On Tuesday 27 May 2025 I went to the first AI Native Netherlands meetup in Amsterdam, organised by re:cinq, the cloud native consultancy whose CEO, Pini Reznik, runs the group. The evening was hosted at Vandebronās office. The first slide read āBuilding AI-Native Platforms: Foundations for the Next Generation of Intelligent Applicationsā with Pini Reznik, CEO of re:cinq, as the name on it. In the opening remarks, the speaker said that several AI-native communities were starting up and that this one hoped to be one of them. That first evening was the start of the AI Native Netherlands series, which later grew past a thousand members.
This is a throwback post. I took photos and recorded parts of two talks. The second speakerās name was not on any slide I photographed, so I do not name them.
Waves of Innovation: AI is not a cost-cutting tool
The next deck, with re:cinq branding, was titled āWaves of Innovation: AI Native, Cloud Native, Real Transformation, Done Rightā. The part I recorded was a story the presenter told about a call centre. A manager with about a hundred people had been told by the board to ādo AIā so that thirty of them could be let go, and was about to buy a chatbot product the presenter called snake oil.
The presenterās argument was that it will not go that way:
- People who struggle to get help from a call centre, such as older customers, often want a human, not a chatbot.
- What is more likely is that the call centre staff get AI assistance, with agents collecting data and performing operations in the background.
- That means the staff have to learn to work with AI, in a prompt-engineering style.
- So the likely result is better and different work, new value and new opportunities, but not lower cost, and it requires relearning.
I like this framing because it matches what I see in platform work: the saving rarely shows up on the line you expected, and the training budget does.

The āWaves of Innovation: AI Native, Cloud Nativeā slide.
The Good, the Bad and the Ugly of MCP
The longest recording was a Wild West themed talk on the Model Context Protocol. The speakerās core message, which they linked to Piniās, was that we are at the trailhead of AI and MCP is a sign of progress, not the end state. They polled the room: only a minority had implemented an MCP server, but many had been asked to.
What MCP is, in the speakerās words. A client-server protocol that connects tools through a standard API, keeps persistent sessions, runs commands and shares context across workflows. The MCP documentation is the place to read the details.
The Bad: security. The slides listed four known risks, which the speaker introduced as āthe perils of the open rangeā:
- Command injection leading to remote code execution. A tool that passes parameters to a shell lets an attacker append a payload such as a semicolon and a command. The slide quoted research by the security vendor Equixly. According to the speaker, 43% of the servers and tools they checked had such vulnerabilities, and of the vendors they told, 30% acknowledged and fixed the problem, 45% said the risk was theoretical or acceptable, and 25% did not respond. The vendorās own write-up is MCP Servers: The New Security Nightmare.
- Tool poisoning. A tool that āadds two numbersā carries hidden instructions in its description, telling the model to read a sensitive file and pass it along while staying polite to the user. The speaker pointed to recent prompt-injection reports in GitLab Duo and in the GitHub MCP integration, the latter published by Invariant Labs in the same week as the talk, where a malicious issue in a public repository could steer an agent into reading private repositories. Invariant also publishes an open-source scanner, MCP-Scan, which the speaker showed as a sign that security tooling is catching up.
- The rug pull, meaning a supply-chain problem: a tool you approved changes behaviour later.
- Cross-server tool shadowing, where one serverās tool descriptions influence how the agent uses anotherās.
On authorisation, the slide quoted the protocol text that authorisation is optional for MCP implementations, and a show of hands suggested almost nobody had implemented it.
Tech debt and protocol wars. The speaker used the story of railway track gauges in nineteenth-century America to talk about tech debt: dozens of incompatible gauges, a standard gauge, and the 1886 āgreat gauge changeā, which the speaker said moved tens of thousands of rails in two days after about 23 years of accumulated debt. Their point was that we may be heading for the same thing. MCP competes with Googleās Agent2Agent protocol, whose partner slide was long, and with IBMās ACP, so there were three protocols in the same space. The speaker thought MCP was ahead because of activity but said nobody knows, and compared it to the container orchestration race of ten years earlier, where they had expected Docker Swarm to win and community and marketing decided otherwise.
MCP registries. The slide listed Smithery, mcp.so, cursor.directory, the awesome-mcp-servers list and the official modelcontextprotocol registry repository. The speaker was overwhelmed by the number of servers, thought we would be better off with ten really good tools than thousands, and was waiting for first-party servers so that you no longer have to send your API key through a proxy. The Postgres reference server got a comment: it is a hole in your database you can query anything through. The āsequential thinkingā server, which lets the model prompt itself through numbered thought steps, was the one they found most interesting.
The Ugly: the human element. The last part left MCP for privacy, with data as āunclaimed rangelandā for rustlers and barons:
- GDPR fines against large platforms, with figures of about 2.4 billion for Meta and about 750 million for Amazon, as quoted by the speaker (no currency was stated; I have not checked the figures).
- A news slide about Meta and a large volume of pirated books used for AI training, which I have not verified, followed by the quote that stealing from one author is plagiarism and from many is research.
- A web scraping market slide and a slide on the EU AI Act under the headline that the EU is trying to regulate AI but first has to define it.
- āHustle cultureā: the headline that time saved by AI is offset by new work created, and a social media post from a founder saying that after he shared how he built his SaaS with Cursor, it came under attack, with API usage maxed out and people bypassing the subscription.
My take: the MCP risk list is mostly old attacks in a new place. Injection, unvetted dependencies and over-broad credentials are what cloud native teams already know, and the same controls apply: allowlist servers, give each server the narrowest identity you can, and read tool descriptions as untrusted input.