Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
arrow_back View All Dates
Thursday, September 17
 

07:30 CEST

Registration & Badge Pick-Up
Thursday September 17, 2026 07:30 - 19:00 CEST

Thursday September 17, 2026 07:30 - 19:00 CEST
Onyx Lounge (Ground Level)

09:00 CEST

Keynote: Welcome - Angie Jones, Vice President of Developer Experience, The Agentic AI Foundation
Thursday September 17, 2026 09:00 - 09:05 CEST

Speakers
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
Thursday September 17, 2026 09:00 - 09:05 CEST
Auditorium (Ground Level)

09:05 CEST

Keynote: Mazin Gilbert, Executive Director, The Agentic AI Foundation
Thursday September 17, 2026 09:05 - 09:15 CEST

Speakers
avatar for Mazin Gilbert

Mazin Gilbert

Executive Director, AAIF, The Linux Foundation
Mazin Gilbert is the Executive Director of the Agentic AI Foundation, part of the Linux Foundation. An IEEE Fellow with a Ph.D. in Artificial Intelligence and a Wharton MBA, Mazin brings 25+ years of experience driving AI innovation from research to global-scale deployment. His career... Read More →
Thursday September 17, 2026 09:05 - 09:15 CEST
Auditorium (Ground Level)

09:20 CEST

Keynote: Clare Liguori, Senior Principal Engineer, AWS Agentic AI
Thursday September 17, 2026 09:20 - 09:30 CEST

Speakers
avatar for Clare Liguori

Clare Liguori

Senior Principal Engineer, AWS Agentic AI
Clare Liguori is a Senior Principal Software Engineer at AWS, focusing on developer tooling and agentic AI. She primarily works on Kiro and Strands Agents SDK. She is also a core maintainer of the Model Context Protocol (MCP) specification. Over 12+ years at Amazon, she has worked... Read More →
Thursday September 17, 2026 09:20 - 09:30 CEST
Auditorium (Ground Level)

09:30 CEST

Keynote: Getting to Stateless MCP: In Production - Shaun Smith, Open Source Agents / MCP, Hugging Face
Thursday September 17, 2026 09:30 - 09:40 CEST
The latest MCP Specification introduces one of the largest changes to the protocol since launch: a stateless transport.

At Hugging Face we use MCP as infrastructure for Agents, Interactive and Inference workloads. 

In this session we will:
- Summarize the MCP Transport story to date 
- Use production analytics from Hugging Face's MCP infrastructure to track migration metrics and success
- Explore new opportunities for Client, Server and Gateway implementations offered by the new transport features.
- Share lessons learned from implementing the stateless transport for Clients and Servers
Speakers
avatar for Shaun Smith

Shaun Smith

Open Source Agents / MCP, Hugging Face
Shaun leads Open Source/MCP at Hugging Face, and is an MCP Steering Committee member serving as a Community Moderator and Transports Working Group. He is also the author of `fast-agent` - one of the few clients with comprehensive protocol support and diagnostic capabilities.
Thursday September 17, 2026 09:30 - 09:40 CEST
Auditorium (Ground Level)

09:45 CEST

Coffee Break
Thursday September 17, 2026 09:45 - 10:05 CEST

Thursday September 17, 2026 09:45 - 10:05 CEST
Solutions Showcse - Diamond Lounge

09:45 CEST

Solutions Showcase
Thursday September 17, 2026 09:45 - 19:30 CEST

Thursday September 17, 2026 09:45 - 19:30 CEST
Diamond Lounge (Ground Level)

10:10 CEST

The Modern AI Stack: Agents, MCP and Skills - Adewale Abati, Block
Thursday September 17, 2026 10:10 - 10:35 CEST
Agent harnesses. MCP. Skills. MCP Apps. If you've been watching the AI space and feeling like everyone else already understands something you don't, this talk is for you.

I've spent the last several months building with each layer of the modern AI stack, and what I kept finding was that the concepts aren't as hard as the terminology makes them sound. Nobody had just sat down and explained what each piece actually is, what problem it solves, and how they fit together. So that's this talk. Technical enough to be useful, grounded in real workflow experience, and paced so that by the end you have a clear mental model of where AI tooling actually stands today and where you fit in it.
Speakers
avatar for Adewale Abati

Adewale Abati

Staff Developer Advocate, Block
Adewale "Ace" Abati is a Web Engineer and Staff Developer Advocate currently helping to shape the future at Block. Ace is passionate about the Web, Open Source and community building, an avid gamer and shares his experience through public speaking and content across social media... Read More →
Thursday September 17, 2026 10:10 - 10:35 CEST
G102 + G103 (Level 1)

10:10 CEST

From Personal Agent To Org Catalog: 13 Specialists, One Orchestrator - Nick Veenhof, GitLab
Thursday September 17, 2026 10:10 - 10:35 CEST
Every team at our company was building agents from scratch. Duplicated prompts. Duplicated tool configs. No shared memory. I watched five teams present their setups at a meetup in Ghent. Same patterns, reinvented five times.

So I built Paul, an AI chief of staff with 13 specialist agents: analyst, writer, broadcaster, operator, architect, reviewer, and more. Each agent has a defined job family, a cultural perspective, and a skill library. One orchestrator delegates. A reviewer gates quality. The whole system runs on open source tooling with MCP servers for memory, calendar, email, GitLab, and smart home.

The sharing layer is a platform AI catalog. Agent definitions, flows, and MCP server configs become organizational assets. A team publishes an agent. Another team reuses it. Skills are composable. Memory is scoped: user, project, or org.

This talk covers the architecture, the real failures, and the pattern for moving from a personal experiment to an organizational capability. You leave with concrete agent definitions, delegation patterns, and a mental model for building a catalog your whole organization can use.
Speakers
avatar for Nick Veenhof

Nick Veenhof

Director, DevRel Engineering, GitLab
Nick Veenhof is Director of Contributor Success at GitLab, where he leads initiatives to enhance open source participation. With 15+ years in open source ecosystems, Nick brings expertise in building contribution frameworks that deliver business value in regulated environments.

... Read More →
Thursday September 17, 2026 10:10 - 10:35 CEST
Auditorium (Ground Level)

10:10 CEST

What Does It Take To Ship a New MCP Spec - Den Delimarsky, Anthropic
Thursday September 17, 2026 10:10 - 10:35 CEST
An end-to-end deep dive into how a new spec goes from idea to a production, stable release. In this session, you will learn more about the MCP governance process, Spec Enhancement Proposals (SEPs) and how all of this work translates into a brand-new MCP spec that then is adopted by the agentic space at large!
Speakers
avatar for Den Delimarsky

Den Delimarsky

Member of Technical Staff, Anthropic
Den is an avid reverse engineer, passionate about APIs, protocols, and security. He leads MCP technical programs at Anthropic and prior to that built authentication and authorization libraries used by millions of developers around the globe. You can learn more about his work on h... Read More →
Thursday September 17, 2026 10:10 - 10:35 CEST
Emerald Room (Level 1)

10:10 CEST

Workshop to be Announced
Thursday September 17, 2026 10:10 - 10:45 CEST

Thursday September 17, 2026 10:10 - 10:45 CEST
G106 + G107 (Level 1)

