[Explanation] Expanded the Claude Managed Agents platform and added the MCP tunnel

IT

Anthropic has added the “MCP Tunnel” to its AI agent construction platform, “Claude Managed Agents,” enabling secure internal connections. This expansion aims to accelerate the vertical integration of infrastructure that enables companies to build advanced AI autonomous execution environments without leaking confidential data externally.

Key Points of the Announcement and Enterprise Market Background

On May 19, 2026, Anthropic announced that it has significantly expanded the capabilities of its AI agent building and operation platform “Claude Managed Agents,” launching the MCP tunnel (research preview version) and a self-hosted sandbox (public beta). This announcement is positioned as a decisive step for AI agents to transition from experimental stages to production operations.

Until now, the biggest barrier for companies implementing AI agents has been secure connections with internal systems that hold sensitive information such as customer lists and sales data. Since launching Managed Agents in April 2026, Anthropic has been rolling out vertically integrated services that reduce infrastructure work from several months to just a few days. With this new feature, even companies with stringent security requirements can safely operate agents under their own governance. In fact, major companies such as Notion in the US, Rakuten Group, and Sentry have already announced their adoption, and AI agents are expected to become the new standard for utilizing AI agents. The diagram below shows the barriers to enterprise adoption that the new feature solves.

Figure 1

Innovative communication model with MCP tunnels

The core technical component, the “MCP tunnel,” is a mechanism that enables secure connections to the Model Context Protocol (MCP) server. With conventional systems, when external AI used the internal database, it was necessary to open the entrance to the internet side and drill inbound (received) holes in the firewall. However, the MCP tunnel reverses this model.

Specifically, a small gateway (relay software) is installed within the customer’s network, and from there, a single outbound encrypted communication is established to the Anthropic side. This communication is end-to-end protected and built using Cloudflared, Cloudflare’s open-source tunnel connector. This enables the security personnel to securely integrate critical resources such as internal databases, private APIs, and knowledge bases as agents without opening inbound ports—the main concern for corporate security personnel.

Redefining Security and Governance

Realizing a Credential-Holding Architecture

Its biggest security feature is the “Credential at the Perimeter” design, where AI agents do not directly hold credentials. In traditional Managed Agents deployments, when using external tools, their access tokens or API keys were placed within the agent’s execution context. This configuration carried a significant risk of secret information leaking from the agent’s address space during prompt injection attacks that manipulate AI with malicious input.

On the other hand, in the new architecture via MCP tunnels, credentials are held by MCP servers located within the customer’s network boundaries and are invisible to the agent. When an agent makes a tool call, the request is transferred through a tunnel to the customer’s proxy, where it is converted locally into a token of appropriate scope and executed. This allows the physical explosion radius of damage to be cut off because there is no secret information to be stolen if an agent is hijacked. For information on the secure flow of communication, please refer to the diagram below.

Figure 2

Compliance with NIST standards and compliance

This extension also aligns closely with the “AI Agent Standardization Initiative” announced by the U.S. National Institute of Standards and Technology (NIST) in February 2026. Under the NIST framework, strict identity authentication and audit trails are required to manage risks associated with autonomous decision-making and tool calls by agents. By combining MCP tunnels with self-hosted sandboxes, companies can apply AI agent activity logs, network policies, and data loss prevention tools (DLP) directly on their existing infrastructure.

Additionally, four sandbox providers—Cloudflare, Vercel, Modal, and Daytona—have initially supported the platform, each offering advanced network controls such as zero trust security and VPC peering. This physical separation of the “Anthropic” and the “on-site (customer environment)” is an extremely advantageous structure for meeting NIST’s proposed federated interoperability and security baseline requirements.

The Future of Social Implementation and Market Impact

The Significance of Market Competition and Vertical Infrastructure Integration

Looking at market trends, Anthropic is currently showing overwhelming momentum in the enterprise market. By 2026, the company’s annual sales have surpassed $44 billion (about 7 trillion yen), capturing a significant share in key B2B market sectors such as code generation and agents. According to research data, Anthropic’s share of the enterprise agent market has reached 40%, far surpassing its competitor OpenAI’s 27%.

Surprisingly, 65% of companies that introduced AI services in March 2026 chose Anthropic, clearly showing support from corporate customers who prioritize reliability and safety. Behind this is the shift to a pay-as-you-go system that visualizes AI usage costs. As companies increasingly question the return on investment (ROI) of their AI investments, infrastructure such as Managed Agents—which can securely and efficiently connect internal assets to AI—is becoming an essential OS for digital transformation, going beyond mere tool provision.

Future Developments and Highlights of the Japanese Market

A key point of interest going forward is expected to accelerate social implementation, especially within Japan’s regulated industry. In fields such as finance, healthcare, and government, requirements such as the Personal Information Protection Act and industry-specific guidelines to prevent data from being handed over to foreign vendors have been major barriers to adoption. By leveraging a self-hosted sandbox, you can operate in a hybrid manner by keeping real data locked within your domestic environment while leveraging Anthropic’s powerful intelligence models.

This will also be a tailwind for domestic SIers such as NTT Data and Fujitsu, and proposals for solutions that integrate existing internal systems with AI agents will become more active. On the other hand, compliance with international frameworks like NIST standards is likely to become a business participation qualification rather than a voluntary choice for Japanese companies in global supply chains. The advent of an era where agents autonomously manipulate internal resources is fundamentally rewriting the corporate security paradigm.

コメント

Copied title and URL