Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
arrow_back View All Dates
Friday, September 18
 

08:00 CEST

Registration & Badge Pick-Up
Friday September 18, 2026 08:00 - 17:20 CEST

Friday September 18, 2026 08:00 - 17:20 CEST
Onyx Lounge (Ground Floor)

08:00 CEST

Cloak Room
Friday September 18, 2026 08:00 - 18:00 CEST

Friday September 18, 2026 08:00 - 18:00 CEST
Cloak Room (-1 Floor)

09:00 CEST

Keynote: Welcome - Manik Surtani, CTO, Agentic AI Foundation
Friday September 18, 2026 09:00 - 09:10 CEST

Speakers
avatar for Manik Surtani

Manik Surtani

CTO, Agentic AI Foundation

Friday September 18, 2026 09:00 - 09:10 CEST
Auditorium (Ground Floor)

09:10 CEST

Keynote: Getting to Stateless MCP: In Production - Shaun Smith, MCP and Transport Working Group Maintainer, Hugging Face
Friday September 18, 2026 09:10 - 09:20 CEST
The latest MCP Specification introduces one of the largest changes to the protocol since launch: a stateless transport.

At Hugging Face we use MCP as infrastructure for Agents, Interactive and Inference workloads. 

In this session we will:
- Summarize the MCP Transport story to date 
- Use production analytics from Hugging Face's MCP infrastructure to track migration metrics and success
- Explore new opportunities for Client, Server and Gateway implementations offered by the new transport features.
- Share lessons learned from implementing the stateless transport for Clients and Servers
Speakers
avatar for Shaun Smith

Shaun Smith

Open Source Agents / MCP, Hugging Face

Friday September 18, 2026 09:10 - 09:20 CEST
Auditorium (Ground Floor)

09:25 CEST

Keynote: Agents as Actors: Harnessing the Power of Agentic Infrastructure - Idit Levine, Founder & CEO & Keith Babo, Chief Product Officer, Solo.io
Friday September 18, 2026 09:25 - 09:35 CEST
Harnessed agents have become the dominant interaction and runtime pattern for agentic AI. Claude Code, Codex, and a fast-growing field of open source harnesses integrate models with MCP tools, skills, and plugins. These harnesses provide sandboxed execution, scoped environment access, and human-in-the-loop controls on the desktop. The industry's next shift is already underway: moving harnessed agents from the desktop onto shared infrastructure, where security, observability, and governance are consistent across every agent interaction. In this talk, we will explore how open source infrastructure can deliver secure, scalable harnessed agents beyond the desktop.
Speakers
avatar for Idit Levine

Idit Levine

Founder & CEO, Solo.io
Idit Levine is the founder and CEO of Solo.io, where she is dedicated to simplifying agentic AI and empowering organizations to embrace cloud-native technologies. With a strong background in distributed systems and cloud infrastructure, Idit is passionate about transforming complex... Read More →
avatar for Keith Babo

Keith Babo

Chief Product Officer, Solo.io

Friday September 18, 2026 09:25 - 09:35 CEST
Auditorium (Ground Floor)

09:35 CEST

Keynote: State of the Software Factory - Dexter Horthy, CEO and Co-Founder, HumanLayer
Friday September 18, 2026 09:35 - 09:45 CEST

Speakers
avatar for Dexter Horthy

Dexter Horthy

CEO and Co-Founder, HumanLayer
Dex is CEO and co-founder at HumanLayer, building an agentic IDE and collaboration platform that helps teams solve hard problems in complex codebases without devolving into slop. Dex coined the term context engineering in April 2025, has keynoted two AI Engineer conferences, and his... Read More →
Friday September 18, 2026 09:35 - 09:45 CEST
Auditorium (Ground Floor)

10:00 CEST

Sponsor Activity - Build and Explore Agentic Infrastructure Hands-On
Friday September 18, 2026 10:00 - 10:10 CEST
Get hands-on with agentic infrastructure through interactive labs covering agentgateway, kagent, Agent Substrate, agentregistry, and more. Explore how these open source projects help you build, run, and connect AI agents, then leave with practical experience you can apply to your own agentic workloads.

Sponsor: Solo.io 
Location: Solutions Showcase in Diamond Lounge (Ground Level) 



In order to facilitate networking and business relationships at the event, you may choose to visit a third party's booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies. 
Friday September 18, 2026 10:00 - 10:10 CEST
Diamond Lounge (Ground Floor)

10:00 CEST

Coffee Break
Friday September 18, 2026 10:00 - 10:20 CEST

Friday September 18, 2026 10:00 - 10:20 CEST
Solutions Showcase - Diamond Lounge

10:00 CEST

Solutions Showcase
Friday September 18, 2026 10:00 - 15:30 CEST

Friday September 18, 2026 10:00 - 15:30 CEST
Diamond Lounge (Ground Floor)

10:10 CEST

Sponsor Activity - Aiboostr Live Demo: Governing Every Model and Agent - Product Architecture & Walkthrough
Friday September 18, 2026 10:10 - 10:20 CEST
Walk through Aiboostr with the people who built it: the architecture, how every model and agent call is routed, authorised and logged, and how it runs in practice. Bring your questions. Everyone who sits through a demo leaves with a product discount voucher.

