read-only demo

Videos CD6R4Wf3jnY

Gateways are All You Need — Karan Sampath, Anthropic

index_state ready data_status ok

AI Engineer· published 2026-04-27· 0:17:48· en-US· indexed 2026-08-10 19:52

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:05, 1 of 1 keyframes kept
  2. Shot 1, 0:05 to 0:09, 1 of 1 keyframes kept
  3. Shot 2, 0:09 to 0:14, 1 of 1 keyframes kept
  4. Shot 3, 0:14 to 1:03, 1 of 1 keyframes kept
  5. Shot 4, 1:03 to 1:07, 1 of 1 keyframes kept
  6. Shot 5, 1:07 to 1:39, 1 of 1 keyframes kept
  7. Shot 6, 1:39 to 1:51, 1 of 1 keyframes kept
  8. Shot 7, 1:51 to 2:06, 0 of 1 keyframes kept
  9. Shot 8, 2:06 to 2:43, 1 of 1 keyframes kept
  10. Shot 9, 2:43 to 3:20, 0 of 1 keyframes kept
  11. Shot 10, 3:20 to 3:27, 1 of 1 keyframes kept
  12. Shot 11, 3:27 to 3:42, 1 of 1 keyframes kept
  13. Shot 12, 3:42 to 4:10, 0 of 1 keyframes kept
  14. Shot 13, 4:10 to 4:45, 1 of 1 keyframes kept
  15. Shot 14, 4:45 to 5:21, 1 of 1 keyframes kept
  16. Shot 15, 5:21 to 5:34, 1 of 1 keyframes kept
  17. Shot 16, 5:34 to 6:02, 1 of 1 keyframes kept
  18. Shot 17, 6:02 to 6:30, 1 of 1 keyframes kept
  19. Shot 18, 6:30 to 6:58, 0 of 1 keyframes kept
  20. Shot 19, 6:58 to 7:14, 1 of 1 keyframes kept
  21. Shot 20, 7:14 to 7:43, 1 of 1 keyframes kept
  22. Shot 21, 7:43 to 8:27, 0 of 1 keyframes kept
  23. Shot 22, 8:27 to 8:58, 1 of 1 keyframes kept
  24. Shot 23, 8:58 to 9:28, 1 of 1 keyframes kept
  25. Shot 24, 9:28 to 9:59, 0 of 1 keyframes kept
  26. Shot 25, 9:59 to 10:07, 1 of 1 keyframes kept
  27. Shot 26, 10:07 to 10:35, 0 of 1 keyframes kept
  28. Shot 27, 10:35 to 11:01, 0 of 1 keyframes kept
  29. Shot 28, 11:01 to 11:26, 1 of 1 keyframes kept
  30. Shot 29, 11:26 to 11:56, 1 of 1 keyframes kept
  31. Shot 30, 11:56 to 12:25, 0 of 1 keyframes kept
  32. Shot 31, 12:25 to 12:54, 0 of 1 keyframes kept
  33. Shot 32, 12:54 to 13:24, 0 of 1 keyframes kept
  34. Shot 33, 13:24 to 13:53, 0 of 1 keyframes kept
  35. Shot 34, 13:53 to 14:23, 1 of 1 keyframes kept
  36. Shot 35, 14:23 to 14:52, 0 of 1 keyframes kept
  37. Shot 36, 14:52 to 15:10, 1 of 1 keyframes kept
  38. Shot 37, 15:10 to 15:25, 1 of 1 keyframes kept
  39. Shot 38, 15:25 to 15:40, 0 of 1 keyframes kept
  40. Shot 39, 15:40 to 15:44, 1 of 1 keyframes kept
  41. Shot 40, 15:44 to 16:03, 1 of 1 keyframes kept
  42. Shot 41, 16:03 to 16:12, 1 of 1 keyframes kept
  43. Shot 42, 16:12 to 16:23, 0 of 1 keyframes kept
  44. Shot 43, 16:23 to 16:55, 1 of 1 keyframes kept
  45. Shot 44, 16:55 to 17:10, 1 of 1 keyframes kept
  46. Shot 45, 17:10 to 17:33, 1 of 1 keyframes kept
  47. Shot 46, 17:33 to 17:47, 1 of 1 keyframes kept