10:45 CEST

Legal Implications Under EU Law When Deploying AI Agents - Mirela Takacs, Law Office Takacs Mirela
Thursday September 17, 2026 10:45 - 11:10 CEST
This presentation highlights general rules that any engineer should keep in mind before implementing an AI agent, around one core idea: legislation should be treated as part of the system architecture. At EU level, the AI Act is the central regulation, but adjacent European legislation may also be activated based on the AI agent’s actions.
Translating legal obligations into technical requirements from the design stage makes deployment safer and more compliant. Five practical takeaways help in doing that:
1. compliance should not be seen as a one-time check, but as a continuous monitoring and evaluation process
2. it demands interdisciplinary work from the design phase, not a back-and-forth decision chain
3. the agent is a system, not a legal person, so the ones held accountable are the humans behind it
4. a clear map of what the agent does, accesses, and produces is what lets you navigate the law
5. there is no universal rule applicable: start with the AI Act, then identify the adjacent legislation activated by the agent’s specific functions
The goal is to design agents that are safe, compliant and genuinely useful, by treating law as an architectural concern, not bureaucracy.
Speakers
avatar for Mirela Takacs

Mirela Takacs

Lawyer, Law Office Takacs Mirela
I began my professional journey as an OSS Compliance Specialist, reviewing open-source components integrated into software products. Later, qualifying as a lawyer in Romania, I developed my legal analytical skills and gained experience in negotiating commercial agreements and handling... Read More →
Thursday September 17, 2026 10:45 - 11:10 CEST
G102 + G103 (Level 1)

10:45 CEST

Sponsored Session: Beyond the Easy 80%: Bringing Legacy, Spatial, and Locked-Down Data to MCP - Don Murray, Safe Software
Thursday September 17, 2026 10:45 - 11:10 CEST
AI models are becoming a commodity. GPT-4, Claude, Gemini.  Pick one, swap it next quarter, and the differentiation has already moved on. What hasn't moved is context: the data an agent can actually reach. Most of today's MCP ecosystem wraps the easy 80 percent.  SaaS APIs, ticketing systems, chat platforms, anything that already had a REST endpoint. The other 20 percent: legacy databases running since the 1980s, CAD/BIM/GIS formats, real-time sensor and SCADA feeds, regulated records that legally can't leave the building, and hybrid environments split across cloud and on-prem by design,  still have no real path to an agent. In most enterprises, that's exactly where the decision-relevant data lives. 
Drawing on 32 years building spatial and enterprise data integration, this talk looks at what it actually takes to expose hard, hybrid, and on-prem data as MCP tools: treating data workflows as callable tools instead of one-off scripts, separating the control plane (what an agent is allowed to call) from execution (where the data actually lives and stays), and building both directions, consuming MCP tools and exposing your own, without hardwiring to one model or vendor. 
Speakers
avatar for Don Murray

Don Murray

CEO, Co-Founder, Safe Software

Thursday September 17, 2026 10:45 - 11:10 CEST
G104 + G105 (Level 1)

10:45 CEST

Stateless: The Future of MCP Transports - Kurtis Van Gent, Google
Thursday September 17, 2026 10:45 - 11:10 CEST
MCP is becoming stateless in one of the largest changes to the protocol since its launch.

This change simplifies the deployment of robust servers, making MCP ready for the next wave of scaled usage driven by agents and use cases like MCP Apps.

This session led by members of the Transports Working Group:
- Explores the upcoming changes - and sharing real data from Google and Hugging Face on the motivation behind them.
- Details the latest approaches on handling serverless Elicitation, Sampling and Sessions.
- Introduces the application and infrastructure patterns that can take advantage of the stateless protocol.

We'll also update on the latest roadmap status and expected migration timelines and approach
Speakers
avatar for Kurtis Van Gent

Kurtis Van Gent

Senior Staff Software Engineer, Google
Kurtis Van Gent is a MCP Core Maintainer and leads the MCP Transports Working Group. By day, he leads AI Ecosystems + Integrations for Google Cloud Databases and helped create MCP Toolbox for Databases.
Thursday September 17, 2026 10:45 - 11:10 CEST
Emerald Room (Level 1)

10:45 CEST

An Orchestra of Agents: What I Learned Running a Multi-Agent System for 5,000+ Developers - Muhammad Ahsan Ayaz, Scania
Thursday September 17, 2026 10:45 - 11:10 CEST
Most "AI agents" are a single LLM wrapped in a system prompt. They look great in demos and collapse the moment real users show up. I know because I built one for my 5,000+ member developer community, and the first version broke in ways I didn't see coming.
In this talk, I'll walk through the multi-agent system I run in production: a tree of 12 specialist agents built on Google's ADK, coordinating through sequential pipelines, parallel fan-out, and LLM-driven dynamic routing, each armed with MCP tools to act on the real world. We'll cover the orchestration primitives, then climb into the real architecture: how onboarding chains three agents in sequence, how external knowledge fans out across GitHub, Dev.to, and StackOverflow in parallel, and how the root agent delegates per message.
Then the fun part: the bugs. The drain-loop that cancelled a ParallelAgent mid-flight. The recency drift that surfaced 2020 articles in 2026. The callback layer I had to build for PII sanitization, caching, and observability ; none of which made it into the tutorial.
You'll leave with a mental model for each pattern, production patterns that kept it running, and war stories that'll save you a week.
Speakers
avatar for Muhammad Ahsan Ayaz

Muhammad Ahsan Ayaz

Software Architect, Scania
Muhammad Ahsan is a Google Developers Expert (GDE) in AI & Angular, an author of 4 world-wide published books, an Educator, and a Software Architect.
https://bio.link/codewithahsan
Thursday September 17, 2026 10:45 - 11:10 CEST
Auditorium (Ground Level)

11:20 CEST

When NOT To Use an Agent: Choosing Between Workflows, Services, and Agent Systems - Jigyasa Grover, Uber & Rishabh Misra, Atlassian
Thursday September 17, 2026 11:20 - 11:45 CEST
LLM-powered “agents” are quickly becoming the default architectural pattern for AI-enabled systems.

Need automation? Agent.
Need integration? Agent.
Need reasoning? Agent.

But agents are not an upgrade; they are a trade-off. They introduce non-determinism, larger attack surfaces, evaluation complexity, and operational unpredictability.

In this session, we’ll examine three common architectural patterns for LLM-enabled systems:
- Deterministic workflows (state machines, orchestrated pipelines)
- Service-oriented architectures with LLM augmentation
- Fully agentic orchestration with dynamic tool use

Rather than comparing features, we’ll analyze these patterns across real engineering constraints:
- Failure isolation and blast radius
- Latency and cost predictability
- Observability and debugging complexity
- Security boundaries and permission scoping
- Evaluation and regression testing strategy
- Operational burden over time

This talk offers a practical decision framework grounded in system design principles. You’ll leave with a mental model and checklist to evaluate whether an agent is justified, or whether a simpler architecture will deliver more predictable, resilient outcomes.
Speakers
avatar for Jigyasa Grover

Jigyasa Grover

ML Tech Lead @ Uber • Google Developer Advisory Board Member • LinkedIn [in]structor • Book Author • Startup Advisor • 12 time AI + Open Source Award Winner • Featured @ Forbes, UN, Google I/O, and more!, Uber
Jigyasa Grover is a 12-time award-winning AI leader and author of Sculpting Data for ML. She drives personalization at Uber, with prior ML leadership at Twitter/X and Meta. A Google I/O speaker and Google Developer Advisory Board member, she works at the intersection of large-scale... Read More →
avatar for Rishabh Misra

Rishabh Misra

Principal ML Engineer, Atlassian
I am a Principal ML Engineer & Researcher with over 10 years of experience in the AI and ML space. I am currently driving LLM pretraining, postraining, and personalization efforts at Atlassian, and have previously led Deep Learning & GenAI-powered user personalization at late-stage... Read More →
Thursday September 17, 2026 11:20 - 11:45 CEST
Auditorium (Ground Level)

11:20 CEST

CHAP, an Open Protocol for Auditable Human-Agent Collaboration - Dr Arsalan Shahid, Brightbeam AI
Thursday September 17, 2026 11:20 - 11:45 CEST


The next phase of agents is not one human supervising one model. It is multi-human, multi-agent work across teams, tools, and trust boundaries. The decisive moments are not model outputs; they are human approvals, edits, overrides, escalations, and handoffs, and the rationale behind them. Today those moments leak into chat logs, tickets, and application code, where they cannot be replayed or audited.