Sponsor: Grao
Location: Solutions Showcase in Diamond Lounge (Ground Level) 



In order to facilitate networking and business relationships at the event, you may choose to visit a third party's booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies. 
Friday September 18, 2026 10:10 - 10:20 CEST
Diamond Lounge (Ground Floor)

10:10 CEST

Sponsor Activity - Get more from Buzz: Five-minute tips for better agent teamwork
Friday September 18, 2026 10:10 - 10:20 CEST
Bring a real problem, or choose one of ours: build a feature, turn feedback into issues, plan a launch, or investigate a bug. The Buzz team will show how people and agents can work through it together in Buzz. Try it live, take home practical tips, and pick up swag.

Sponsor: Buzz
Location: Solutions Showcase in Diamond Lounge (Ground Level) 



In order to facilitate networking and business relationships at the event, you may choose to visit a third party's booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies. 
Friday September 18, 2026 10:10 - 10:20 CEST
Diamond Lounge (Ground Floor)

10:20 CEST

Self-Healing Agents Need Observability - Marcelo Trylesinski, Pydantic
Friday September 18, 2026 10:20 - 10:45 CEST
Self-healing agents sound inevitable: an agent fails, understands what went wrong, proposes a fix, validates it, and improves the system. But without observability, self-healing is just guessing.

This talk explains why reliable agent improvement needs a feedback loop built on traces, evaluations, approvals, and rollback. We will follow an agent run across prompts, model calls, tool selection, MCP servers, validation, policy checks, downstream APIs, and final responses, then show what evidence is needed to reconstruct what happened.

The core idea is simple: agents can only improve safely when they can observe their own behavior. We will discuss what kinds of failures can be detected from telemetry, what changes an agent might propose, where evaluations fit, and which actions should require human or policy approval. The goal is to make “self-healing” concrete, bounded, and useful for production agent systems.
Speakers
avatar for Marcelo Trylesinski

Marcelo Trylesinski

Software Engineer, Pydantic
Founder Engineer @ Pydantic
Python MCP maintainer
Uvicorn/Starlette maintainer
Friday September 18, 2026 10:20 - 10:45 CEST
G104 + G105 (1st Floor)

10:20 CEST

Pull Requests Are Dead, Long Live Peer Review - Dylan Ratcliffe, Overmind
Friday September 18, 2026 10:20 - 10:45 CEST
When AI writes 80–90% of the code on a team, peer review breaks. The pull request is produced by a machine you can't argue with, and the reviewer is auditing a diff instead of talking to a peer. Review has stopped feeling like collaboration, and most of us have started hating it.

We rebuilt how we deploy AI-assisted development in production. Human review moved off the diff and onto the plan: the intent written before any code gets generated. Engineers review the thinking they care about and let the agent fill in the gaps. When the PR lands, CI runs the usual checks plus an automated comparison against the approved plan. Only deviations route back to the original reviewer.

This is a case study in integrating AI into a real SDLC without breaking accountability, quality, or culture. I'll walk through what broke, what we automated, and what stayed human: an in-house MCP server for plan review in the IDE, deviation-checking on every PR, and cultural bets (everyone operates as a team lead; no questions until working code; customer context radiated to the whole team).

We massively improved our velocity and our lead time, and our engineers love the job again.
Speakers
avatar for Dylan Ratcliffe

Dylan Ratcliffe

Founder & CEO, Overmind
Before founding Overmind, Dylan spent 6 years in the trenches helping companies adopt DevOps at Puppet. Hey got frustrated seeing smart people and good products not being used to the best of their ability because of fear of change, so he started Overmind.
Friday September 18, 2026 10:20 - 10:45 CEST
G102 + G103 (1st Floor)

10:20 CEST

Potential Issues for Cross-domain Multi-hop API Calls and Their Solution Proposal - Takashi Norimatsu, Hitachi, Ltd.
Friday September 18, 2026 10:20 - 10:45 CEST
When an MCP server calls an API server requiring an access token in a different domain, elicitation in URL mode is defined by the MCP. Furthermore, token exchange is also used in real-world use cases. We describes the security and operational issues associated with these two methods and proposes solutions.

Elicitation in URL mode may cause user swapping. Moreover, even if an authorization server performing the initial authorization securely perform it by following MCP spec, the well-known attacks may succeed if the other authorization server performing the external authorization does not care about security.

Token exchange may cause information leaks, fraudulent access token use, and availability problems.

In both methods, there are two access tokens: for accessing the MCP server, for accessing the API server. To detect user swapping, it is needed to ensure that both users bound with the first and second token are the same. However, even if the same user registered in both different domains, their user identifiers are usually different. Therefore, simply matching them exactly is not effective.

We describe these issues and propose their solutions.
Speakers
avatar for Takashi Norimatsu

Takashi Norimatsu

Chief OSS Specialist, Hitachi, Ltd.
Takashi Norimatsu, PhD in Engineering, Chief OSS Specialist, Hitachi, Ltd. is a maintainer of Keycloak. He has been implemented and contributed security features like Financial-grade API (FAPI) security profiles, Passkeys, Model Context Protocol (MCP) support. He leads Keycloak's... Read More →
Friday September 18, 2026 10:20 - 10:45 CEST
Emerald Room (1st Floor)

10:20 CEST

Workshop: Keep Infrastructure Out of Your AI Agents: The Agent Gateway Pattern - Lin Sun, Solo.io
Friday September 18, 2026 10:20 - 11:55 CEST
As AI agents move into production, engineering teams face a growing set of challenges. How do you secure and govern MCP servers without modifying them? Route and fail over across multiple LLM providers? Enforce rate limits, access controls, and governance policies? Observe agent traffic, and scale operations across environments?

Rather than embedding these capabilities into every agent, MCP server, and application, organizations can adopt a single architectural pattern: the agent gateway.

