Videos CD6R4Wf3jnY
Gateways are All You Need — Karan Sampath, Anthropic
Scene timeline
47 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 177
- whisperx 177
- chunks
- 31
- from 177 cues
- keyframes
- 32
- kept of 47 captured
- frames with text
- 32
- 561 lines read
- chapters
- 11
- from the source metadata
- keyframe bytes
- 4.6 MB
- word timings on 177 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 16:37 | 1m 47s |
stt |
done | — | 2026-08-10 16:39 | 22s |
chunk |
done | — | 2026-08-10 16:39 | 0s |
text_embed |
done | — | 2026-08-10 19:52 | 1s |
keyframe |
done | — | 2026-08-10 16:40 | 1m 26s |
ocr |
done | — | 2026-08-10 16:41 | 12s |
frame_embed |
done | — | 2026-08-10 19:52 | 5s |
Frames, and what the machine read
-
- AlEngineer0.98
- EUROPE1.00
-
- PRESENTINGSPONSOR1.00
- Google DeepMind1.00
-
- PLATINUM SPONSORS0.98
- # Braintrust0.96
- WorkOS OpenAI0.95
-
- AlEngineer0.98
- MCPs in the Enterp0.99
- EUROPE1.00
- AKA1.00
- Gateways are all y0.96
- EU/ACC1.00
- AlEngineer1.00
- EUROPE1.00
-
- A bit about me1.00
- AIE1.00
- ★1.00
- ★1.00
- Karan Sampath1.00
- Applied AI FDE · First outside AMER0.99
- ANTHROP\C1.00
- EU/ACC0.89
- Google DeepMind1.00
- Engineer1.00
- 0260.93
-
- Overview1.00
- M0.95
- AIE1.00
- ANTHROP\C1.00
- ★1.00
- ★1.00
- ★1.00
- ★0.99
- Created at Anthropic0.99
- An Official Registry1.00
- An open standard for1.00
- registry.modelcontextprotocol.1.00
- Thousands of Servers1.00
- connecting AI to tools & data1.00
- io1.00
- ...and growing every week0.99
- ANTHROP\C1.00
- EU/ACC0.95
- Braintrust1.00
- WorkOS OpenAI0.98
- Engineer1.00
- 0260.89
-
- Enterprise State of Play0.99
- Observability1.00
- AIE1.00
- ★1.00
- ★1.00
- Who's using my MCP?1.00
- What servers and tools are1.00
- being used?0.98
- ANTHROP\C1.00
- EU/ACC0.96
- Braintrust1.00
- WorkOS OpenAI0.96
- Engineer1.00
- 0260.90
-
- Enterprise State of Play1.00
- Observability1.00
- Access Control1.00
- Security1.00
- AIE1.00
- ★1.00
- ★1.00
- Making it easy to verify0.99
- Who's using my MCP?0.99
- How do I ensure the1.00
- security posture of1.00
- What servers and tools are1.00
- correct users have access1.00
- various servers1.00
- being used?0.99
- to each server?0.99
- Allowing remote clients to1.00
- access private servers1.00
- ANTHROP\C1.00
- EU/ACC0.97
- AlEngineer0.96
- Engineer1.00
- EUROPE1.00
- 0260.97
-
- Registries Help — But Aren't Enough for Enterprises0.99
- U0.74
- References1.00
- npm1.00
- python1.00
- AIE1.00
- ★1.00
- MCP Servers1.00
- Official MCP Registry0.99
- ★1.00
- ★1.00
- ★1.00
- ★1.00
- ✓ Registries give you0.97
- x Still missing for the enterprise0.97
- Discovery of public servers1.00
- Authentication & SSO1.00
- Centralized metadata1.00
- Access control / RBAC0.99
- Unified installation1.00
- Observability & audit logs0.98
- Credential management1.00
- ANTHROP\C1.00
- 51.00
- BU/ACC0.95
- Engineering the future of Al0.99
- Engineer1.00
- 0260.96
-
- ies Help - But Aren't0.97
- AlEngineer0.99
- EUROPE1.00
- ✓ Registries give you0.98
- Discovery of publie servers0.95
- Centralized metadata0.98
- Unified installation0.97
- AlEngineer1.00
- EUROPE1.00
-
- The Bottleneck1.00
- Infra MCP0.99
- Knowledge Base1.00
- AIE1.00
- MCP1.00
- ★1.00
- SECURITY1.00
- ★1.00
- ★1.00
- CRM MCP1.00
- REVIEW1.00
- Approved1.00
- Analytics MCP1.00
- DevOps MCP1.00
- Teams want to ship1.00
- Most enterprises stay with a handful of MCP servers — often very0.98
- ANTHROP\C0.99
- few tools1.00
- EU/ACC0.94