CHAP, the Collaborative Human-Agent Protocol, gives this shared workspace a protocol layer. A small Core (workspaces, participants, tasks, artefacts, and an append-only evidence log) carries composable profiles for review, structured override, operating modes, handoff, deliberation, identity, and signed audit. It composes with MCP and A2A rather than replacing them: MCP connects agents to tools, A2A connects agents to agents, CHAP lets humans and agents do accountable work together.

The talk covers the protocol gap, the Core primitives, a worked 'override as evidence' flow, and lessons from building the open reference implementations and conformance harness. Spec, code, and examples are public.

Paper: https://arxiv.org/abs/2606.09751
Repo: https://github.com/BrightbeamAI/chap
Speakers
avatar for Dr Arsalan Shahid

Dr Arsalan Shahid

Principal Solutions Director, Brightbeam AI
Arsalan Shahid is Principal Solutions Director at Brightbeam AI and co-author of CHAP. He leads AI R&D for clients in regulated manufacturing, biopharma, and financial services. Previously a Principal Investigator at CeADAR, Ireland's centre for applied AI, he worked with startups... Read More →
Thursday September 17, 2026 11:20 - 11:45 CEST
G102 + G103 (Level 1)

11:20 CEST

Call Now, Fetch Later: Durable MCP Tasks on an Event Log - Jeremy Frenay, Lenses
Thursday September 17, 2026 11:20 - 11:45 CEST
MCP's new Tasks primitive makes tool calls asynchronous: a request returns a durable handle now, and the result arrives later. That's the right model for work that runs for minutes or hours, like ETL jobs, deep research, or batch reasoning, but the spec leaves the hard parts to implementers.
Where does in-flight work live? How does a task survive a restart? How do you deliver a result exactly once and let multiple clients subscribe to it?

This talk argues that an append-only event log is a natural backend, because a Task is a state machine and a state machine's history is just an ordered log of its transitions. We walk a concrete, vendor-neutral implementation: creation, status, and completion become events, recovery becomes replay, and the server can go stateless, lining up with MCP's roadmap. We dig into the failure modes that bite in production: orphaned tasks, duplicate side effects, and at-least-once versus exactly-once delivery, plus the gaps the 2026 roadmap is still closing around retry and expiry.

You'll leave with a reference architecture you can build on any log or queue, and an honest view of what Tasks gives you today and what it doesn't yet.
Speakers
avatar for Jeremy Frenay

Jeremy Frenay

Field CTO, Lenses
Jeremy Frenay is Field CTO & AI Engineer at Lenses.io (part of Celonis). He has been building agentic workflows since 2022, including co-founding Arcane, an Accel-backed AI copilot for marketers. At Lenses he works on AI-agent enablement, security, and governance for Apache Kafka... Read More →
Thursday September 17, 2026 11:20 - 11:45 CEST
Emerald Room (Level 1)

11:55 CEST

The Other 90%: Agentic AI for the Legacy Codebases Nobody Wants To Touch - Ayush Bhardwaj, Siemens
Thursday September 17, 2026 11:55 - 12:20 CEST
The AI coding conversation has been almost entirely about greenfield: new features, fresh repos, throwaway scripts. Meanwhile the codebases that quietly run hospitals, factories, and banks are maintained by skeleton crews drowning in tribal knowledge, dead build systems, and 20-year-old decisions. Single-LLM code assistants do not survive contact with them.
Agentic systems can, but only with very different workflow patterns than the ones usually demoed. This session is a field report from modernizing a long-lived industrial codebase: what worked, what catastrophically did not, and the patterns that emerged.
We cover the shift from "LLM completes my code" to "agents reason about my codebase": the two-loop research and execute split, vertical slicing, measurement-first execution, structured unknowns, and rollback discipline. We name the failure modes that wreck naive setups on legacy code, including context overflow, hallucinated APIs, false-positive fixes, and agentic drift, and the practices that prevent them.
It closes with where agents still lose, what OSS tooling is missing, and how the community can treat legacy maintenance as a first-class agentic AI problem.
Speakers
avatar for Ayush Bhardwaj

Ayush Bhardwaj

Senior Software Engineer - Agentic AI, Siemens
Senior Software Engineer specializing in Agentic AI, leading development of enterprise-grade multi-agent systems at Siemens. Holds 3 AI patents, published NLP research, and collaborated with Meta's research team on AudioSeal. Pursuing research around information-theoretic frameworks... Read More →
Thursday September 17, 2026 11:55 - 12:20 CEST
Auditorium (Ground Level)

11:55 CEST

MCP Conformance Testing V1.0, Testing the 2026-07-28 Spec in SDK's and Online - Paul Carleton, Anthropic
Thursday September 17, 2026 11:55 - 12:20 CEST
MCP Conformance testing is a set of tools for ensuring SDK's implement the spec in a way that's compatible with each other.

The most recent spec revision 2026-07-28 is the first release that requires conformance testing as a part of the Specification Enhancement Proposal (SEP) process. This talk will go over lessons learned from the rollout of that specification, and also introduce hosted conformance testing that clients and servers can use to test their deployed implementations.
Speakers
avatar for Paul Carleton

Paul Carleton

Member of Technical Staff, Anthropic
Paul Carleton is a Core Maintainer of the Model Context Protocol and Auth Nerd at Anthropic, where he leads auth implementations across Anthropic's clients and the TypeScript and Python SDKs. He drives MCP conformance testing efforts to ensure consistent behavior across the ecosy... Read More →
Thursday September 17, 2026 11:55 - 12:20 CEST
Emerald Room (Level 1)

11:55 CEST

From Opaque To Observable: Tracing Multi-Agent OpenClaw Workflows With OpenTelemetry - Pavan Sudheendra, Cisco Systems
Thursday September 17, 2026 11:55 - 12:20 CEST
Agent systems are getting more capable, but they are still hard to operate when a single user request fans out across multiple agents, tools, model calls, queues, and outbound messages. In this session, we will walk through how we built an open observability plugin for OpenClaw (InsightClaw) that turns that opaque execution path into a connected telemetry story using OpenTelemetry.

The talk covers a practical design that combines three signal paths: typed lifecycle hooks for request, agent, tool, and response flow; diagnostics events for model usage, cost, queue, webhook, and stuck-session signals; and optional provider SDK auto-instrumentation for GenAI calls. Together, these produce connected traces, useful operational metrics, and cross-session lineage for handoffs, spawned subagents, and parallel branches.