An agent gateway acts as a unified control plane for AI systems. It can function as an MCP gateway, LLM gateway, inference gateway, and traditional API gateway, centralizing security, observability, routing, resilience, and policy enforcement across agents, tools, models, and services.

In this hands-on workshop, you'll learn how to secure and federate MCP servers without code changes, route and fail over LLM traffic across providers, enforce authentication and usage policies, and gain end-to-end visibility into agent interactions. Through practical exercises, you'll see how a single gateway layer simplifies operations while enabling secure, scalable, and governable AI systems.
Speakers
avatar for Lin Sun

Lin Sun

Head of Open Source, Solo.io
Lin is the Head of Open Source at Solo.io, co-chair of KubeCon + CloudNatibeCon 2026. She actively contributes to AAIF and CNCF projects. She is the author of “Sidecar-less Istio Explained” and “AI Agents in Kubernetes”, and holds more than 200 patents.
Friday September 18, 2026 10:20 - 11:55 CEST
G106 + G107 (1st Floor)

10:55 CEST

From "Works on My Prompt" To Production SLOs: Building Agent Observability - Manik Khandelwal, Microsoft
Friday September 18, 2026 10:55 - 11:20 CEST
hen we shipped an AI agent powered by Cosmos DB's MCP server internally at Microsoft, it passed every test we threw at it—until real users found creative ways to break it. The agent would silently degrade: returning plausible-but-wrong query results, calling tools in inefficient loops, or burning through token budgets without completing tasks. Traditional monitoring showed green dashboards while users filed complaints. We needed observability designed for agents.

This talk presents the observability and evaluation stack I built to make agent failures visible, measurable, and catchable before users notice—combining OpenTelemetry instrumentation, LLM-as-judge evaluation, and automated regression gates in CI/CD.
Speakers
avatar for Manik Khandelwal

Manik Khandelwal

Senior Software engineer, Microsoft
Manik Khandelwal is an Engineer at Microsoft and a core maintainer of the Azure Cosmos DB Node.js SDK. He builds tools that make modern apps more scalable and intelligent—using AI, real-time data, and JavaScript.
Friday September 18, 2026 10:55 - 11:20 CEST
Auditorium (Ground Floor)

10:55 CEST

From MCP Playground To Org-Wide Infrastructure: Lessons From Building Booking.com's Agent Foundry - Anushka Bhandari, Booking.com
Friday September 18, 2026 10:55 - 11:20 CEST
Most MCP talks stop at the gateway. This one starts there.
The barrier to contributing has never been lower — agents write code, PMs ship tools, designers prototype integrations. But newcomers don't carry the institutional knowledge from a 2am production incident: the performance edge cases, the security gotchas, the failure modes that only show up under real load.
Most MCP projects die between proof of concept and production. The gap isn't technical, it's organizational. Who owns the servers? Who reviews contributions? How does a UX designer, PM, and autonomous agent share the same infrastructure without ten different logins?
Booking.com's Agent Foundry closed that gap. A two-tier MCP gateway with 20+ org-wide servers (Grafana, Honeycomb, Atlassian, Slack, GitLab). One OAuth flow for humans and agents alike. A skills registry with AI-reviewed contributions. Composable profiles that bundle MCPs and skills into workflow-specific harnesses.
Every skill one team contributes compounds value for every team that follows.
We'll share what the architecture got right, what broke, and what a small team can realistically own at this scale.
Speakers
avatar for Anushka Bhandari

Anushka Bhandari

Software Engineer, Booking.com
Anushka Bhandari is a Software Engineer at Booking.com Amsterdam and Founding Engineer of Agent Foundry : the company's org-wide agentic AI platform, built from hackathon to production. Before Booking.com: Databricks, Goldman Sachs, IIIT Delhi. Outside work she skis, cycles, and can't... Read More →
Friday September 18, 2026 10:55 - 11:20 CEST
G102 + G103 (1st Floor)

10:55 CEST

Outcome Engineering: Why Your Agentic Architecture Doesn't Matter (Yet) - Kierra Dotson, Further
Friday September 18, 2026 10:55 - 11:20 CEST
The open agentic ecosystem is technically brilliant and strategically incomplete. Engineers across the enterprise are deploying multi-agent systems, integrating MCP, and building sophisticated context infrastructure — and yet the majority of it never reaches production at scale, fails to earn sustained organizational investment, or generates no measurable competitive value. This stems from looking at model and tool selection as the outcome instead of business value produced.

Outcome Engineering is the discipline of designing agentic systems backward from competitive strategy, instead of forward from technical capability. It is the difference between building impressive infrastructure and building systems that are indispensable. It is the difference between an agent that gets demoed and an agent that gets shipped. And it is the difference between an engineer who just builds things and an engineer who changes what a business is capable of.

This session challenges a widely held belief in the engineering community: that deploying the most advanced agentic architecture is the end goal. It is not. The end goal is winning disproportionately because your AI systems are connected to proprietary data, embedded in proprietary workflows, and architected around prioritized business goals and competitive positions that cannot be replicated by any organization running the same off-the-shelf stack.

This session will expose the critical disconnect between how engineers build agentic systems and how those systems actually survive contact with business reality. We will cover how to map technical architecture directly to strategic outcomes — why proprietary data and institutional knowledge are the most defensible moats in the agentic era, and what it actually takes to build systems the business cannot afford to turn off.

Attendees will leave with a clear framework for reverse-engineering their agent architecture from the outcome back to the infrastructure. Ultimately, the engineers who define this era will be the ones who build systems so embedded in how the business wins that replacing them becomes a risk no one is willing to take.

