Back to blog
Enterprise AI

Speakeasy joins the Agentic AI Foundation

Sagar Batchu

Sagar Batchu

August 12, 2026 · 5 min read

Speakeasy joins the Agentic AI Foundation

TL;DR

Speakeasy has joined the Agentic AI Foundation (AAIF), the Linux Foundation organization that stewards the Model Context Protocol (MCP), goose, and AGENTS.md. We’re joining to contribute what we’ve learned running MCP infrastructure in production: enterprise governance requirements for the MCP specification, tool design lessons from generating servers at scale, and security research on agent-specific threats.

Speakeasy is now a member of the Agentic AI Foundation (AAIF). If you build on the Model Context Protocol, and we do, this is the room where the protocol’s future gets decided. We intend to be useful in it.

What the AAIF is

The AAIF was established in December 2025 under the Linux Foundation as a neutral home for the open standards that agentic AI runs on. It was anchored by three founding project contributions:

  • Model Context Protocol (MCP), contributed by Anthropic: the universal protocol for connecting AI models to tools, data, and applications.
  • goose, contributed by Block: an open-source, local-first AI agent framework built on MCP-based integration.
  • AGENTS.md, contributed by OpenAI: a universal standard that gives AI coding agents consistent, project-specific guidance across repositories and toolchains.

The platinum membership roster reads like the infrastructure layer of the AI industry: Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, and OpenAI. Since launch, the membership has broadened to enterprises whose interest is less in building models and more in deploying agents safely, with companies like Teradata joining to represent the governance and security requirements of regulated industries.

That second wave is the important one. Protocols mature when the people operating them in production show up alongside the people who designed them.

Why we joined

Speakeasy’s business is built on open standards. We started with OpenAPI, generating SDKs from the API contracts enterprises already maintain. When MCP emerged, the same thesis applied: the contract is the interface, and open protocols are what let an ecosystem compound instead of fragmenting into proprietary islands.

Today MCP is load-bearing infrastructure for us and for our customers. The Speakeasy MCP gateway sits between AI agents and MCP servers in production enterprise environments, enforcing identity-scoped access, inspecting traffic for threats, and producing audit trails. We generate MCP servers from OpenAPI contracts at scale, and we’ve published what we learned from 50 production servers and from cutting token usage 100x with dynamic toolsets.

That position, on the path between every agent and every tool, gives us a specific vantage point on where the protocol works, where it strains, and what enterprises need from it that isn’t specified yet. Membership in the AAIF is how we put that vantage point to work upstream instead of only in our product.

There’s a self-interested reason too, and we’d rather state it plainly: our product bets depend on MCP remaining open, vendor-neutral, and enterprise-credible. A protocol governed by a neutral foundation, with the major model providers and cloud vendors at the same table, is the version of the future we built for. We’d like to help keep it that way.

What we plan to contribute

We’re joining to work, not to put a logo on a page. Four areas, in order of how much we have to offer:

1. Enterprise governance and security requirements for MCP

The gap between MCP’s developer experience and enterprise requirements is where we live. Identity propagation across the agent-to-tool path, authorization scopes at the tool and parameter level, audit semantics that satisfy compliance teams, and human-in-the-loop approval flows are all areas where we’ve had to build ahead of the specification. We plan to bring those production requirements, and the designs we’ve validated against real security reviews, into the MCP specification process, so the next team doesn’t have to solve them in proprietary ways.

2. Tool design lessons from generating MCP servers at scale

Most MCP servers will not be hand-written. They’ll be generated from the API contracts enterprises already maintain, and generation at scale surfaces protocol-level questions fast: how to keep large toolsets token-efficient, how tool descriptions should be structured so models use them reliably, and how OpenAPI semantics should map onto MCP. We’ve generated servers across hundreds of APIs and published our lessons. We’ll contribute that evidence base to the protocol and ecosystem discussions where tool design is being standardized.

3. Security research on agent-specific threats

Tool poisoning, prompt injection through tool outputs, and confused-deputy patterns are attacks that only exist because agents exist. We research these threats to build defenses into our gateway, and we’ll share that research with the foundation’s security work so that mitigations land in the protocol and its reference implementations, not just in commercial products. The right long-term home for baseline agent security is the standard, not the vendor.

4. Interoperability across the project portfolio

The AAIF’s scope is wider than MCP, spanning agent frameworks like goose and conventions like AGENTS.md. The connective tissue between these projects, how a gateway advertises capability to an agent framework, and how project-level agent guidance interacts with organization-level policy, is exactly the layer our customers deploy. We’ll represent that operator’s perspective across projects.

What this means for our customers

Nothing changes in the product today, and that’s the point. If you run the Speakeasy MCP gateway or generate MCP servers with us, this membership is our commitment that the standards underneath your deployment stay open and that your requirements have a channel into them. When your security team asks for something the protocol doesn’t do yet, our answer can now be “we’re working on it upstream” rather than “here’s our proprietary workaround.”

Open standards are how enterprises avoid betting their AI architecture on a single vendor’s roadmap. We joined the AAIF to keep that true for the agentic stack. If there’s something you need from MCP that it doesn’t do today, tell us, because we’re now in a position to carry it further than our own backlog.

Last updated on

AI everywhere.

Control here.