Agents vs MCP: The actor and the connection

  • Nick Donaldson

    Nick Donaldson

    Senior Director of Growth, Knak

Published Aug 10, 2026

Agents vs MCP: The actor and the connection

Dive deeper with AI

Two words are doing a lot of work in marketing conversations right now, and people tend to use them as if they compete: agent and MCP. They don't compete. An AI agent is software that takes actions toward a goal. MCP, the Model Context Protocol, is the standard connection that lets an agent or an assistant reach a tool, including your inbox. One is the actor. The other is the wire the actor reaches through. Treat them as rivals and you end up governing the wrong thing, which in an enterprise is the expensive kind of mistake.

Both are already touching email, which is why the distinction is worth ten minutes. The protocol that assistants use to reach tools scaled roughly 970 times in under two years, from about 100,000 monthly SDK downloads at its late-2024 launch to around 97 million by early 2026. That is not a forecast. That is adoption that already happened, and it means the plumbing for an AI to reach into a mailbox is being laid faster than most marketing teams have written a policy for it.

What an AI agent is

Start with the agent, because it is the easier of the two to pin down. An AI agent pursues a goal by taking a sequence of actions, choosing each next step from what happened in the last one. The plain test is whether it acts or only answers. A model that drafts a subject line when you ask is answering. A system that reads your inbox, decides which three messages need a reply today, drafts them, and files the rest is acting. The second one is an agent because it strings actions together toward an outcome without a human directing each step.

Agents come in two shapes that are easy to mix up, and the difference is where the agent lives. A provider-built agent lives inside the product: Gmail's Gemini features, Outlook's Copilot, Apple Intelligence in Mail. These are scoped by the provider, run on the provider's terms, and can only do what the product exposes. The other shape is your own AI pointed at the inbox from outside, the Claude or ChatGPT you asked to go do some work for you. That external agent needs a way in. It can't touch your mail by wishing. It needs a connection, and that connection is where MCP comes in, at a genuinely different layer of the stack.

What an MCP is

MCP is an open standard for how an AI application connects to an external tool or data source. Before a shared standard existed, every assistant needed a bespoke integration for every tool, which is the same integration sprawl any marketing-ops leader knows from wiring a MAP to a CRM to a CDP. MCP is the attempt at one connector pattern that any assistant can speak and any tool can expose, the way a common port replaced a drawer full of proprietary cables.

The scale of what is being wired up is worth a pause. Public directories already list hundreds of marketing-automation MCP servers, and Zapier's MCP alone fronts roughly 8,000 apps and 40,000 actions. On the inbox specifically, a cluster of Gmail MCP servers already exists, most of them open-source projects built by individual developers, connecting over the Gmail API with OAuth. The point isn't the roster. The point is that MCP is the connection, not the actor. It decides nothing. It carries the request from the agent to the tool and the response back.

So the relationship is layered, not rival. The agent forms the intent, clear my inbox and flag anything from a customer. MCP is how that intent reaches Gmail and how Gmail's data comes back. Ask which is better, agent or MCP, and the question doesn't parse, the way asking whether a driver is better than a road doesn't parse.

Why the difference changes how you govern

The reason this is worth getting right is that the agent and the connection raise different questions, and most of the risk lives at the connection. An agent's behavior is bounded by what the connection permits. Grant an assistant full mailbox access when read-only would have done the job, and the agent can now do far more than the task required, and so can anything that hijacks it. That isn't hypothetical. The documented failure modes are concrete. Indirect prompt injection, where instructions hidden in an email body get read by the agent and treated as commands, potentially moving data out with no click from the user. Over-broad OAuth scopes, where a server asks for the whole mailbox when a single label would do. Tool poisoning on hosted servers, where a connection you trusted changes what it does after you granted it access. Each of these lives at the connection layer, which is exactly why treating MCP as just plumbing is the mistake.

The defenses live at the same layer, and they are just as concrete. Least-privilege scopes, so the agent gets read-only when it only needs to read. Content sanitization, so the email body is cleaned before the model sees it and is harder to smuggle instructions through. Provider-governed servers with admin control, the model Microsoft uses with its Work IQ MCP inside Agent 365, where an administrator sets what the agent may reach through a managed identity layer rather than an individual pasting credentials into a config file. The pattern to notice is that the safe versions put control at the connection, not inside the agent's reasoning, because you can't reliably reason a model out of following a well-crafted injected instruction.

For an enterprise marketing team, that reframes the buying question. You are not really asking whether to let AI into the inbox. You are asking through what connection, at what scope, and under whose administration. That is a governance question, and it is the one the agent-versus-MCP confusion hides.

The connection is also how AI reaches what you send

There is a second reason the connection layer matters to marketers, and it points back at what you send rather than what you receive. As assistants increasingly reach content through governed connections instead of by rendering a decorated HTML email, the thing that travels well through that connection is structured content a machine can parse correctly. An image-only email is opaque to an agent reading over a protocol. Structured, labeled content survives the trip. It is the same machine-readability argument the receiver-side AI already forced, arriving now from the connection side too.

This is where a production platform earns a mention, and it earns it on the governance argument rather than a feature list. Knak shipped its own MCP server in April 2026, and the reason it fits here isn't that it exists. It is that an MCP server run by the platform makes the connection a governed one. An administrator decides what an assistant may reach, at what scope, under a managed identity, rather than a marketer wiring a personal credential to a mailbox by hand. The connection stops being an individual's side project and becomes something the enterprise controls. The connection is where control belongs, and a governed server is how you put it there.

What to hold onto

Keep the two apart and the inbox conversation gets clearer. An agent is the software that takes actions toward a goal. MCP is the standard connection it reaches tools through. They are different layers, so the real questions are what the agent may do and what the connection permits, and you can reason about capability and control separately instead of arguing about which word wins.

One caveat is worth keeping on the record: the MCP specification is still a release candidate as of July 28, 2026, with breaking changes in flight, so the exact shape of what these connections permit will keep moving for a while. The direction is set even if the details are not: structured, governed, machine-readable connections are how AI reaches the inbox, and the control lives at the connection. If you want to see how a governed connection works in practice rather than in the abstract, book a demo and Knak's team will walk the setup with you.


Share this article

  • Nick Donaldson 2025 headshot gradient

    Author

    Nick Donaldson

    Senior Director of Growth, Knak

Why marketing teams love Knak

  • 95%better, faster campaigns = more success

  • 22 minutesto create an email*

  • 5x lessthan the cost of a developer

  • 50x lessthan the cost of an agency**

* On average, for enterprise customers

** Knak base price

Ready to see Knak in action?

Get a demo and discover how visionary marketers use Knak to speed up their campaign creation.

Watch a Demo
green sphere graphic used for decorative accents - Knak.com