Speakers
KD

Kierra Dotson

Director of AI Strategy and Governance, Further

Friday September 18, 2026 10:55 - 11:20 CEST
G104 + G105 (1st Floor)

10:55 CEST

ID-JAG: Solving OAuth Sprawl for Enterprise AI Agents - Joey Orlando, Archestra.AI; Aaron Parecki, Okta & Paul Carleton, Anthropic
Friday September 18, 2026 10:55 - 11:20 CEST
Enterprise AI agents are moving from demos into production, and auth is becoming a blocker. Demo agents can connect to tools with OAuth, but real enterprise agents may need SaaS services for thousands of employees. Per-user, per-service consent does not scale.

This session explains ID-JAG, the Identity Assertion JWT Authorization Grant pattern behind MCP's Enterprise-Managed Authorization extension. ID-JAG turns an existing SSO login into centrally governed, auditable access to approved MCP servers, without repeated OAuth prompts.

We'll cover the production problem, protocol flow, and lessons from implementing ID-JAG support in Archestra, one of the first MCP clients to support it. We'll also discuss what identity provider support enables.

Attendees will leave with a model for production agent auth: one SSO login, centralized policy, scoped MCP-native access tokens, fewer consent screens, and a cleaner security review story.

We'll close with the missing piece: SaaS provider adoption. To unlock enterprise deployments, authorization servers need to support this flow so agents can access approved business systems without key-sharing, manual credentials, or one-off integrations.
Speakers
avatar for Paul Carleton

Paul Carleton

Member of Technical Staff, Anthropic
Paul Carleton is a Core Maintainer of the Model Context Protocol and Auth Nerd at Anthropic, where he leads auth implementations across Anthropic's clients and the TypeScript and Python SDKs. He drives MCP conformance testing efforts to ensure consistent behavior across the ecosy... Read More →
avatar for Joey Orlando

Joey Orlando

Co-Founder, Archestra.AI
Co-Founder of Archestra.AI - previous engineer on the Grafana IRM team. Active member of the MCP contributors community, currently involved in the Enterprise and tool annotation working groups. Prior to software, worked as a biochemist for several years :)
avatar for Aaron Parecki

Aaron Parecki

Director of Identity Standards, Okta
Aaron Parecki is Director of Identity Standards at Okta and active in multiple standards development organizations, including IETF, OpenID Foundation, W3C, and MCP. He is an editor of several other OAuth specifications, and has been influential in shaping how MCP has adopted OAuth... Read More →
Friday September 18, 2026 10:55 - 11:20 CEST
Emerald Room (1st Floor)

11:30 CEST

Agents Can Pay. Can They Prove It? - Diego Zuluaga, Open Mobile Hub
Friday September 18, 2026 11:30 - 11:55 CEST
This is the EUDI Wallet architecture, running inside an agent, 18 months before the Dec-2026 mandate.

Every "agent that verifies you" or "agent that pays" demo skips the hard part: how does an AI agent request a real, government- or bank-grade credential from your device, on any phone, any wallet, Android or iOS, and prove who authorized it?

We'll run the full chain live. An MCP server renders a verifier inside Claude and ChatGPT; the W3C Digital Credentials API requests a credential over OpenID4VP; FIDO caBLE carries it cross-device to your phone; the wallet returns an mdoc or SD-JWT credential held in hardware (StrongBox, TEE, Secure Enclave); an AP2 mandate binds your intent.

Identity is the headline, age, membership, passport, healthcare, with payments as one example. And it's not a stage trick: it's an open-source Digital Credential MCP server, soon to be released and donated, that you can clone, point at your own credential, and ship. Built on open standards, across every platform, with UCP & ACP conformance on the roadmap.

Here are some examples of the demos we're planning to showcase: https://github.com/dzuluaga/mcp-apps-shopping-demo
Speakers
avatar for Diego Zuluaga

Diego Zuluaga

Lead, Open Mobile Hub (Linux Foundation), Open Mobile Hub
Leads agentic commerce on Multipaz (OpenWallet Foundation's mdoc credential library, what Google Wallet runs on) and heads Open Mobile Hub under the Linux Foundation. Represents Futurewei in the Agentic AI Foundation (Agentic Commerce, Identity & Trust working groups), alongside Mastercard... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
G104 + G105 (1st Floor)

11:30 CEST

I Was the Bottleneck, Not the Agent - Vincent Ysmal, Datadog
Friday September 18, 2026 11:30 - 11:55 CEST
Running 4 to 8 parallel agent coding sessions sounds like a superpower. It nearly broke me.

I was spending more time switching context to check what each agent had done than I would have spent writing the code myself.

Manual testing, staging deployments, code reviews just to understand what the agent had built: I had become the bottleneck.
The agents were fast. I wasn't.

