Issue 82
Join 250,000 Founders & CEO's Staying Ahead
Ever reach the end of your workday and wonder what happened in the business world while you were busy running yours? Max’s CEO Report catches you up on the biggest business, tech, and AI stories in just a few minutes.
Each edition gives you the news and context worth knowing, so you can stay informed, spot new opportunities, and sound suspiciously well-read in your next meeting.
Table of Contents
Introduction
In July, I held an API governance roundtable where I invited API governance practitioners – API architects and product managers – to discuss agent-ready APIs. The roundtable included six participants working in enterprises across insurance, finance, logistics, and technology services. I posed the following questions to them:
What does "agent-ready" mean in your organisation, and how are you evaluating your APIs for agent readiness?
What are your thoughts around auth, rate limiting, and observability for agents?
If you had £100K to prepare your API platform for agentic workflows, where would you invest first?
We had a fascinating discussion on these topics. The conversation showed that agent-readiness touches on several areas, including API discovery, identity management, token cost governance, semantic quality, and contextual knowledge management. I captured the key insights in a report that I would like to offer to you for free. You can download it using the link below.
In other news, we have completed our move to the new domain for this newsletter, https://www.apiplatformsforscale.com. This is part of consolidating the branding for this newsletter and our podcast under the API Platforms for Scale brand.
I was in Bengaluru, India, last week for the Apidays India conference. It was a great event, and I’ll bring you some of my key takeaways from it in the next issue of this newsletter. In the meantime, here are some links for your reading pleasure.
Open-Source AI Governance Is Moving Into the Mainstream
As AI adoption accelerates, governance can no longer remain an afterthought or a proprietary capability locked inside individual platforms. This article explores Red Hat's push towards an open-source approach to AI governance, highlighting the need for common frameworks and controls as organisations deploy increasingly complex AI systems. The bigger question is whether open governance can provide the transparency and interoperability enterprises need to scale AI responsibly.
MCP Is Going Stateless, What Changes for Engineers?
MCP's move towards stateless operation could have significant consequences for how teams build and operate agent infrastructure. Michael Levan digs into the engineering details behind the specification changes, exploring what stateless MCP means for sessions, scalability, infrastructure, and deployment patterns. The shift could simplify some architectures—but it also introduces important design considerations for teams running MCP at scale.
AI Agents Don't Just Need to Recover—They Need to Compensate
What happens when an AI agent makes a mistake halfway through a complex workflow? Srinath Perera introduces Robust Agent Compensation (RAC), a recovery approach designed to help AI agents undo or compensate for the effects of failed actions rather than simply retrying from scratch. The approach points towards a more reliable way of handling failures in multi-step, tool-using agent workflows.
Should AI Agents Be Trusted Directly With Your MCP Servers?
Giving every MCP server its own agent authentication setup can quickly become a governance headache. Josh Twist argues for putting a gateway between agents and MCP servers, allowing authentication to be translated centrally while authorisation, tool-level access, and auditing are enforced in one place. The approach also reduces the need to distribute long-lived credentials across MCP infrastructure.
MCP vs APIs: Do You Really Need Both?
MCP isn't replacing APIs, but it is changing who discovers and uses them. Jamdesk Team explains the crucial difference between traditional APIs, where developers handle discovery and integration, and MCP, where AI models can discover and invoke tools at runtime. The interesting part is what this means for teams that already have a mature API strategy.
Your API Can Be Great, and Still Fail Without Good Documentation
A well-designed API is only useful if developers can figure out how to use it. ReadMe Team explores what separates API documentation developers can trust from documentation that quickly becomes outdated and frustrating. From working examples and clear error handling to docs-as-code, analytics, and keeping documentation accessible to AI tools, it offers a practical look at treating documentation as part of the API product, not an afterthought.
Your API Has a New Audience, and It Doesn't Read Like a Developer
What happens when an AI agent, rather than a developer, decides whether to use your API? Austin Rowland article explores the emerging concept of AI-ready APIs, arguing that the standards for API usability are changing. Agents need more than good documentation, they need machine-readable discovery, clear schemas, predictable errors, discoverable authentication, and APIs they can operate without human help.
The Velocity of Everything
What happens when everything in software starts moving faster? API development, AI, tooling, and developer workflows are all accelerating—but speed alone doesn't guarantee better outcomes. Peter Schroeder explores how the increasing velocity of software is changing the way teams build, ship, and manage APIs, raising important questions about whether traditional processes and governance can keep up.
AWS Is Turning AI Agent Governance Into Code
What if you could define exactly what an AI agent is allowed to do—and enforce it automatically? Mike Vizard explores AWS's open-sourcing of Dogwood, a policy language designed specifically for governing AI agents across sequences of actions rather than evaluating each request in isolation. That opens the door to rules around approvals, spending limits, sensitive data, and what an agent can do after a particular action. The interesting shift is from simply authorising an agent's next action to governing its behaviour over time.
LangChain’s dcode: The Governance Story Behind AI Coding Agents
AI coding agents can move fast. But can enterprises trust them with sensitive code? Tom Smith looks beyond dcode itself to the governance layer making agentic coding more viable for enterprise environments. Approval gates, persistent memory, tracing, sandboxing, audit trails and credential isolation point to a bigger shift: the next challenge for AI coding agents may not be what they can build, but how safely organisations can let them operate.
Can MCP Servers Finally Get Their Own OpenAPI?
MCP is gaining traction, but describing and documenting MCP servers still presents a familiar API problem. This article explores whether the lessons of OpenAPI can be applied to MCP, and what a standardised description layer could mean for discovering, documenting, and integrating MCP servers.
What do you think of this newsletter issue?
About this newsletter
The API Platforms for Scale Newsletter curates intelligence on the trends, technologies, and practices shaping API platforms, MCP, developer, and agent experience.




