Disclaimer: This article is best-effort research based on public sources available as of October 2026. Details in this area change quickly, so verify facts against the primary sources listed at the end before acting.
On August 17, 2026, the Agent2Agent protocol (A2A) became a hosted project of the Agentic AI Foundation (AAIF), the Linux Foundation body that already governs Anthropic’s Model Context Protocol (MCP). The move puts the two most widely adopted open protocols for AI agents under one neutral roof. According to Axios, AAIF has grown to more than 250 members since its launch in December 2025, including Google, Microsoft, Amazon, Anthropic, OpenAI, Bloomberg, Shopify and Block.
For enterprise architects, this is a meaningful signal. A year ago, teams building agents faced a choice between competing specifications and real risk of betting on the wrong one. That risk has shrunk. But consolidation of protocols is not the same as an interoperable, secure agent platform, and the gap between the two is where most enterprise work now sits.
What each protocol actually does
The two protocols solve different problems, and it helps to keep them separate.
MCP connects an AI application to tools and data. An MCP server exposes tools, resources and prompts. An AI application, such as an assistant or a coding agent, acts as the client and calls them. MCP is how an agent reads a ticket, queries a database or posts to a chat channel without a custom integration for each one.
A2A connects agents to other agents. Agents publish “agent cards,” structured descriptions of what they can do and how to reach them. Another agent can discover that card and delegate a task, even if the two agents run on different platforms from different vendors. Forbes reported that A2A reached version 1.0 in March 2026, adding multi-protocol bindings, version negotiation, multi-tenancy and cryptographically signed agent cards.
AAIF also hosts two other founding projects that matter in practice: OpenAI’s AGENTS.md, a plain-text convention that tells coding agents how to work inside a repository, and Block’s goose, an open agent runtime. Forbes also lists agentgateway, a proxy for agent traffic, among AAIF projects.

How we got here
The consolidation happened quickly. Anthropic released MCP in November 2024. Google announced A2A in April 2025 and donated it to the Linux Foundation that June. IBM folded its competing Agent Communication Protocol into A2A in August 2025. The Linux Foundation formed AAIF on December 9, 2025, anchored by contributions of MCP from Anthropic, goose from Block and AGENTS.md from OpenAI, with AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI as platinum members. A2A’s arrival in August 2026 completes the picture for now.

What changes for enterprise architecture
Protocol risk is lower. With both protocols under neutral governance and supported by the major cloud platforms, building on MCP for tool access and A2A for cross-agent delegation is now a defensible default. Forbes reported support for A2A in Google Cloud, Azure AI Foundry and AWS Bedrock AgentCore. You can reasonably require both in vendor evaluations instead of accepting proprietary connectors.
Multi-vendor agent estates become practical. Most large organizations will run agents from several sources: those embedded in SaaS products, those from cloud platforms and those built in-house. A2A gives them a common way to hand work to each other. Google Cloud’s Rao Surapaneni told Axios that customers are deploying agentic systems from multiple vendors and need them to work together.
Integration effort shifts to governance. When connecting is easy, the hard questions become which agent may talk to which, on whose behalf, with what permissions, and how that is recorded. That work does not get easier because the protocols matured. It gets more urgent, because connections multiply faster.
What the standards do not solve
This is the part vendor announcements tend to skip. Forbes noted that the consolidation does not standardize authorization policies. Four gaps deserve explicit attention.
- Identity and delegation. When agent A asks agent B to act, whose authority is B using? You need a model for user-delegated versus agent-owned permissions, and a way to carry that context across hops.
- Authorization policy. Protocols define how to call; they do not define who may call what. Central policy, applied consistently at gateways or in each server, remains your responsibility.
- Trust in agent cards and tool descriptions. Signed agent cards help verify origin, but a validly signed card can still describe an agent you should not trust. MCP tool descriptions are also text an agent reads and may follow. Our analysis of recent MCP supply chain attacks shows why that matters.
- Audit and accountability. Regulators and auditors will ask who did what. Each delegation and tool call should be logged with the user, agent and server identities involved.
A practical checklist for the next two quarters
- Set protocol defaults. Standardize on MCP for tool and data access and A2A for agent-to-agent delegation in your reference architecture. Document exceptions.
- Add protocol questions to procurement. Ask vendors which versions they support, whether agent cards are signed and validated, how multi-tenancy is isolated, and what audit data they expose.
- Put a gateway in the path. Route agent and MCP traffic through a gateway or proxy where authentication, authorization and logging can be enforced centrally. Open options exist, but commercial gateways are also maturing quickly.
- Build an agent registry. Keep an inventory of approved agents and MCP servers, their owners and their permissions. Treat additions like new third-party software.
- Bound autonomy. Decide in advance which actions require human approval. Our Bounded Agent Stack gives a structure for this.
The bottom line
The plumbing for agent interoperability is settling, which is good news for buyers. The work that remains is the work that was always hardest: identity, authorization and accountability across systems that now connect easily. Organizations that treat August’s announcement as permission to connect everything will create a sprawling, hard-to-audit agent estate. Those that pair the open protocols with a gateway, a registry and clear autonomy limits will be able to scale agents with confidence.
For governance templates covering agent identity, MCP controls and human oversight, see our report Governing Agentic AI 2026. Related research: Generative and Agentic AI and Securing AI Systems.
Sources
- Axios, “AI agents inch toward interoperability,” 17 August 2026. axios.com
- Forbes, “Agent2Agent Joins The Agentic AI Foundation Alongside MCP,” 19 August 2026. forbes.com
- Linux Foundation, “Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF),” 9 December 2025. linuxfoundation.org