This talk is about how our team redesigned the workflow around one principle: the agent should be able to prove its own work. That means agents that deploy themselves, run their own test suites, watch CI and fix failures, and produce PRs with enough evidence that a reviewer can approve with confidence, without reading every line.
I'll share what it concretely took to get there, and where humans still need to stay in the loop and why.
Speakers
avatar for Vincent Ysmal

Vincent Ysmal

Senior Software Engineer, Datadog
I'm a Senior Software Engineer at Datadog, working on AI-powered developer tooling. Before that, four years leading R&D at IQVIA France, and two decades building platforms at startups across fintech and insurtech. I've been obsessed with developer workflows since long before AI made... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
G102 + G103 (1st Floor)

11:30 CEST

Governance You Can Run: Checkable Properties for Production Agents - Seshu Tolety & Ayush Bhardwaj, Siemens
Friday September 18, 2026 11:30 - 11:55 CEST
Most agent governance lives in documents nobody can enforce. The agent ships, the policy sits in a wiki, and no one can answer the question that matters in production: is this running system compliant right now?
This talk presents governance built the other way around, as properties you can check on a live agent system rather than promises on a slide. We decompose any agentic system into a small three-object model, define properties that are individually testable against a running deployment, and rank failure modes into the handful of Tier-1 risks that actually cause incidents. Regulatory mappings (EU AI Act, ISO/IEC 42001, GDPR) fall out as a consequence of satisfying those properties, not as the starting point.
You leave with a vendor-neutral framework you can apply to your own agents the same week, independent of stack or model provider.
Speakers
avatar for Ayush Bhardwaj

Ayush Bhardwaj

Associate Software Architect - Agentic AI, Siemens AG
Associate Software Architect specializing in Agentic AI, designing & leading development of enterprise-grade multi-agent systems at Siemens. Holds 3 AI patents, published NLP research, and collaborated with Meta's research team on AudioSeal. Pursuing research around information-theoretic... Read More →
avatar for Seshu Tolety

Seshu Tolety

Director - Agentic AI, Siemens
Visionary technology leader | 20+ years engineering transformation at global scale.

Architect of high-performing teams, cloud platforms, IoT, and Agentic AI strategies. I turn legacy systems into resilient delivery engines and engineering cultures into innovation powerhouses.

N... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
Auditorium (Ground Floor)

11:30 CEST

Economies of Scale for MCP and Agents: Why You Need an Identity Broker - Magnus Jungsbluth & Jan Brennenstuhl, Zalando SE
Friday September 18, 2026 11:30 - 11:55 CEST
Drawing from lessons of how to scale an enterprise to thousands of microservices, we make the case that pushing concerns to the infrastructure for agentic systems should be a no-brainer when planning to scale agentic systems.
This talk explores how Zalando tackled this challenge by building and open-sourcing our own agentic identity broker as part of our broader agentic platform initiative. We will share how it supports delegation chains across third-party and in-house applications, integrates with the CNCF project agentgateway and how it allows us to keep these pesky authentication / authorization concerns on the infrastructure and keep MCP servers and agents simple.
We will dive into the technical mechanics, how it integrates into a larger enterprise and allows us to apply just enough governance to stay ahead of the game. We will cover practical applications and limitations of dynamic client registration.
A closing outlook will illustrate how tool approvals and human-in-the-loop can be enforced centrally without agent authors or MCP authors having to build anything. Practical examples of CIBA and intent-based access will complete the session.
Speakers
avatar for Magnus Jungsbluth

Magnus Jungsbluth

Senior Principal Engineer, Zalando SE
Magnus has been working for over two decades in software engineering with a strong focus on security and cryptography. At Bundesdruckerei he led a platform team for trust center applications. Since joining Zalando he leads initiatives to build more platform capabilities around security... Read More →
avatar for Jan Brennenstuhl

Jan Brennenstuhl

Principal Software Engineer, Zalando SE
Jan Brennenstuhl is a Principal Engineer and product-minded security enthusiast with a proven track record of building identity solutions for millions of users while balancing UX and security in high-stakes revenue funnels. Currently focused on making the agentic SDLC more secure... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
Emerald Room (1st Floor)

12:05 CEST

Governed Agent Autonomy: Building a Control Plane for Agentic Systems - Nnenna Ndukwe, Qodo AI
Friday September 18, 2026 12:05 - 12:30 CEST
We see how quickly AI coding tools and agent harnesses are improving. But how can the surrounding system keep that autonomy governable once an agent starts planning, executing tools, changing files, and consuming budget on a team’s behalf?

In this talk, I break down a technical case study based on a real AI coding control-plane architecture and show how serious systems structure autonomy through explicit boundaries: plan gates, permission controls, trust review, independent verification, and runtime observability. I will walk through the patterns and production-grade examples, explain why telemetry and quota tracing are integral to code governance, and show why integrity failures can still happen even with strong coding workflows.

This session gives engineering leaders and practitioners a framework for evaluating AI coding tools. The goal is to achieve agent governance that teams can trust, audit, and scale.
Speakers
avatar for Nnenna Ndukwe

Nnenna Ndukwe

AI Developer Relations Engineering Lead, Qodo AI
Nnenna Ndukwe is a Developer Relations Engineering Lead and Software Engineer, passionate about AI. With 9+ years in industry, she's a global AI community architect championing engineers to build in emerging tech. She studied Computer Science at Boston University and is a proud member... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
G102 + G103 (1st Floor)

12:05 CEST

When Agents Run Healthcare: Building Reliable Agentic Systems in Highly Regulated Environments - Janosch Woschitz, BARMER
Friday September 18, 2026 12:05 - 12:30 CEST
The public statutory health insurance system in Germany faces a dual challenge: demographic change is creating a shortage of skilled professionals while operational pressure continues to rise due to an aging population. Healthcare organisations must therefore automate high-volume processes without compromising reliability, governance, or trust.

This session presents BARMER’s journey from governed data and analytics platforms to production-oriented agentic systems supporting real operational workflows. Rather than focusing on isolated chatbots or copilots, it explores how agentic systems can be embedded into core enterprise processes in highly regulated environments.