We will show the trace model we used, the session semantics we had to define for real workflows, and the engineering tradeoffs around payload capture, runtime patching, and correlating control-plane events with agent execution.
Speakers
avatar for Pavan Sudheendra

Pavan Sudheendra

Engineering Technical Leader, Cisco Systems
Pavan Sudheendra is a Technical Lead at Outshift by Cisco, where he leads technical efforts on distributed systems and emerging multi-agent architectures. His work is focused on the intersection of agentic AI and system design at scale. He is an active contributor to the LF ecosystem... Read More →
Thursday September 17, 2026 11:55 - 12:20 CEST
G102 + G103 (Level 1)

11:55 CEST

Workshop to be Announced
Thursday September 17, 2026 11:55 - 13:30 CEST

Speakers
avatar for Arun Gupta

Arun Gupta

Director, Open Source Ecosystem & Developer Platform, NVIDIA

Thursday September 17, 2026 11:55 - 13:30 CEST
G106 + G107 (Level 1)

12:30 CEST

We Built AI Agents To Fix Security Findings in Production — Here's What Developers Actually Merged - Amine Boudraa, Ruchita Kshirsagar, Nihit Gupta & Gianfranco Romani, Thomson Reuters
Thursday September 17, 2026 12:30 - 12:55 CEST
AI is accelerating vulnerability discovery, finding more security issues than any team can fix by hand. The obvious next step is letting AI fix them too, but pushing automated changes into production is difficult, and the trust bar is super high.

Over the past year, we built and shipped two autonomous remediation agents raising PRs against hundreds of production repositories: one for SAST findings in first-party code, and one for SCA findings in third-party libraries. While developers can already fix vulnerabilities by going back and forth with a general-purpose AI assistant, our goal is to make that loop faster and more trustworthy.

That trust came from unglamorous engineering: teaching our agents how to build and test an application, trace data flows to reject risky fixes, and resolve breaking changes when modernizing legacy code. Along the way, we’ll share common patterns we’ve seen across rejected PRs, and what we had to iterate on to get hundreds of them merged.

We are open sourcing both agents for the community. The volume of CVEs keeps growing, automated remediation will become a must, and existing solutions don't yet solve this problem at the level we need.
Speakers
avatar for Amine Boudraa

Amine Boudraa

Senior Product Security Engineer, Thomson Reuters
Amine Boudraa is a Senior Product Security Engineer at Thomson Reuters specializing in application security. He builds AI agents, MCP servers, and automation that help engineering teams stay fast while ensuring the time they spend addressing security issues is meaningful and impa... Read More →
avatar for Ruchita Kshirsagar

Ruchita Kshirsagar

Senior Product Security Engineer, Thomson Reuters
Ruchita Kshirsagar is a cybersecurity professional with 9+ years of experience in application security and software development. A Senior Product Security Engineer at Thomson Reuters, she specializes in SAST/DAST/SCA, DevSecOps, threat modeling, container security, vulnerability management... Read More →
avatar for Nihit Gupta

Nihit Gupta

Senior Product Security Engineer, Thomson Reuters
Nihit is a passionate and enthusiastic Product Security Engineer with over 4 years of experience in software development and security. Skilled in SAST and SCA remediation, architecting Secure-SDLC environments, and cloud security. He enjoys working on projects that can enhance software... Read More →
avatar for Gianfranco Romani

Gianfranco Romani

Senior ML Engineer, Thomson Reuters
Gianfranco Romani is an Senior ML Engineer on Thomson Reuters' Cybersecurity team, leading strategy and delivery of AI security tools. He focuses on automated vulnerabilities discovery/remediation and securing enterprise LLM apps. Previously at Thomson Reuters Labs, he built AI products... Read More →
Thursday September 17, 2026 12:30 - 12:55 CEST
Auditorium (Ground Level)

12:30 CEST

A2A Goes Stable: What Changed, Why, and What's Next - Sam Betts, Cisco Systems & Kuba Herczyński, Google
Thursday September 17, 2026 12:30 - 12:55 CEST
A2A Protocol v1.0 is the first stable, production-ready release of the open standard for agent-to-agent communication — marking the transition from a protocol you could experiment with to a foundation organisations can commit to with confidence.

This talk is delivered by two maintainers who helped shape the release. We cover what changed from v0.3 and why: the deliberate choice to prioritise maturity over reinvention, new enterprise capabilities — signed Agent Cards, multi-tenancy, modern OAuth flows, and a web-aligned architecture — and the breaking changes that were unavoidable on the path to a durable standard.

We also cover the SDK story: how official SDKs support v1.0 while maintaining backward compatibility with v0.3, and a per-interface versioning strategy that makes progressive migration practical rather than a forced cutover.

Finally, we look at extensibility: how extensions add capabilities while keeping a stable core, and how custom protocol bindings let implementations replace the default transport while preserving A2A semantics.

If you are building on A2A today or evaluating it, this talk gives you a clear picture of what changed, why, and how to migrate.
Speakers
avatar for Sam Betts

Sam Betts

Engineering Technical Leader, Cisco Systems
Sam Betts is an Engineering Technical Lead at Outshift by Cisco with over 14 years of experience building cloud-native platforms, security solutions, and AI-driven systems. He has led development on OpenClarity, Cisco Panoptica, and OpenStack Ironic, and actively contributes to AGNTCY... Read More →
avatar for Kuba Herczyński

Kuba Herczyński

Staff Software Engineer, Google
Kuba is a Software Engineer turned Technical Lead at Google with over 15 years of experience building things. Lately most interested in AI Agents, actively involved in A2A for almost a year - both in the protocol spec as well as it's adoption at Google.
Thursday September 17, 2026 12:30 - 12:55 CEST
G102 + G103 (Level 1)

12:30 CEST

MCP Doesn't Have a Context Problem - Sam Morrow, GitHub
Thursday September 17, 2026 12:30 - 12:55 CEST
People frequently assume MCP requires tools to be dumped straight into the system prompt, and responses to be returned straight to the model. Critics say the protocol has a context problem, that CLIs and agent skills are more efficient and composable. They're right about the symptoms, but wrong about the diagnosis. The problem isn't MCP - it's for a long time few had applied serious context engineering to it.

Through a self-built agent harness (mcpi), I will demonstrate three complementary strategies for progressive tool discovery over MCP - each paying only the context tokens it needs.

This talk focuses on the most transformative of the three: skills over MCP that describe the tool surface, and progressively enable tools upon skill invocation. I will also look at MCP CLIs and Code Mode approaches, and show how they can complement each other with their different strengths.

Attendees will leave with practical patterns they can implement in their own MCP servers and agent harnesses today.
Speakers
avatar for Sam Morrow

Sam Morrow

Senior Software Engineer, GitHub
Sam is a Senior Software Engineer at GitHub, where he leads development of the GitHub MCP server. He works on AI developer tools and helps shape agentic workflows at GitHub. In a past life he was also a professional drummer.
Thursday September 17, 2026 12:30 - 12:55 CEST
Emerald Room (Level 1)

13:05 CEST

What *IS* an Agent's Identity? - Christian Posta, Solo.io
Thursday September 17, 2026 13:05 - 13:30 CEST
Enterprises understand human identity fairly well. You could argue they are decent at service accounts. But what about an AI agent? Is it either of these?

Agents are driven by intent, discover/invoke tools, make decisions, and interact with other resources (APIs, databases, other agents, etc). Enterprises will care about "Who is this agent?", "What is it allowed to do?", "What has it done?" and of course "Can we revoke its authority?"

In this talk we'll break down what actually makes up an agent's identity. We'll look at authentication, delegated authority, provenance, trust establishment, and accountability. We'll also examine where technologies like OAuth, OpenID Connect, SPIFFE, and emerging efforts such as AAuth fit into the picture.

