GPAI and the EU AI Act: what MCP server builders owe
What the EU AI Act reaches when you ship an MCP server: GPAI duties, Article 50 transparency, the Article 25(4) value-chain rule, and the post-Omnibus dates.
Scoring philosophy, MCP security, and what changed this week.
What the EU AI Act reaches when you ship an MCP server: GPAI duties, Article 50 transparency, the Article 25(4) value-chain rule, and the post-Omnibus dates.
SBOMs, build attestations and SLSA explained for MCP servers, plus our measurement of how many npm and OCI packages publish verified provenance.
Tools do things, resources supply data, prompts are user-invoked templates. How the spec divides them, and the rule for deciding which one you need.
The roles are fixed and easy to get backwards. What a host, a client and a server each do, who initiates, and which side owns the security decisions.
What actually changes when you host an MCP server yourself versus using a managed platform, and the deployment details that decide its trust score today.
What separates a trustworthy MCP server from a popular one: supply-chain checks for packages, connection checks for remote endpoints, and where to look.
The MCP security considerations that matter, as two checklists covering remote endpoints and packaged servers. Every check has a command and a pass condition.