The talk highlights key design patterns including workflow orchestration, agent runtime separation, observability, and human-in-the-loop escalation. It also demonstrates why many early agent architectures fail under regulatory constraints and what changes are required to meet enterprise standards for compliance, auditability, and resilience.
Speakers
avatar for Janosch Woschitz

Janosch Woschitz

Senior AI Architect, BARMER
Janosch Woschitz is a Senior AI Architect at BARMER’s AI innovation unit, BARMER KI, where he builds scalable AI/ML platforms and production-grade agentic systems for healthcare. With a background in software engineering, distributed systems, and enterprise AI architecture, he has... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
Auditorium (Ground Floor)

12:05 CEST

Testing Agents and Their Tools: Offline Evaluation, Synthetic Tasks, and A/B Experiments - Ksenia Bobrova, GitHub
Friday September 18, 2026 12:05 - 12:30 CEST
A three-layer evaluation strategy for AI agents and their tools, from experience operating across multiple LLM providers and runtimes.

Offline evaluation: designing benchmark suites with curated requests, expected tool selections, and arguments. Computing precision, recall, F1 scores, confusion matrices for tool mix-ups, and argument hallucination rates to pinpoint description problems.

End-to-end benchmarks: multi-tool flows where the agent chains several calls to complete a task, catching integration regressions that single-tool evaluation misses.

Production A/B experiments: a case study of tool search experiments across OpenAI and Anthropic through staged rollouts. Challenges we hit: caching bugs under real traffic, tool discovery failures, and data skew making early results inconclusive. How we decided whether to advance, pause, or roll back.

These layers compensate for each other's blind spots, forming a testing pyramid that enabled us to safely ship changes to MCP and agent across model providers. Attendees leave with a reusable playbook for testing MCP servers, agents, and running A/B experiments.
Speakers
avatar for Ksenia Bobrova

Ksenia Bobrova

Senior Software Engineer, GitHub
I'm currently focusing on building AI agents and tooling around it.
Friday September 18, 2026 12:05 - 12:30 CEST
G104 + G105 (1st Floor)

12:05 CEST

MCP Apps and the Nearly Headless Web - Liad Yosef, MCP Apps
Friday September 18, 2026 12:05 - 12:30 CEST
MCP Apps are the last piece in moving toward a new web - one that's "nearly" headless. Autonomous agents, not humans, will interact with most websites through MCP, APIs, and other data channels. Websites and browsers become obsolete, replaced by personal assistants that orchestrate tasks on our behalf. In rare cases, agents will fall back to browser capabilities to navigate sites that aren't yet agent-ready.
But we'll still need the last mile.
Some moments still require human eyes and human input: choosing a seat at a venue, completing a check-in, reviewing a 3D model, verifying intent on important decisions. This is where MCP Apps come in - letting tools, websites, and services send composable, interactive chunks of UI directly to agents, exactly when needed, maintaining brand and identity.
We'll explore the full cycle of this nearly headless web: the infrastructure required to support autonomy and trust, the new UI layer, and how assistants are becoming the new browsers.
MCP Apps redefine the web's interface. Headless, but with a human eye at the end.
Speakers
avatar for Liad	Yosef

Liad Yosef

Co-creator, MCP Apps
Liad Yosef is the co-author and maintainer of MCP Apps on the MCP Steering Committee. He is the co-builder of MCP-UI, and previously AI Lead in Shopify's CEO office. Liad is currently a co-founder and CTO, building the future of agentic interfaces at Ora. Liad is a web enthusiast... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
Emerald Room (1st Floor)

12:05 CEST

Workshop: Harness Engineering: Building the System Around Your AI Coding Agent - Ji Darwish, Lunatech
Friday September 18, 2026 12:05 - 13:40 CEST
AI coding agents feel like magic. It is easy to assume there is something exotic inside, some secret sauce that makes agents reliable. Well, there isn't, the core of every AI coding agent is dead simple: send a message to a model, parse tool calls, execute them, feed the results back, repeat. Everything else (context management, permissions, observability, safety guardrails) is engineering layered on top of it that we should be building.

In this deep dive, we build that engine from scratch (in Java!), live on stage. Not to build the best agent, but to understand how the pieces fit together. We point it at a real codebase, and watch what happens. It compiles. Tests pass. And it violates every convention the team agreed on. So we iterate. We add context, constraints, and feedback, and at each step we examine what changed, why it helped, and what it maps to in the tools you already use.

The goal is a mental model. By the end, you will understand the components inside the AI coding tools you use every day, what you can layer on top to get smoother results and safer expectations, and where the honest limits still are, the gap no amount of engineering has closed yet.
Speakers
avatar for Ji Darwish

Ji Darwish

Data Platform Engineer, Xomnia
Ji is a Software Engineer at Lunatech with a background in Computer Science & Engineering from TU Delft and a recently completed MSc in Artificial Intelligence from Utrecht University. With years of experience in software development, he focuses on solving real-world software and... Read More →
Friday September 18, 2026 12:05 - 13:40 CEST
G106 + G107 (1st Floor)

12:40 CEST

Stateless Agents, Stateful Worlds: Designing for Interruption - Arul Kumaran, Luracast / Portel
Friday September 18, 2026 12:40 - 13:05 CEST
Anthropic just announced MCP is going stateless. Most agent frameworks assume long-running, uninterrupted sessions. Real deployments face forced interruptions every hour: rate limits, auth refreshes, network partitions, process restarts, the laptop lid closing. When a session dies mid-task, most agents start over. That is not a model problem. It is a runtime design problem.