You'll leave with a practical framework for thinking about agent identity, which problems have already been solved, and which ones we're still figuring out.
Speakers
avatar for Christian Posta

Christian Posta

Global Field CTO, Solo.io
Christian Posta (@christianposta) is VP, Global Field CTO at Solo.io. He is the author of "Istio in Action", "AI Gateways in the Enterprise" and many other books on cloud-native architecture. He is well known in the cloud-native community for being an architect, speaker, blogger (https://blog.christianposta.com... Read More →
Thursday September 17, 2026 13:05 - 13:30 CEST
Auditorium (Ground Level)

13:05 CEST

Cleared for Landing: Designing MCP Servers for Long-Horizon Agents - Casey Chow, OpenAI
Thursday September 17, 2026 13:05 - 13:30 CEST
As agents evolve from quick tool calls to work that unfolds over hours or even days, MCP servers need to do more than expose tools. They need to teach agents what work they are suited for, how to sequence it, how to monitor progress, when to involve a human, and recognize when results have actually landed.

This talk presents a practical quality bar for MCP servers that support long-horizon agentic work. We'll discuss patterns for describing capabilities, guiding workflows, coordinating changes across services and validating outcomes, drawing on lessons from building effective MCP apps and plugins inside of ChatGPT and Codex. These patterns let us separate enduring design principles from changing protocol details, and discuss how today’s servers can adapt as tasks, triggers, resources, skills, and related MCP capabilities evolve.
Speakers
avatar for Casey Chow

Casey Chow

Member of Technical Staff, OpenAI
Casey Chow is a Member of Technical Staff at OpenAI, working on the ecosystem and developer platform team.
Thursday September 17, 2026 13:05 - 13:30 CEST
Emerald Room (Level 1)

13:05 CEST

Composable, Low-code Agent Systems With the Tools You Already Have - Adam Jones, Anthropic
Thursday September 17, 2026 13:05 - 13:30 CEST
You don't write a pile of glue code to onboard a new hire — you give them an account and point them at a few channels. So why do we hardcode workflows and wire up orchestration SDKs to put AI agents to work?

There's a lighter path: let agents coordinate the way people already do — by tagging each other and posting into channels — so the system is something you own and shape rather than something you engineer. This talk makes the case for that low-code, team-owned approach, the patterns that make it work, and the surprising amount of custom infrastructure it lets you delete.
Speakers
avatar for Adam Jones

Adam Jones

Member of Technical Staff, Anthropic
Adam Jones is a member of technical staff at Anthropic working on RL research, a maintainer of many open-source MCP servers and tools, and a maintainer of the Model Context Protocol (MCP) registry.
Thursday September 17, 2026 13:05 - 13:30 CEST
G102 + G103 (Level 1)

13:30 CEST

14:45 CEST

Welcome Back - Angie Jones, Vice President of Developer Experience, The Agentic AI Foundation
Thursday September 17, 2026 14:45 - 14:50 CEST

Speakers
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
Thursday September 17, 2026 14:45 - 14:50 CEST
Auditorium (Ground Level)

14:52 CEST

Keynote: David Soria Parra, Member of Technical Staff, Anthropic
Thursday September 17, 2026 14:52 - 15:02 CEST

Speakers
avatar for David Soria Parra

David Soria Parra

Member of Technical Staff, Anthropic
I am the co-creator of the Model Context Protocol (Modelcontextprotocol.io) and a Member of Technical Staff at Anthropic working on a wide variety of things. Formerly a senior manager at Facebook working on static analysis and simulation based testing. I was responsible of integrating... Read More →
Thursday September 17, 2026 14:52 - 15:02 CEST
Auditorium (Ground Level)

15:02 CEST

Keynotes to Announced
Thursday September 17, 2026 15:02 - 15:25 CEST

Thursday September 17, 2026 15:02 - 15:25 CEST

15:25 CEST

Keynote: Arun Gupta, Director, Open Source Ecosystem & Developer Platform, NVIDIA
Thursday September 17, 2026 15:25 - 15:35 CEST

Speakers
avatar for Arun Gupta

Arun Gupta

Director, Open Source Ecosystem & Developer Platform, NVIDIA

Thursday September 17, 2026 15:25 - 15:35 CEST
Auditorium (Ground Level)

15:45 CEST

Your Agent Has a Wallet. Who Has the Receipts? - Bharath Nallapeta, Mirantis Inc.
Thursday September 17, 2026 15:45 - 16:10 CEST
In one year, agents went from unable to pay for anything to spoiled for choice. x402 (Coinbase, now Linux Foundation) for machine-to-machine. AP2 (Google, donated to the FIDO Alliance) for signed payment mandates. ACP (OpenAI and Stripe) for checkout. MPP (Stripe and Tempo, launched March 2026) for streamed micropayments against a pre-authorized session. Four protocols, four layers, real volume.

What none of them owns is the part that decides whether an agent is allowed to spend this, now, on this. MCP returns HTTP 402 inside a tool call, but it has no concept of a budget, an attribution, or an audit trail. The vendor bolt-ons are already multiplying and fragmenting.

And the question stopped being academic. US regulators now treat agent purchases as ordinary card transactions, Europe is moving to put liability on whoever deployed the agent unless they can produce the mandate and audit trail. The receipts are now a legal requirement with no standard home.

This talk maps the four-protocol stack, shows the MCP payment handshake live, and argues for the one layer the agent economy is still missing.
Speakers
avatar for Bharath N R

Bharath N R

OSPO Lead, Mirantis Inc.
Bharath Nallapeta leads the Open Source Program Office at Mirantis. He works across AI and Agentic systems, Kubernetes, and NVIDIA GPU infrastructure, and contributes to open source projects including Cluster API (CAPI)
and Cluster API Provider OpenStack (CAPO). Before Mirantis he built platforms at Red Hat and Stakater. He speaks regularly at conferences and meetups, and is focused on making AI and Agentic workloads practical, portable, and safe to run in production... Read More →
Thursday September 17, 2026 15:45 - 16:10 CEST
G104 + G105 (Level 1)

15:45 CEST

Six Months of Proof: Independently-Verifiable Records for Agent Actions Under the EU AI Act - Steven Mih, Action State Group, Inc.
Thursday September 17, 2026 15:45 - 16:10 CEST
The EU AI Act makes "what did the agent actually do?" a legal obligation: high-risk AI must support automatic record-keeping over its lifetime (Article 12) — for traceability, human oversight, and post-market monitoring — with logs retained at least six months (Article 19). But the Act can only require the logs to exist, not to be trustworthy: a log is only as good as the party that keeps it, and the operator who ran the action is not a disinterested witness — even an immutable one can be incomplete, cherry-picked, or built after the fact. The fix is simple and old: anchoring. Commit each record to a hash, write that hash to an independent, append-only transparency log, and any party can verify what the agent did — without trusting the operator. This session shows how the Agent Action Capsule project uses open transparency-log standards (SCITT/COSE) to produce anchored, independently-verifiable records of agent actions to the letter of the Act, plus the trust it can't legislate.

