Model Hardware Standard (MHS) โ€” the "physical MCP" question

Anthropic's Model Hardware Standard (research preview, Aug 27 2026, with HHMI Janelia) exposes
lab/manufacturing instruments to AI agents through standardized drivers. The open question it
raised: does this become the "MCP of hardware" โ€” a shared driver-tag contract that standardizes like
MCP's tool contract โ€” or do driver formats fragment per vendor? Answer (verified first-hand at the
Anthropic page + The Register, 08-28): **shape yes, contract no โ€” and the safety semantics land on
the driver author, with a regulatory owner (EU Machinery Regulation) waiting.**

The driver model

Verified first-hand: the contract does NOT standardize

The Anthropic page specifies the functional shape but has **no driver versioning, no schema
formalization, no backward-compatibility language, and no contractual guarantee for tags**. MCP's tool
contract (name/title/description/inputSchema/outputSchema/annotations) has a parallel here only in
name: MHS tags are free-form prose. The Register's framing is the sharpest: the "durable safety
boundary" is "the layer written in prose by a busy postdoc" โ€” a wrong operating range in a tag is the
most plausible first-incident path.

Safety semantics: who owns them

Quantified results (vendor + preview, not independent)

Partner/backer ecosystem

AWS (Strands Robots, private pre-release), Automata, Danaher, Doosan Robotics, MBF Bioscience
(ScanImage driver), QIAGEN (QIAsymphony Connect PoC), Tecan (Fluent), Universal Robots, Hugging Face
(LeRobot), Raspberry Pi (Camera driver). No standards body has adopted it.

Caveats (read past the headline)

ICS/OT extension: unclaimed

Manufacturing control (robotic arms, liquid handlers, factory machinery) is explicitly in-scope, but
the preview has **no OT threat model, no authentication/segmentation language, no fail-safe/stop
semantics beyond driver limits** โ€” the security OT-attack-surface concern (cf. Xiiaozet LK100W)
is not addressed. Whether the preview's "safety evaluations with launch partners" cover control-system
attack models is the watch item.

The verdict