This talk covers the patterns that make agents resumable: idempotent tool calls that can safely re-execute, checkpoint-first execution that captures decisions before side effects, explicit continuation tokens that let a new session pick up an interrupted task, and the specific primitives a TypeScript runtime on Cloudflare Workers exposes to make all of this cheap. Every pattern shown is running in production on Photon, an open-source agentic tool runtime deployed to edge infrastructure.

Attendees leave with a concrete checklist: five changes to their agent architecture that make it survive the real world, not just the happy path.
Speakers
avatar for Arul Kumaran

Arul Kumaran

Founder, Luracast / Portel
Arul Kumaran builds developer infrastructure for the agentic era. He created Photon, a runtime that compiles TypeScript into CLI, web app, and MCP-compatible agent tools simultaneously, and NCP (Natural Context Provider), a meta-MCP unifying 50+ tools behind 2-3 interfaces - cutting... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
Auditorium (Ground Floor)

12:40 CEST

Beyond Vibe-Testing: Engineering Deterministic Agent Skills - Shuva Jyoti Kar, Palo Alto Networks
Friday September 18, 2026 12:40 - 13:05 CEST
The AI ecosystem suffers from a critical engineering immaturity: deploying stochastic models via manual "vibe checks." Operating autonomous agents at enterprise scale requires abandoning ad-hoc observation for strict, distributed systems rigor. This session introduces a deterministic, CI/CD-native evaluation architecture for Agent Skills, shifting from indeterministic to reliable software execution.

By adhering to the formalized capability standards defined by agentskills.io, we will deconstruct the transition from subjective testing to hermetic, code-driven audits. Attendees will learn to engineer scenario matrices that enforce strict cognitive boundaries via negative testing—guaranteeing agents safely reject out-of-scope triggers. We will demonstrate isolating execution within sandboxed environments to capture pristine telemetry: deterministic tool-call structures, system exit codes, and exact token utilization.

Crucially, we address the anti-pattern of relying on "LLM-as-a-judge" for critical path assertions. Instead, we architect a framework grading system invariants via AST parsing and JSON Schema enforcement to achieve instantaneous, hallucination-immune evaluation.
Speakers
avatar for Shuva Jyoti Kar

Shuva Jyoti Kar

Principal Engineer, Palo Alto Networks
Shuva is a Principal Engineer at Palo Alto Networks, architecting secure enterprise AI platforms. An open-source contributor and author of the upcoming books: Engineering the Data Agent Control Plane (O'Reilly), Agent Skills in Action (Manning), and The Agentic Mind(Apress), his work... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
G104 + G105 (1st Floor)

12:40 CEST

From API Catalogs To Agent Catalogs: Solving MCP Server Discovery With Open Resource Discovery - Vyshnavi Gadamsetti & Sebastian Wennemers, SAP SE
Friday September 18, 2026 12:40 - 13:05 CEST
As MCP servers multiply, the ecosystem is hitting the fragmentation problem APIs hit a decade ago: every server is a point-to-point integration with no shared way to discover or describe it. Live introspection over a connected session does not scale to the catalogs, registries, and gateways that need to reason about thousands of servers without starting each one up. Open Resource Discovery (ORD) solved this for APIs, events, and data products. Each resource publishes a static, machine-readable description at a well-known endpoint. Aggregators crawl those descriptions and build catalogs that registries and gateways can query without connecting to the resource. Recent ORD work applies the same shape to agents and the MCP servers they depend on, scoping the dependency to the tools and prompts an agent uses. The same pattern fits MCP. The talk walks through a Server Card design that serves tools, prompts, and resources alongside metadata from a well-known endpoint, so registries and gateways can reason about a server before any agent connects. The design has been contributed into the open MCP community via SEP-2127, with a public renderer and playground demonstrating it end-to-end.
Speakers
avatar for Vyshnavi Gadamsetti

Vyshnavi Gadamsetti

Software Development Architect, SAP SE
Vyshnavi Gadamsetti is a software architect at SAP, where she has worked for 14 years across enterprise software. Earlier in her career, she worked at PwC. Her current work spans MCP (Model Context Protocol), ORD (Open Resource Discovery), agent extensibility and governance, and the... Read More →
avatar for Sebastian Wennemers

Sebastian Wennemers

Chief Architect, SAP SE
Sebastian Wennemers has 15+ years of experience in building and architecting solutions that need a solid metadata foundation. He is currently driving SAPs metadata story that grounds the AI strategy.
Friday September 18, 2026 12:40 - 13:05 CEST
Emerald Room (1st Floor)

12:40 CEST

Agents Talking To Agents: MCP, A2A, and the Reality of Multi-Agent Orchestration in Production - Willem Berroubache, Orange
Friday September 18, 2026 12:40 - 13:05 CEST
Building a multi-agent system in a notebook is straightforward
Running one on production infrastructure, where a wrong handoff triggers a real incident, is a different problem entirely.

This talk shares hard-won lessons from deploying autonomous agents using both MCP and A2A protocols in a large-scale, regulated environment.
We move past the happy path and focus on what actually breaks: agents that lose task context mid-chain, trust boundaries that collapse during agent-to-agent delegation, tool conflicts between concurrent agents, and orchestration failures that only surface under real load.
We walk through three patterns that emerged from this work. How to split responsibilities between MCP and A2A so each protocol does what it is actually good at. How to scope agent authority using MCP server boundaries without creating coordination bottlenecks. And how to design agent-to-agent handoffs that degrade gracefully when part of the chain fails mid-task.