Live demo of the Agent Action Capsule project: emit a record at an action boundary, anchor it, verify it with an open verifier, then tamper and watch verification fail. You'll leave with an open, framework-agnostic pattern mapped to Article 12/19 — and a running verifier to try.
Speakers
avatar for Steven Mih

Steven Mih

Founder/CEO ·, Action State Group, Inc.
Steven Mih is Founder/CEO of Action State Group, building the verifiable-record layer for AI agent actions, filed as an IETF Internet-Draft, with an open verifier. Previously he co-founded and led Ahana (acquired by IBM, 2023) and served on Presto Foundation (Linux Foundation) board... Read More →
Thursday September 17, 2026 15:45 - 16:10 CEST
Auditorium (Ground Level)

15:45 CEST

MCP in Production: Reliability Contracts for Multi-Agent Tool Use - Krishna Chaitanya, Meta Platforms
Thursday September 17, 2026 15:45 - 16:10 CEST
MCP creates a common way for models to use tools, but production use still breaks down when reliability expectations are left implicit. This talk argues that MCP systems need explicit reliability contracts covering permission boundaries, tool-call semantics, retries, observability, and recovery behavior. It will show how multi-step failures emerge in real tool-use chains and how traces, evals, and protocol-aware safeguards can make those failures debuggable instead of mysterious. The session also covers design patterns for graceful degradation when tools, transport layers, or model reasoning do not behave as expected. Attendees will leave with a concrete framework for making MCP-based systems more trustworthy in real deployments.
Speakers
avatar for Krishna Chaitanya

Krishna Chaitanya

Senior Software Engineer, Meta Platforms
I am a Senior Software Engineer at Meta working on OpsMate, an AI-driven incident response system for large-scale production infrastructure. My work focuses on AI infrastructure, observability, distributed systems reliability, and operational automation. Before Meta, I worked at Microsoft... Read More →
Thursday September 17, 2026 15:45 - 16:10 CEST
Emerald Room (Level 1)

15:45 CEST

Sandboxing My AI Agent, One Layer at a Time - Juan Antonio Osorio, Stacklok Inc.
Thursday September 17, 2026 15:45 - 16:10 CEST
We hand coding agents our workspace, our keys, and a shell, then walk away while they run code generated at runtime from untrusted input: files in the repo, docs fetched off the web, output from MCP servers nobody audited. The obvious fix is isolation: give every agent its own kernel. So we start there, running Claude Code, Codex, and others inside sub-second, hardware-isolated microVMs (libkrun/KVM), where even root in the guest is stuck behind the hypervisor's MMU boundary, not just a shared-kernel namespace.

But isolation on its own isn't enough. An isolated agent can still read the .env beside your code, exfiltrate it, wreck your workspace, or abuse a tool you never vetted. So we add defenses, live, one layer at a time: copy-on-write workspace snapshots with a per-file review gate, non-overridable secret exclusions, a DNS-aware egress firewall, a hardened Wolfi guest (custom Go PID 1, dropped capabilities, seccomp, no-new-privs), and an MCP proxy with Cedar authorization profiles. We finish on the attack surface most tools forget: the security tool's own config.

It's all Apache-2.0. The lesson carries to any agent you run: isolation is the floor, not the ceiling.
Speakers
avatar for Juan A. Osorio

Juan A. Osorio

Principal Engineer, Stacklok Inc.
Juan Antonio "Ozz" Osorio is a Mexican software engineer living in Finland. His background spans security for OpenStack, Kubernetes, and bare metal environments. Currently at Stacklok, he founded the ToolHive project and has been building MCP infrastructure, including supply chain... Read More →
Thursday September 17, 2026 15:45 - 16:10 CEST
G102 + G103 (Level 1)

16:20 CEST

90 Days To Agentic Engineering - Thomas Schöne, Project Lions Development GmbH
Thursday September 17, 2026 16:20 - 16:45 CEST
Most software companies are experimenting with AI, yet many struggle to move beyond isolated chat interactions and proof-of-concepts.

This session presents a practical case study of how a traditional software development organization with little prior AI experience adopted agentic engineering practices within 90 days. Guided by an engineer with hands-on experience in AI agents, MCP, RAG systems, and AI-native development workflows, the organization moved from sporadic experimentation to productive use of agentic systems in everyday engineering work.

Attendees will learn how high-value use cases were identified, how MCP-based tools, agent skills, and RAG-powered knowledge systems were introduced, and how trust in agent-driven workflows was established across development teams.

Not every experiment succeeded. Some assumptions proved wrong, some tools disappointed, and several approaches had to be reworked. This session shares the lessons learned, the mistakes made, and the strategies that ultimately accelerated adoption.

The result was a measurable shift from AI curiosity to AI-enabled engineering, establishing the foundations for long-term AI-native development.
Speakers
avatar for Thomas Schöne

Thomas Schöne

Lead AI Architect, Project Lions Development GmbH
Thomas Schöne is a software engineer with more than 15 years of experience in web development, software architecture, and digital transformation. He specializes in AI agents, MCP, RAG systems, and AI-native engineering workflows. Thomas regularly speaks at developer conferences and... Read More →
Thursday September 17, 2026 16:20 - 16:45 CEST
Auditorium (Ground Level)

16:20 CEST

Agentic AI for Enterprise Mainframes: From Dead Code Elimination To Business Knowledge - Thamarai Selvi Ravi Kumar, Legal and General
Thursday September 17, 2026 16:20 - 16:45 CEST
Enterprise mainframe systems often contain large amounts of unused and unreachable code, increasing complexity and risk. Safely removing this logic is difficult due to deeply interconnected execution paths.

In this session, I present a real-world case study where we delivered large-scale dead code remediation into production with zero incidents using an MCP-powered agentic AI approach.

We developed specialised AI agents, backed by Python tooling, to analyse code, detect unused logic, and support safe, auditable remediation with human validation. This reduced analysis time from days to under an hour per program.

The same approach was extended to business knowledge enablement using a reverse engineering agent, generating structured context integrated into Copilot Spaces, enabling finance teams to query system behaviour using natural language.

Learn how agentic AI can safely modernise legacy systems and bridge developer and business understanding.
Speakers
avatar for Thamarai Selvi Ravi Kumar

Thamarai Selvi Ravi Kumar

Senior Mainframe Developer, Legal and General
Senior Mainframe Developer specialising in enterprise platform modernisation. Focused on applying agentic AI and MCP to automate legacy system analysis and improve code quality. Recently built AI agents for safe code remediation and integrated Copilot to enable business users to interact... Read More →
Thursday September 17, 2026 16:20 - 16:45 CEST
G104 + G105 (Level 1)

16:20 CEST

What Networking Got Right That Agentic AI Risks Getting Wrong: The Case for an Agent Control Plane - Parisa Foroughi, Nokia
Thursday September 17, 2026 16:20 - 16:45 CEST
Every major agent orchestration framework today conflates task execution with the control layer that should govern authority and policy. This talk argues for a cross-domain agent control plane: a runtime layer external to the agent that performs authority checks and policy enforcement at defined boundaries, independent of the agent’s internal logic. Grounded in inter-domain routing, it proposes a semantic model built on five invariants: domain boundary as the control unit, boundary-crossing capability classes as the permission unit, scope-narrowing delegation with bounded elevation, unbroken provenance to a registered trust anchor, and boundary enforcement without inspecting internal behavior or payload content. The model introduces two runtime artifacts: the Agent Control Envelope (ACE) for authorization and the Agent Activity Envelope (AAE) for behavioral constraint. Attendees will leave with a precise mental model, two concrete artifacts, and a clear argument for why agent interoperability needs explicit boundary semantics before wire formats harden around the wrong primitives.
Speakers
avatar for Parisa Foroughi

Parisa Foroughi

Senior research specialist, Nokia
Parisa Foroughi is a Senior Research Specialist at Nokia working at the intersection of agentic AI systems, large-scale distributed networks, and standardization. Her work bridges gaps between emerging AI capabilities and production systems, combining hands-on insights with system-level... Read More →
Thursday September 17, 2026 16:20 - 16:45 CEST
G102 + G103 (Level 1)

16:20 CEST

MCP, Skills, and the Persistence of AI Agent Compromise - Steven Duckaert, Onyx
Thursday September 17, 2026 16:20 - 16:45 CEST
Prompt injection ends when the session ends. Memory poisoning doesn't.
As enterprise agents mature, three attack surfaces are converging: MCP server trust, agent skill libraries, and long-term memory retrieval. Each is dangerous in isolation. Together, they create a threat model most teams aren't yet reasoning about.