- AlEngineer0.97
- Engineer1.00
- EUROPE1.00
- 0260.97
-
- The Bottleneck1.00
- Infra MCP0.99
- Knowledge Base1.00
- AIE1.00
- MCP1.00
- SECURITY1.00
- ★1.00
- ★1.00
- CRM MCP1.00
- REVIEW1.00
- Approved1.00
- Analytics MCP1.00
- DevOps MCP1.00
- Teams want to ship1.00
- Most enterprises stay with a handful of MCP servers — often very0.98
- ANTHROP\C1.00
- few tools0.98
- BU/ACC0.93
- Engineering the future of Al1.00
- Engineer1.00
- 0260.90
-
- 660.99
- These are important papercuts.1.00
- AIE1.00
- ★1.00
- ★1.00
- ★1.00
- ★0.99
- The protocol is incredibly powerful –0.97
- But we must invest in better infrastructure to0.99
- realize its value.1.00
- ANTHROPIC0.97
- EU/ACC0.68
- Engineering the future of Al0.97
- Engineer1.00
- 0260.84
-
- THE FIX0.93
- Don't hand-roll MCPs.0.99
- Establish a Root of Trust.1.00
- AIE1.00
- ★1.00
- ★1.00
- Security blesses one platform →1.00
- Teams ship MCPs that focus on business logic1.00
- ANTHROP\C1.00
- 81.00
- EU/ACC0.90
- Engineering the future of Al0.99
- Engineer1.00
- 0260.86
-
- THEFIX1.00
- Don't hand-roll MCPs.0.99
- AIE1.00
- Establish a Root of Trust.0.99
- ★1.00
- ★1.00
- ★1.00
- Security blesses one platform →1.00
- Teams ship MCPs that focus on business logic0.99
- ANTHROP\C1.00
- 81.00
- EU/ACC0.92
- AlEngineer0.96
- Engineer1.00
- EUROPE1.00
- 0260.90
-
- What is a Gateway?0.98
- Your network1.00
- AIE1.00
- MCP1.00
- GATEWAY1.00
- MCP1.00
- ★0.98
- CLIENTS1.00
- SERVERS1.00
- ★1.00
- ★1.00
- Auth · Authz · Ops · Deploy · Connect0.95
- Your enterprise control plane for MCPs1.00
- ANTHROP\C1.00
- EU/ACC0.95
- Engineering the future of Al0.99
- Engineer1.00
- 0260.92
-
- a Gateway?1.00
- AlEngineer0.99
- EUROPE1.00
- MCP1.00
- GATEV1.00
- CLIENTS1.00
- EU/ACC1.00
- Auth · Authz· Ops0.92
- Your enterprise contr0.95
- AlEngineer1.00
- EUROPE1.00
-
- Inside the Gateway1.00
- Your network1.00
- GATEWAY1.00
- AIE1.00
- Auth Handler1.00
- RBAC Engine1.00
- Proxy Router1.00
- ★1.00
- ★1.00
- ★1.00
- MCP1.00
- MCP1.00
- CLIENTS1.00
- SERVERS1.00
- Tunnel1.00
- Subregistry0.98
- Tooling1.00
- Handler1.00
- CLI · MCP server0.97
- ANTHROP\C1.00
- EU/ACC0.94
- Braintrust1.00
- WorkOS OpenAI0.93
- Engineer1.00
- 0260.96
-
- Inside the Gateway1.00
- Your network1.00
- GATEWAY1.00
- AIE1.00
- Auth Handler1.00
- RBAC Engine1.00
- Proxy Router1.00
- ★1.00
- ★1.00
- ★1.00
- MCP1.00
- MCP1.00
- CLIENTS1.00
- SERVERS1.00
- Tunnel1.00
- Subregistry0.98
- Tooling1.00
- Handler1.00
- CLI · MCP server0.99
- ANTHROP\C1.00
- EU/ACC0.97
- AlEngineer0.97
- Engineer1.00
- EUROPE1.00
- 0260.96
Transcript
177 cues· 3,443 words· 18,670 chars
- 0:14 All right, so, hey everyone, I'm Karan Sampath.
- 0:19 I'll be talking to you about how we at Anthropic think about MCPs in the enterprise.
- 0:26 I've alternatively titled it, I think more casually, is why we think gateways are all you need.
- 0:31 So before I go into the talk, I'm gonna quickly tell you a bit about me.
- 0:34 I'm a forward deploy engineer at Anthropic, first one outside the US.
- 0:40 A lot of my work includes working with enterprises on things like MCPs, and I also work on our internal use cases.
- 0:47 In this talk, I'm gonna be
- 0:49 positing to you what we think the problems with enterprises, what enterprises face with MCPs today, why we think gateways and the necessary implications that come out of it are the best way to fix a lot of these problems, and how does that align with our future vision for agent tech deployments?