47 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
177
whisperx 177
chunks
31
from 177 cues
keyframes
32
kept of 47 captured
frames with text
32
561 lines read
chapters
11
from the source metadata
keyframe bytes
4.6 MB
word timings on 177 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-10 16:37 1m 47s
stt done 2026-08-10 16:39 22s
chunk done 2026-08-10 16:39 0s
text_embed done 2026-08-10 19:52 1s
keyframe done 2026-08-10 16:40 1m 26s
ocr done 2026-08-10 16:41 12s
frame_embed done 2026-08-10 19:52 5s

Frames, and what the machine read

  • 0:03 #0 done2 line(s)

    shot 0·sharpness 658.4

    1. AlEngineer0.98
    2. EUROPE1.00
  • 0:08 #1 done2 line(s)

    shot 1·sharpness 829.1

    1. PRESENTINGSPONSOR1.00
    2. Google DeepMind1.00
  • 0:13 #2 done3 line(s)

    shot 2·sharpness 907.7

    1. PLATINUM SPONSORS0.98
    2. # Braintrust0.96
    3. WorkOS OpenAI0.95
  • 0:25 #3 done8 line(s)

    shot 3·sharpness 651.9

    1. AlEngineer0.98
    2. MCPs in the Enterp0.99
    3. EUROPE1.00
    4. AKA1.00
    5. Gateways are all y0.96
    6. EU/ACC1.00
    7. AlEngineer1.00
    8. EUROPE1.00
  • 1:04 #4 done11 line(s)

    shot 4·sharpness 1792.0

    1. A bit about me1.00
    2. AIE1.00
    3. 1.00
    4. 1.00
    5. Karan Sampath1.00
    6. Applied AI FDE · First outside AMER0.99
    7. ANTHROP\C1.00
    8. EU/ACC0.89
    9. Google DeepMind1.00
    10. Engineer1.00
    11. 0260.93
  • 1:36 #5 done22 line(s)

    shot 5·sharpness 2594.3

    1. Overview1.00
    2. M0.95
    3. AIE1.00
    4. ANTHROP\C1.00
    5. 1.00
    6. 1.00
    7. 1.00
    8. 0.99
    9. Created at Anthropic0.99
    10. An Official Registry1.00
    11. An open standard for1.00
    12. registry.modelcontextprotocol.1.00
    13. Thousands of Servers1.00
    14. connecting AI to tools & data1.00
    15. io1.00
    16. ...and growing every week0.99
    17. ANTHROP\C1.00
    18. EU/ACC0.95
    19. Braintrust1.00
    20. WorkOS OpenAI0.98
    21. Engineer1.00
    22. 0260.89
  • 1:46 #6 done14 line(s)

    shot 6·sharpness 2101.6

    1. Enterprise State of Play0.99
    2. Observability1.00
    3. AIE1.00
    4. 1.00
    5. 1.00
    6. Who's using my MCP?1.00
    7. What servers and tools are1.00
    8. being used?0.98
    9. ANTHROP\C1.00
    10. EU/ACC0.96
    11. Braintrust1.00
    12. WorkOS OpenAI0.96
    13. Engineer1.00
    14. 0260.90
  • 1:53 #7 skipped

    shot 7·duplicate of #3

  • 2:39 #8 done24 line(s)

    shot 8·sharpness 2933.0

    1. Enterprise State of Play1.00
    2. Observability1.00
    3. Access Control1.00
    4. Security1.00
    5. AIE1.00
    6. 1.00
    7. 1.00
    8. Making it easy to verify0.99
    9. Who's using my MCP?0.99
    10. How do I ensure the1.00
    11. security posture of1.00
    12. What servers and tools are1.00
    13. correct users have access1.00
    14. various servers1.00
    15. being used?0.99
    16. to each server?0.99
    17. Allowing remote clients to1.00
    18. access private servers1.00
    19. ANTHROP\C1.00
    20. EU/ACC0.97
    21. AlEngineer0.96
    22. Engineer1.00
    23. EUROPE1.00
    24. 0260.97
  • 3:16 #9 skipped

    shot 9·duplicate of #8

  • 3:25 #10 done28 line(s)

    shot 10·sharpness 3081.7

    1. Registries Help — But Aren't Enough for Enterprises0.99
    2. U0.74
    3. References1.00
    4. npm1.00
    5. python1.00
    6. AIE1.00
    7. 1.00
    8. MCP Servers1.00
    9. Official MCP Registry0.99
    10. 1.00
    11. 1.00
    12. 1.00
    13. 1.00
    14. ✓ Registries give you0.97
    15. x Still missing for the enterprise0.97
    16. Discovery of public servers1.00
    17. Authentication & SSO1.00
    18. Centralized metadata1.00
    19. Access control / RBAC0.99
    20. Unified installation1.00
    21. Observability & audit logs0.98
    22. Credential management1.00
    23. ANTHROP\C1.00
    24. 51.00
    25. BU/ACC0.95
    26. Engineering the future of Al0.99
    27. Engineer1.00
    28. 0260.96
  • 3:37 #11 done9 line(s)

    shot 11·sharpness 615.5

    1. ies Help - But Aren't0.97
    2. AlEngineer0.99
    3. EUROPE1.00
    4. ✓ Registries give you0.98
    5. Discovery of publie servers0.95
    6. Centralized metadata0.98
    7. Unified installation0.97
    8. AlEngineer1.00
    9. EUROPE1.00
  • 3:48 #12 skipped

    shot 12·duplicate of #10

  • 4:38 #13 done23 line(s)

    shot 13·sharpness 2013.0

    1. The Bottleneck1.00
    2. Infra MCP0.99
    3. Knowledge Base1.00
    4. AIE1.00
    5. MCP1.00
    6. 1.00
    7. SECURITY1.00
    8. 1.00
    9. 1.00
    10. CRM MCP1.00
    11. REVIEW1.00
    12. Approved1.00
    13. Analytics MCP1.00
    14. DevOps MCP1.00
    15. Teams want to ship1.00
    16. Most enterprises stay with a handful of MCP servers — often very0.98
    17. ANTHROP\C0.99
    18. few tools1.00
    19. EU/ACC0.94
    20. AlEngineer0.97
    21. Engineer1.00
    22. EUROPE1.00
    23. 0260.97
  • 5:10 #14 done21 line(s)

    shot 14·sharpness 2023.4

    1. The Bottleneck1.00
    2. Infra MCP0.99
    3. Knowledge Base1.00
    4. AIE1.00
    5. MCP1.00
    6. SECURITY1.00
    7. 1.00
    8. 1.00
    9. CRM MCP1.00
    10. REVIEW1.00
    11. Approved1.00
    12. Analytics MCP1.00
    13. DevOps MCP1.00
    14. Teams want to ship1.00
    15. Most enterprises stay with a handful of MCP servers — often very0.98
    16. ANTHROP\C1.00
    17. few tools0.98
    18. BU/ACC0.93
    19. Engineering the future of Al1.00
    20. Engineer1.00
    21. 0260.90
  • 5:30 #15 done15 line(s)

    shot 15·sharpness 1196.9

    1. 660.99
    2. These are important papercuts.1.00
    3. AIE1.00
    4. 1.00
    5. 1.00
    6. 1.00
    7. 0.99
    8. The protocol is incredibly powerful –0.97
    9. But we must invest in better infrastructure to0.99
    10. realize its value.1.00
    11. ANTHROPIC0.97
    12. EU/ACC0.68
    13. Engineering the future of Al0.97
    14. Engineer1.00
    15. 0260.84
  • 5:53 #16 done14 line(s)

    shot 16·sharpness 2224.8

    1. THE FIX0.93
    2. Don't hand-roll MCPs.0.99
    3. Establish a Root of Trust.1.00
    4. AIE1.00
    5. 1.00
    6. 1.00
    7. Security blesses one platform →1.00
    8. Teams ship MCPs that focus on business logic1.00
    9. ANTHROP\C1.00
    10. 81.00
    11. EU/ACC0.90
    12. Engineering the future of Al0.99
    13. Engineer1.00
    14. 0260.86
  • 6:05 #17 done16 line(s)

    shot 17·sharpness 2216.7

    1. THEFIX1.00
    2. Don't hand-roll MCPs.0.99
    3. AIE1.00
    4. Establish a Root of Trust.0.99
    5. 1.00
    6. 1.00
    7. 1.00
    8. Security blesses one platform →1.00
    9. Teams ship MCPs that focus on business logic0.99
    10. ANTHROP\C1.00
    11. 81.00
    12. EU/ACC0.92
    13. AlEngineer0.96
    14. Engineer1.00
    15. EUROPE1.00
    16. 0260.90
  • 6:44 #18 skipped

    shot 18·duplicate of #17

  • 7:01 #19 done18 line(s)

    shot 19·sharpness 2034.9

    1. What is a Gateway?0.98
    2. Your network1.00
    3. AIE1.00
    4. MCP1.00
    5. GATEWAY1.00
    6. MCP1.00
    7. 0.98
    8. CLIENTS1.00
    9. SERVERS1.00
    10. 1.00
    11. 1.00
    12. Auth · Authz · Ops · Deploy · Connect0.95
    13. Your enterprise control plane for MCPs1.00
    14. ANTHROP\C1.00
    15. EU/ACC0.95
    16. Engineering the future of Al0.99
    17. Engineer1.00
    18. 0260.92
  • 7:20 #20 done11 line(s)

    shot 20·sharpness 596.3

    1. a Gateway?1.00
    2. AlEngineer0.99
    3. EUROPE1.00
    4. MCP1.00
    5. GATEV1.00
    6. CLIENTS1.00
    7. EU/ACC1.00
    8. Auth · Authz· Ops0.92
    9. Your enterprise contr0.95
    10. AlEngineer1.00
    11. EUROPE1.00
  • 7:53 #21 skipped

    shot 21·duplicate of #19

  • 8:45 #22 done25 line(s)

    shot 22·sharpness 2372.2

    1. Inside the Gateway1.00
    2. Your network1.00
    3. GATEWAY1.00
    4. AIE1.00
    5. Auth Handler1.00
    6. RBAC Engine1.00
    7. Proxy Router1.00
    8. 1.00
    9. 1.00
    10. 1.00
    11. MCP1.00
    12. MCP1.00
    13. CLIENTS1.00
    14. SERVERS1.00
    15. Tunnel1.00
    16. Subregistry0.98
    17. Tooling1.00
    18. Handler1.00
    19. CLI · MCP server0.97
    20. ANTHROP\C1.00
    21. EU/ACC0.94
    22. Braintrust1.00
    23. WorkOS OpenAI0.93
    24. Engineer1.00
    25. 0260.96
  • 9:22 #23 done25 line(s)

    shot 23·sharpness 2277.9

    1. Inside the Gateway1.00
    2. Your network1.00
    3. GATEWAY1.00
    4. AIE1.00
    5. Auth Handler1.00
    6. RBAC Engine1.00
    7. Proxy Router1.00
    8. 1.00
    9. 1.00
    10. 1.00
    11. MCP1.00
    12. MCP1.00
    13. CLIENTS1.00
    14. SERVERS1.00
    15. Tunnel1.00
    16. Subregistry0.98
    17. Tooling1.00
    18. Handler1.00
    19. CLI · MCP server0.99
    20. ANTHROP\C1.00
    21. EU/ACC0.97
    22. AlEngineer0.97
    23. Engineer1.00
    24. EUROPE1.00
    25. 0260.96

Transcript

177 cues· 3,443 words· 18,670 chars

  1. 0:14 All right, so, hey everyone, I'm Karan Sampath.
  2. 0:19 I'll be talking to you about how we at Anthropic think about MCPs in the enterprise.
  3. 0:26 I've alternatively titled it, I think more casually, is why we think gateways are all you need.
  4. 0:31 So before I go into the talk, I'm gonna quickly tell you a bit about me.
  5. 0:34 I'm a forward deploy engineer at Anthropic, first one outside the US.
  6. 0:40 A lot of my work includes working with enterprises on things like MCPs, and I also work on our internal use cases.
  7. 0:47 In this talk, I'm gonna be
  8. 0:49 positing to you what we think the problems with enterprises, what enterprises face with MCPs today, why we think gateways and the necessary implications that come out of it are the best way to fix a lot of these problems, and how does that align with our future vision for agent tech deployments?
  9. 1:07 So before we go on, I know a lot of you already know this.
  10. 1:09 I'm going to quickly run through this.
  11. 1:11 But just a very quick overview of MCPs as it is relevant today.
  12. 1:14 The first is, of course, we all know it's an open standard that was created.
  13. 1:17 Most of us know that at Anthropic.
  14. 1:19 There is an official registry today which contains over thousands of servers, and this has grown rapidly over the last year.
  15. 1:26 And we see this happening that individual companies all the time are building new servers very quickly and are trying to ensure that they stay ahead and try to adhere to this protocol nowadays.
  16. 1:36 But still, even if this happens, we see a major problem where enterprises try to use it.
  17. 1:42 Enterprises struggle to deal with what they believe to be table stakes.
  18. 1:46 Things like observability.
  19. 1:47 When they want to know who's using my MCP, who's using these tools, how do I ensure that the correct people are using it, and how do I know how to develop on certain parts of my MCP protocol which parts of my tools aren't working properly.
  20. 2:00 These are something that's simply completely opaque to enterprises today.
  21. 2:03 Second is access control, something I just touched upon already, right?
  22. 2:07 How do I ensure the correct users have access to these servers?
  23. 2:10 Things like ensuring that certain servers are scoped correctly, tools are only made
  24. 2:15 are only allowed for certain groups of servers.
  25. 2:17 If you're working in observability MCP, you might want the entire company to have view into which things are failing, but only certain people to have the ability to actually change things and update new dashboards.
  26. 2:28 These are the kind of things that are currently quite hard to do with MCP servers,
  27. 2:31 And honestly, not something that we as a community have worked on enough.
  28. 2:35 And finally, security.
  29. 2:37 I like to think of the three of these as almost like a three-headed hydra in some ways, right?
  30. 2:41 Security is a wide range of things.
  31. 2:43 I like to think not only in terms of the MCP server, where enterprises want to know how do you verify whether a server is safe, it has the correct protocols and the correct ways of ensuring data exfiltration doesn't occur, things like the tools can't be used in a harmful way, both for infrastructure,
  32. 3:01 externally, but your internal infrastructure as well.
  33. 3:04 But secondly, how do you ensure remote clients that are perhaps untrusted in nature can access your private data as an enterprise, right?
  34. 3:11 These are all really hard problems that you've kind of solved in previous paradigms with APIs, but we really don't have a good way of solving it at the moment.
  35. 3:20 So just going back to the registry point, it's really useful to think of where we are and where we wanna go, right?
  36. 3:26 Registries are really useful, and I don't think there's any discussion that here where we're having where we think they're not useful.
  37. 3:31 We're really proud of it, we're really happy we helped develop this.
  38. 3:34 But it's very important to realize that registry simply aren't complete for an enterprise.
  39. 3:39 And what's funny about this is that MCPs are specifically designed, if you attended David's talk earlier today,
  40. 3:47 MCPs are specifically designed because they allow themselves to be so much more useful for enterprises.
  41. 3:51 And there's this kind of gap which the protocol allows for that we have yet to build into well.
  42. 3:57 And these include things like authentication, but also access control, observability, and credential management.
  43. 4:01 These are all things that enterprises need in the critical part, but are simply not working.
  44. 4:06 So now that we have this happening, what do enterprises do nowadays?
  45. 4:11 What they do is something like this, where every single team now with Cloud Code and explosion of coding across various surfaces can now start developing MCPs.
  46. 4:22 but suddenly find out that they can't actually get them deployed.
  47. 4:25 Or even if they want to get them deployed, the MCPs often can't use the tools they want to, those tools can't give them the correct access, and security teams on the other end are also pretty justified how they're going about it because they're often overloaded and they're often unable to see which MCPs they want to go through and which they want to allow.
  48. 4:43 And finally, at the company level, CEOs and C-suites are like, why are my MCPs not working correctly?
  49. 4:49 Why are my agents ineffective?
  50. 4:51 Why can't your agents actually be the thing that we all thought it was going to be?

Chapters

  1. 0:00 <Untitled Chapter 1>
  2. 0:14 Introduction: Enterprise MCP challenges.
  3. 1:13 Enterprise Hurdles: Observability, access control, and security (the "three-headed hydra").
  4. 3:35 Deployment Bottlenecks: Scalability limits of current decentralized models.
  5. 5:35 The Case for Gateways: Establishing a unified "root of trust."
  6. 7:00 Gateway Definition: A middleware layer for auth, proxying, and routing.
  7. 8:28 Core Components: Implementing OAuth, tunnels, and developer CLIs.
  8. 10:03 Strategic Benefits: Improved authentication and standardized access control.
  9. 11:30 Operational Gains: Multi-surface integration, security, and faster iteration.
  10. 15:13 Future Vision: Decoupling agent architecture from data layers.
  11. 16:58 Summary: Invest in common infrastructure to scale enterprise agents.

Open at this second