MCP enables agents to acquire tools dynamically, including from servers never explicitly authorised. Agent skills package reusable behaviours that can be poisoned at the source. Memory systems built on vector retrieval treat past experience as trusted context, with limited provenance validation.

The MINJA research (NeurIPS 2025) demonstrated injection success rates approaching 98% across GPT-4o, Gemini, and Llama-based agents. Crucially, better reasoning models don't solve this - they may amplify it. A more capable model becomes more faithful to a poisoned memory once retrieved.

OWASP's 2026 Agentic Top 10 dedicates a standalone category: ASI06 Memory and Context Poisoning.

This session maps the attack chain, shares real enterprise exposure patterns, and offers a framework for memory provenance tracking, skill validation, and MCP server trust evaluation.
Speakers
avatar for Steven Duckaert

Steven Duckaert

EMEA Pre-Sales, Onyx
Steven Duckaert leads EMEA Pre-Sales at Onyx Security, working with enterprises across the region on the security and governance challenges of deploying AI agents at scale.
With a background in AI product strategy and go-to-market, Steven focuses on agentic AI adoption and enterprise risk helping security teams understand what they're running before it becomes a problem... Read More →
Thursday September 17, 2026 16:20 - 16:45 CEST
Emerald Room (Level 1)

16:55 CEST

We Built an Agent, We Shipped a Compiler. Here's Why. - Joel Verezhak, Grafana Labs
Thursday September 17, 2026 16:55 - 17:20 CEST
We promised our CX team an agent that would write customer success plans. Six months and four architectures later, we shipped a compiler that calls LLMs in four places.

Each architecture was the right fix for the previous one's failure. The single skill could not enforce quality. The subagents drifted across stages. The scripted prompts hit determinism walls. Only when we accepted that "agentic" was the wrong frame did the output become reviewable, replay-able, and trustworthy enough to ship to real customers.

The talk is a tour of the architectural moments where we learned what LLM-driven systems can and cannot own. Specific failures: a real customer plan shipped with the wrong rows, a quality firewall the LLM kept violating until we made it structural, and "temperature=0" arriving as a footnote rather than a solution.

You leave with three things. A maturity curve from skill to engine. A working distinction between pipeline work and agent work. And a vocabulary for the conversation with stakeholders who keep asking when the agent will be ready, when what they actually want is a compiler with an agentic UI.
Speakers
avatar for Joel Verezhak

Joel Verezhak

Observability Architect, Grafana Labs
As an observability architect, my job is to make sure that telemetry data keeps flowing, whatever happens!
Thursday September 17, 2026 16:55 - 17:20 CEST
G104 + G105 (Level 1)

16:55 CEST

Skills Need SemVer Too - Pedro Rodrigues, Supabase
Thursday September 17, 2026 16:55 - 17:20 CEST
The agent ecosystem is converging on a common way to discover skills, making it easier for agents to find and load domain-specific knowledge. But discovery only solves the first problem.

Once skills become part of production workflows, they need to evolve. Instructions change, best practices improve, and capabilities grow. Without a way to version and manage those changes, agents risk relying on outdated or incompatible knowledge.

In this talk, I’ll explore lessons learned from publishing and distributing skills at scale, discuss the emerging standards around skill discovery, and propose a framework for skill versioning, compatibility, and evolution. If skills are becoming the package ecosystem for agents, it’s time to start thinking about dependency management too
Speakers
avatar for Pedro Rodrigues

Pedro Rodrigues

AI Tooling Engineer, Supabase
I’m an AI Tooling Engineer at Supabase, part of the team maintaining all AI initiatives including our MCP server, AI assistant, and Skills. I’ve been involved with the MCP protocol since its early days, contributing to its SDKs and projects like Skybridge. I’ve spoken at MCP... Read More →
Thursday September 17, 2026 16:55 - 17:20 CEST
G102 + G103 (Level 1)

16:55 CEST

MCP Borrowed LSP's Design. It Skipped LSP's Lesson - Gorkem Ercan, Jozu
Thursday September 17, 2026 16:55 - 17:20 CEST
MCP borrowed its design from the Language Server Protocol. It skipped LSP’s hardest lesson, the one about packaging and trust, and a decade later that lesson is still unlearned.

LSP never standardized how servers were packaged or verified. Each editor invented its own channel, the VS Code extension format won by default, and signing was bolted on much later, marketplace by marketplace. It still has not closed the gap.

MCP repeats this with a larger blast radius. An MCP server runs arbitrary code that reaches into credentials, data, and local systems. Today’s packaging work falls short: the official registry delegates trust to npm and PyPI, the MCPB format repeats the VS Code extension model, and the provenance that exists is locked inside vendor silos.

What is missing is open, registry-neutral provenance verified before an agent loads a server. That standard does not need inventing. Packaging MCP servers as OCI artifacts inherits the signing, attestation, and policy tooling the container ecosystem already proved. This talk traces that history firsthand, then shows how to reuse it rather than rebuild it registry by registry.
Speakers
avatar for Gorkem Ercan

Gorkem Ercan

CTO, Jozu
Gorkem Ercan is the CTO and co-founder of Jozu, building open-source infrastructure to bring security and reproducibility to the AI/ML lifecycle. A longtime contributor to cloud-native developer tools, he previously led developer experience at Red Hat. Gorkem bridges platform engineering... Read More →
Thursday September 17, 2026 16:55 - 17:20 CEST
Emerald Room (Level 1)

16:55 CEST

Distributed Mess: A Production Guide To Multi-Agent Failures - Oleksandra Bovkun, Databricks
Thursday September 17, 2026 16:55 - 17:20 CEST
Most agent failures don't happen in a model. They happen in the handoff. When a supervisor agent passes a flawed context downstream (wrong tool output, misrouted state, a hallucination that looked plausible), the receiving agent has no way to know. It continues confidently on a corrupted foundation. In MCP-based systems, this is structural: tool call responses become shared context across agents that never directly communicate. A bad result upstream poisons every agent that touches it downstream. Traditional end-to-end testing misses this because the final output can still look reasonable.

This session is a technical walkthrough of what that failure mode looks like in production and what you need to catch it: tracing context across agent boundaries (not just individual inference calls), distinguishing model errors from routing errors from context corruption, and evaluating the coordination layer — not just outputs.

