in the requirements table where it belongs.

If you buy, the deprecation policy is the most useful paragraph in the release and nobody has told you about it. Twelve months of written notice before a capability can disappear is a continuity commitment you did not have in April, and it is the kind of thing that belongs in your next security review next to the questions you already ask about model availability. Ask your AI vendors which spec version they build against, and what their plan is when it moves.

I never read the OpenRTB spec. The people who did read it went on to build the companies that took our media budgets.

Share this post

About the author

Christopher Dorsey

Christopher Dorsey

Enterprise Sales Leader · AI Go-To-Market · Startup Advisor · Denver, CO

Fifteen years selling technology to Fortune 500 brands across AI, advertising, and data infrastructure — most recently at Zeta Global, Oracle, and Fastly. Currently advising founders and sales leaders on AI go-to-market and Generative Engine Optimization.

Questions, pushback, or just want to compare notes?