{"id":585,"date":"2026-03-19T20:05:01","date_gmt":"2026-03-19T20:05:01","guid":{"rendered":"https:\/\/buildconsole.com\/blog\/qcon-london-2026-morgan-stanley-rethinks-its-api-program-for-the-mcp-era\/"},"modified":"2026-03-19T20:05:01","modified_gmt":"2026-03-19T20:05:01","slug":"qcon-london-2026-morgan-stanley-rethinks-its-api-program-for-the-mcp-era","status":"publish","type":"post","link":"https:\/\/buildconsole.com\/blog\/qcon-london-2026-morgan-stanley-rethinks-its-api-program-for-the-mcp-era\/","title":{"rendered":"QCon London 2026: Morgan Stanley Rethinks Its API Program for the MCP Era"},"content":{"rendered":"<p>During the QCon London 2026 conference, Morgan\u202fStanley engineers Jim\u202fGough and Andreea\u202fNiculcea presented a new approach to the bank\u2019s application programming interface (API) strategy. The presentation, held in the main conference hall, focused on how the firm is adapting its API ecosystem to support artificial\u2011intelligence agents through the use of the Microservice Container Platform (MCP) and the FINOS CALM framework. The session attracted developers, architects and security specialists from across the financial services industry.<\/p>\n<h2>Technical Highlights<\/h2>\n<h4>Compliance Guardrails and Deployment Gates<\/h4>\n<p>The live demonstrations showcased a series of compliance guardrails that automatically enforce regulatory requirements during API deployment. Deployment gates were introduced to ensure that each API version passes a set of automated checks before it can be released to production. These gates include static code analysis, security vulnerability scanning and policy compliance verification.<\/p>\n<h4>Zero\u2011Downtime Rollouts Across 100+ APIs<\/h4>\n<p>One of the key achievements highlighted was the ability to roll out updates to more than one hundred APIs without any service interruption. The MCP platform orchestrates traffic routing and can perform blue\u2011green deployments, allowing new API versions to be tested in parallel with the existing ones. Once the new version passes all tests, traffic is switched over seamlessly.<\/p>\n<h4>Reduced Deployment Time<\/h4>\n<p>Historically, the first deployment of an API at Morgan\u202fStanley required a two\u2011year development cycle. The new MCP\u2011CALM integration has cut that time down to just two weeks. The reduction is attributed to automated build pipelines, continuous integration, and the use of declarative configuration files that describe the desired state of each API service.<\/p>\n<h4>Google A2A Protocol Integration<\/h4>\n<p>In addition to the MCP and CALM stack, the engineers demonstrated the Google A2A (Application\u2011to\u2011Application) protocol running alongside MCP. The A2A protocol provides a standardized way for applications to exchange data securely, and its coexistence with MCP shows the bank\u2019s commitment to interoperability with external partners.<\/p>\n<h2>Implications for the Banking Sector<\/h2>\n<p>The presentation illustrates a broader trend in financial technology: the shift toward API\u2011centric architectures that can support autonomous agents and machine\u2011learning workloads. By reducing deployment times and enforcing compliance automatically, banks can accelerate innovation while maintaining regulatory oversight. The zero\u2011downtime rollout capability is particularly relevant for institutions that must keep trading, payments and customer\u2011facing services available 24\/7.<\/p>\n<p>Adopting open\u2011source frameworks such as FINOS CALM also signals a move away from proprietary solutions. CALM provides a common language for API governance, which can simplify collaboration between internal teams and external partners. The integration of Google\u2019s A2A protocol further demonstrates the importance of cross\u2011vendor interoperability in a highly regulated industry.<\/p>\n<h2>Future Outlook<\/h2>\n<p>Following the QCon presentation, Morgan\u202fStanley has announced plans to extend the MCP\u2011CALM stack to all remaining core banking APIs over the next twelve months. The bank\u2019s technology roadmap indicates that the next phase will involve the deployment of AI agents that can autonomously negotiate API contracts and manage data flows in real time. While specific timelines for these releases have not been disclosed, industry observers expect incremental rollouts to begin in the second quarter of 2027.<\/p>\n<p>Regulatory bodies are likely to scrutinize the new compliance guardrails, especially as the bank expands its API offerings to external developers. Morgan\u202fStanley has indicated that it will engage with regulators to ensure that the automated checks meet the latest standards for data protection and financial crime prevention.<\/p>\n<p>Overall, the QCon London 2026 session highlighted a significant evolution in Morgan\u202fStanley\u2019s API strategy, positioning the bank to support next\u2011generation AI services while maintaining stringent compliance and operational resilience. The industry will watch closely as the bank implements these changes and as other financial institutions follow suit in adopting similar open\u2011source frameworks and deployment models.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>During the QCon London 2026 conference, Morgan\u202fStanley engineers Jim\u202fGough and Andreea\u202fNiculcea presented a new approach to the bank\u2019s application programming interface (API) strategy. The presentation, held in the main conference hall, focused on how the firm is adapting its API ecosystem to support artificial\u2011intelligence agents through the use of the Microservice Container Platform (MCP) and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":586,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[127],"tags":[619,621,623,622,620],"class_list":["post-585","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dev-news","tag-qconlondon","tag-apiprogram","tag-digitalbanking","tag-mcpera","tag-morganstanley"],"_links":{"self":[{"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/posts\/585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/comments?post=585"}],"version-history":[{"count":0,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/posts\/585\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/media\/586"}],"wp:attachment":[{"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/media?parent=585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/categories?post=585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buildconsole.com\/blog\/wp-json\/wp\/v2\/tags?post=585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}