- 1:07 So before we go on, I know a lot of you already know this.
- 1:09 I'm going to quickly run through this.
- 1:11 But just a very quick overview of MCPs as it is relevant today.
- 1:14 The first is, of course, we all know it's an open standard that was created.
- 1:17 Most of us know that at Anthropic.
- 1:19 There is an official registry today which contains over thousands of servers, and this has grown rapidly over the last year.
- 1:26 And we see this happening that individual companies all the time are building new servers very quickly and are trying to ensure that they stay ahead and try to adhere to this protocol nowadays.
- 1:36 But still, even if this happens, we see a major problem where enterprises try to use it.
- 1:42 Enterprises struggle to deal with what they believe to be table stakes.
- 1:46 Things like observability.
- 1:47 When they want to know who's using my MCP, who's using these tools, how do I ensure that the correct people are using it, and how do I know how to develop on certain parts of my MCP protocol which parts of my tools aren't working properly.
- 2:00 These are something that's simply completely opaque to enterprises today.
- 2:03 Second is access control, something I just touched upon already, right?
- 2:07 How do I ensure the correct users have access to these servers?
- 2:10 Things like ensuring that certain servers are scoped correctly, tools are only made
- 2:15 are only allowed for certain groups of servers.
- 2:17 If you're working in observability MCP, you might want the entire company to have view into which things are failing, but only certain people to have the ability to actually change things and update new dashboards.
- 2:28 These are the kind of things that are currently quite hard to do with MCP servers,
- 2:31 And honestly, not something that we as a community have worked on enough.
- 2:35 And finally, security.
- 2:37 I like to think of the three of these as almost like a three-headed hydra in some ways, right?
- 2:41 Security is a wide range of things.
- 2:43 I like to think not only in terms of the MCP server, where enterprises want to know how do you verify whether a server is safe, it has the correct protocols and the correct ways of ensuring data exfiltration doesn't occur, things like the tools can't be used in a harmful way, both for infrastructure,
- 3:01 externally, but your internal infrastructure as well.
- 3:04 But secondly, how do you ensure remote clients that are perhaps untrusted in nature can access your private data as an enterprise, right?
- 3:11 These are all really hard problems that you've kind of solved in previous paradigms with APIs, but we really don't have a good way of solving it at the moment.
- 3:20 So just going back to the registry point, it's really useful to think of where we are and where we wanna go, right?
- 3:26 Registries are really useful, and I don't think there's any discussion that here where we're having where we think they're not useful.
- 3:31 We're really proud of it, we're really happy we helped develop this.
- 3:34 But it's very important to realize that registry simply aren't complete for an enterprise.
- 3:39 And what's funny about this is that MCPs are specifically designed, if you attended David's talk earlier today,
- 3:47 MCPs are specifically designed because they allow themselves to be so much more useful for enterprises.
- 3:51 And there's this kind of gap which the protocol allows for that we have yet to build into well.
- 3:57 And these include things like authentication, but also access control, observability, and credential management.
- 4:01 These are all things that enterprises need in the critical part, but are simply not working.
- 4:06 So now that we have this happening, what do enterprises do nowadays?
- 4:11 What they do is something like this, where every single team now with Cloud Code and explosion of coding across various surfaces can now start developing MCPs.
- 4:22 but suddenly find out that they can't actually get them deployed.
- 4:25 Or even if they want to get them deployed, the MCPs often can't use the tools they want to, those tools can't give them the correct access, and security teams on the other end are also pretty justified how they're going about it because they're often overloaded and they're often unable to see which MCPs they want to go through and which they want to allow.
- 4:43 And finally, at the company level, CEOs and C-suites are like, why are my MCPs not working correctly?
- 4:49 Why are my agents ineffective?
- 4:51 Why can't your agents actually be the thing that we all thought it was going to be?
loading
Chapters
- 0:00 <Untitled Chapter 1>
- 0:14 Introduction: Enterprise MCP challenges.
- 1:13 Enterprise Hurdles: Observability, access control, and security (the "three-headed hydra").
- 3:35 Deployment Bottlenecks: Scalability limits of current decentralized models.
- 5:35 The Case for Gateways: Establishing a unified "root of trust."
- 7:00 Gateway Definition: A middleware layer for auth, proxying, and routing.
- 8:28 Core Components: Implementing OAuth, tunnels, and developer CLIs.
- 10:03 Strategic Benefits: Improved authentication and standardized access control.
- 11:30 Operational Gains: Multi-surface integration, security, and faster iteration.
- 15:13 Future Vision: Decoupling agent architecture from data layers.
- 16:58 Summary: Invest in common infrastructure to scale enterprise agents.