This session is not about the future of AI, but about the unglamorous work of building agentic systems you can actually trust.
Speakers
avatar for Oleksandra Bovkun

Oleksandra Bovkun

Sr. Developer Advocate, Databricks
Oleksandra is a Developer Advocate at Databricks with a background as a Data Engineer, AI Engineer, and Solutions Architect. She's spent her career building real-world AI solutions and architecting data platforms — which means she's made most of the mistakes so you don't have to... Read More →
Thursday September 17, 2026 16:55 - 17:20 CEST
Auditorium (Ground Level)

17:30 CEST

The Unix Philosophy for AI Agents: Filesystems as the Context Primitive - Cannis Chan & Daniel Temesgen, Bloomberg
Thursday September 17, 2026 17:30 - 17:55 CEST
Every agent framework reinvents context management differently: scratchpads, artifacts, or memory stores. This creates distinct storage problems (system config, user memory, thread scratch, task state, shared workspaces, external data, and inter-agent messaging) collapsed under "agent context", with no shared vocabulary and a lack of interoperability.

In an attempt to close this gap for the industry at large, we present a production architecture that models agent context as scoped virtual filesystems. Agents interact through standard filesystem tool calls (read, write, and list), while the agentic AI platform enforces scope, lifecycle, and access control per mount.

The talk covers three layers. First, scoped state: how four filesystem scopes (system, user, thread, and task) compose across collaborating agents, using file modes and mount isolation to prevent cross-scope leakage. Second, external data as mountpoints: turning retrieval into navigable directory trees with ls/cd/cat semantics instead of opaque vector search. Third, protocol implications: how this maps to the MCP spec today and the case for filesystem operations as a first-class agent interoperability primitive.
Speakers
avatar for Cannis Chan

Cannis Chan

Technical Product Manager, Bloomberg
Cannis Chan is a Technical Product Manager in the Office of the CTO at Bloomberg, building infrastructure platforms for AI products. With 10 years in B2B and Enterprise (AutogenAI, Deutsche Bank, Ondat/Akamai), she specializes in navigating complex products through pre- and post-product... Read More →
avatar for Daniel Temesgen

Daniel Temesgen

Senior Software Engineer, Bloomberg
Daniel Temesgen is a senior software engineer in the AI Foundational Platforms Engineering team at Bloomberg in London. His work involves the development of Kubernetes controllers targeting access enforcement, agentic sandboxes, and change management. He previously worked at Expedia... Read More →
Thursday September 17, 2026 17:30 - 17:55 CEST
G104 + G105 (Level 1)

17:30 CEST

Verify, Abstain, or Amplify: A Field Guide To Confidently-Wrong Agents - Michal Orzechowski, Sano – Centre for Computational Personalised Medicine
Thursday September 17, 2026 17:30 - 17:55 CEST
Your coding agent earns trust because it has an oracle: a compiler and tests catch its mistakes. Most agents don't. They pass their evals and still ship confident, wrong answers, because for many tasks, there's nothing to check against.

Two failures hide under "confidently wrong": the model doesn't know (retrieve it), or it knows wrong, a priori it reasserts even against a correct context, which RAG won't fix.

A field guide, three honest moves. Verify, when you can check: deterministic checks on the answer, not the tool calls, run in the harness. Abstain, when you can't: make the agent say "I can't verify this," gated on an external check, not its own confidence. Amplify, when there's no right answer, only judgment: the model collapses toward the average exactly when you want the opposite, so you push it off and amplify the novelty you put in, judged by a human.

We ground all three in our own builds where the model is reliably wrong: a finance agent, a genomics agent that invents false-but-plausible mechanisms, and a microtonal-music agent that keeps dragging toward Western tonality. The move comes down to two questions: can you check the answer, and is there a right one?
Speakers
avatar for Michal Orzechowski

Michal Orzechowski

Agentic AI & Cloud Architect, Sano – Centre for Computational Personalised Medicine
Agentic AI & Cloud Architect at Sano, affiliated with AGH University of Krakow and ACK Cyfronet. After a decade in Kubernetes and cloud-native distributed systems, and a PhD in the field, he now builds multi-agent pipelines across genomics, healthcare, and microtonal music. He maintains... Read More →
Thursday September 17, 2026 17:30 - 17:55 CEST
Auditorium (Ground Level)

17:30 CEST

What a Year of Breaking MCP Tells Builders: Protocol Gaps and What Ships Next - Amine Raji, Molntek AB
Thursday September 17, 2026 17:30 - 17:55 CEST
The session opens with the pre-deployment checklist, seven controls, no preamble, then walks through the evidence for why each one exists. This audience deploys MCP in production and needs to leave knowing what to do.

The empirical baseline: 30+ CVEs in 60 days. 24,008 secrets in public MCP configs. 85% attack success rate against major hosts (MCPSecBench, ICLR 2026). Reported as lower bounds with stated provenance.

Three attack classes, demonstrated with lab code. Tool description poisoning: exfiltrates an SSH key simultaneously. Cross-server shadowing: a trusted WhatsApp server weaponised by a malicious daily-facts server, end-to-end encryption intact. The rug pull: postmark-mcp, reconstructed.

The protocol gap analysis is the content specific to this audience. I show the SDK code implementing the flat namespace, the spec text that acknowledges the trust boundary but enforces nothing, then four protocol changes with concrete JSON-RPC schema diffs: today's schema, the addition, the attack class it closes. The finding that changes model selection: more capable models follow poisoned instructions more reliably.

No vendor tools. Source: github.com/aminrj-labs/mcp-attack-labs.
Speakers
avatar for Amine Raji

Amine Raji

Security Lead, Molntek
Amine Raji, PhD, CISSP. 15+ years securing critical systems in banking, defense, aerospace, and automotive. Has spent the past year breaking Model Context Protocol deployments and writing down what breaks. Maintainer of mcp-attack-labs, an open set of labs reproducing agentic attack... Read More →
Thursday September 17, 2026 17:30 - 17:55 CEST
Emerald Room (Level 1)

17:30 CEST

MAS-Lab: An Open Framework for Spec-Driven, Interoperable Multi-Agent Systems - Jordan Augé, Cisco Systems
Thursday September 17, 2026 17:30 - 17:55 CEST
Building multi-agent systems for production remains challenging, not only due to integration complexity, but because validating that systems behave as intended is still largely unsystematic. Teams hand-wire LLMs, tools, and memory, add observability late, and lack clear ways to ensure agent interactions remain reliable and aligned as systems evolve.

This session introduces MAS-Lab, an open, spec-driven framework that makes agent systems composable and verifiable. It extends the integration discipline of protocols like MCP and A2A to all components -- models, tools, memory, messaging, governance, and observability -- through declarative specifications. The result is systematic integration, built-in observability, and reusable best practices.

During the session, we demonstrate a multi-agent trip planner and show how a single spec enables teams to compose agents, apply governance controls such as budgets and guardrails without modifying logic, and validate behavior by exploring alternative designs through reproducible experiments.

Attendees will leave with practical patterns to ensure agent systems behave predictably, remain aligned with intent, and can be trusted in production.
Speakers
avatar for Jordan Augé

Jordan Augé

Tech Lead, Outshift@Cisco - Chair of Accuracy and Reliabiity WG, Cisco Systems
Tech lead at Cisco Outshift, where he builds open-source infrastructure for multi-agent AI. Creator of MAS-Lab, an open framework for spec-driven, interoperable agent systems that decouples runtime, control, and infrastructure. Chair of the AAIF Accuracy & Reliability Working Group... Read More →
Thursday September 17, 2026 17:30 - 17:55 CEST
G102 + G103 (Level 1)

18:00 CEST

Attendee Reception
Thursday September 17, 2026 18:00 - 19:30 CEST

Thursday September 17, 2026 18:00 - 19:30 CEST
Solutions Showcase
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -