The Agent Stack Just Got a Neutral Owner
MCP, AGENTS.md and goose now sit inside a Linux Foundation body backed by AWS, Google, Microsoft, Anthropic and Block — and the Gates Foundation just became its first philanthropic member.
The Agentic AI Foundation — formed under the Linux Foundation and anchored by three donated projects — now holds the connective tissue of the agent ecosystem.
The contributions: Anthropic's Model Context Protocol, OpenAI's AGENTS.md, and Block's goose. The membership: OpenAI as co-founder alongside Anthropic and Block, with platinum members AWS, Google, Microsoft, Anthropic and Block, plus support from Bloomberg and Cloudflare. In September it welcomed the Gates Foundation as its first philanthropic member and added TRACE, an open specification for verifiable AI workload evidence built with AMD, Anthropic, Intel, Microsoft and NVIDIA among others.
Its flagship events are now scheduled: AGNTCon + MCPCon Europe ran September 17–18 in Amsterdam; North America follows October 22–23 in San Jose.
Read the founder list again. OpenAI and Anthropic co-founding the same standards body, with all three hyperscalers at platinum, is not a normal configuration.
Why the labs gave these away
MCP is the load-bearing item. It is the protocol by which an agent discovers and calls external tools, and since its release it has become the de facto integration layer for the entire agent ecosystem — thousands of servers, adopted across vendors including the ones competing directly with Anthropic.
Anthropic donating it is the move that makes the foundation credible, and the logic is straightforward. A protocol owned by one lab is a protocol every other lab has a standing incentive to replace. MCP's value is entirely a function of how many tools speak it, and that network effect stalls the moment a competitor decides that adopting it means depending on Anthropic's roadmap. Handing it to a neutral foundation converts a competitive liability into infrastructure — and locks in the position by removing the reason to fork.
OpenAI's AGENTS.md follows the same reasoning at a smaller scale: a convention for how a repository tells an agent what it needs to know. Conventions are worth nothing proprietary and quite a lot universal.
Block's goose is the odd one out and the most telling. It is a working open-source agent framework from a company that is neither a frontier lab nor a hyperscaler — which is precisely the constituency the foundation needs represented if it is going to be more than a cartel of the five largest vendors agreeing with each other.
What TRACE adds
TRACE — Trust, Runtime Attestation and Compliance Evidence — is the piece that turns this from a developer-convenience story into a deployment story.
It generates hardware-attested, cryptographically verifiable records of AI agent and confidential-workload execution: a tamper-proof receipt for every operation that a third party can verify without trusting the operator. It binds the runtime environment, software, policies, data classifications and tool usage into a portable artifact that travels with the workload across clouds and confidential-computing environments. Rather than inventing a new framework, it composes established standards — RATS, EAT, SLSA, SCITT, SPIFFE and EAR — into a single evidence layer.
Contributed by OPAQUE and developed with AMD, Intel, Microsoft and TII, it went to the Linux Foundation for vendor-neutral governance in late August.
The reason this matters: the binding constraint on enterprise agent deployment has stopped being capability and started being provability. A regulated institution cannot run an agent against its systems if it cannot demonstrate afterward what the agent ran, under which policy, against which data classification, with which tools. "The vendor's logs say so" does not survive an audit. TRACE is an attempt to make that demonstration cryptographic and portable, so it holds across clouds and across vendors.
Pair it with MCP and the shape is clear. MCP standardizes what an agent is allowed to reach for. TRACE standardizes the proof of what it actually reached for. Those are the two halves of a governance story that a bank or a hospital can act on.
The Gates Foundation is not decoration
A philanthropic foundation joining a technical standards body reads as public-relations garnish until you consider what it implies about deployment targets.
The Gates Foundation's operating domains — global health, agriculture, financial inclusion, education in low-resource settings — are exactly the environments where agent tooling is most useful and least served. They are also environments where the deployment constraints are severe: intermittent connectivity, minimal local infrastructure, heavy data-sensitivity requirements, and no budget for per-seat frontier licensing.
Those constraints do not get addressed by a commercial roadmap, because the customer cannot pay enough to appear on one. A neutral foundation with a philanthropic member is one of the few structures where that work gets funded and, more importantly, gets a vote on the specification before it is frozen.
What to watch
The failure mode for this kind of body is well documented: a foundation becomes the venue where competitors slow each other down, decisions require consensus among parties who want different outcomes, and the specification ossifies while the market moves around it.
The early evidence points the other way. MCP has been evolving fast under neutral governance, including a session-layer overhaul that would have been far harder to justify under single-vendor ownership. The events calendar is real. The member list spans labs, clouds, enterprise platforms and developer tools rather than one tier.
The stake is whether the agent era gets a shared substrate or five incompatible ones. Every dominant vendor in the category has now bet publicly on the first outcome — which usually means they each concluded they could not win the second.