No toy examples. No vendor pitches. Concrete decisions, the tradeoffs behind them, and what we would change today. Attendees leave with patterns they can apply the next day, regardless of their agent framework.
Speakers
avatar for Willem Berroubache

Willem Berroubache

AI for Security Project Manager, Orange
I work as Stream manager for 5G Core security monitoring & APIs at Orange.
Before that, I have managed innovative 5G projects involving Edge Computing and k8s in collaboration with Google.
I have conducted studies and PoCs on Edge Computing, automated and deployed 5G NF, and pro... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
G102 + G103 (1st Floor)

13:15 CEST

Agent-Smith: Never Send a Human To Do a Machine’s Job - Glenn ten Cate, The Linux Foundation & Jorge Carvalho, Nedap
Friday September 18, 2026 13:15 - 13:40 CEST
Most AI security agents are wrappers around fixed scripts. Agent-Smith takes a different approach: reusable skills encode security methodology, while the model determines how to investigate, chain tools, validate findings, and select its next action.

This session presents the architecture and lessons behind Agent-Smith, an open-source, MCP-enabled autonomous penetration-testing agent spanning web, cloud, Active Directory, source-code review, threat modeling, and AI red teaming and more. We will examine MCP tool exposure, methodology-as-code, autonomous skill chaining, model portability, ephemeral Docker sandboxes, and server-side controls for cost, execution time, and tool calls.

A practical demonstration will show Agent-Smith progressing from reconnaissance to a verified finding, reproducible proof of concept, remediation guidance, and code patch. Attendees will leave with concrete patterns for building capable agents without sacrificing isolation, observability, human oversight, or control.

“Never send a human to do a machine’s job.”
Speakers
avatar for Glenn ten Cate

Glenn ten Cate

Senior Cybersecurity trainer, The Linux Foundation
Glenn Ten Cate is a cybersecurity expert and trainer at the Linux Foundation with more than 20 years of experience as an ethical hacker, educator, and offensive security practitioner. He previously co-created and led the Security Knowledge Framework, an open-source flagship project... Read More →
avatar for Jorge Carvalho

Jorge Carvalho

Application Security Engineer, Nedap
Jorge Carvalho is an Application Security Engineer at Nedap with a passion for building secure software and exploring the security implications of emerging technologies. Much of his expertise has been developed through self-directed learning, hands-on research, and practical experience... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
Auditorium (Ground Floor)

13:15 CEST

From Vibes To Data: Evaluating Agents on Your Real Work - Ville Hellman, Datadog
Friday September 18, 2026 13:15 - 13:40 CEST
Frontier labs are spending billions making agents better at SWE-Bench. But how much of your engineering work actually looks like SWE-Bench? At Datadog we kept seeing agents that crushed public benchmarks fail on our codebase: missing our conventions, reaching for the wrong internal libraries, technically correct but doing the work the wrong way.

To get past demos and gut feel, we built an evaluation platform that measures agents on tasks drawn from our real work, and gave our platform teams a way to encode best practices as evals. Teams shipping skills, steering docs, agent harnesses, and MCP servers can now see whether their changes actually moved the needle.

In this talk I'll share how SOTA and open-weight models actually compare on real work, what their cost-performance profiles look like, tooling decisions that can shift token usage by 10% or more, and how a surprisingly small eval suite can produce stable signal.

You'll leave with a clearer way to think about model choice as a tradeoff between performance you actually need and tokens you're willing to spend, and a sharper sense of what makes an eval keep paying off over time instead of becoming a one-off exercise.
Speakers
avatar for Ville Hellman

Ville Hellman

Staff Engineer, Datadog
Ville is a Staff Engineer in Datadog's AI DevX group, where he builds evaluation infrastructure for the agents and tooling Datadog engineers use every day. He writes on AI-augmented engineering, AI literacy, and developer experience to make what's coming next easier for others to... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
G104 + G105 (1st Floor)

13:15 CEST

Beyond Chatbots: Agentic UI With Open Standards - Manfred Steyer, ANGULARarchitects
Friday September 18, 2026 13:15 - 13:40 CEST
Integrating agentic AI into the UI easily leads to ad hoc integrations, tight coupling to backend technologies, and vendor lock-in. So how do we design scalable, maintainable interactions between agents and users?

This session shows how open standards like AG-UI, A2UI, and MCP Apps enable a protocol-driven approach to Agentic UI, establishing clear, message-based boundaries that decouple UI, agent logic, and tools. You’ll learn how to apply these standards, leveraging dynamic UI generation, tool integration, and Human-in-the-Loop patterns.

By the end, you’ll understand how to design Agentic UI using open standards and integrate them through clear, protocol-based boundaries.
Speakers
avatar for Manfred Steyer

Manfred Steyer

Trainer and Consultant, ANGULARarchitects
Trainer and Consultant with a focus on Agentic UI and Angular. Google Developer Expert (GDE) for Angular and Trusted Collaborator in the Angular team. Writes for O'Reilly, Hanser, and the German Java Magazine. Regularly speaks at conferences.
Friday September 18, 2026 13:15 - 13:40 CEST
G102 + G103 (1st Floor)

13:15 CEST

Spotify’s Bet on MCP and Investment in Open Source - Reinoud Kruithof & Yannick Epstein, Spotify
Friday September 18, 2026 13:15 - 13:40 CEST
Spotify’s workforce went from zero to near universal use of MCP servers in breakneck time. It was only possible due to the MCP gateway - custom code written in a weekend to support the urgent need to expose Spotify’s extensive internal API ecosystem to AI agents.

The MCP gateway rapidly became a victim of its own success; multiple teams were committing significant changes to the codebase, and domain ownership and on-call support for the gateway were somewhat uncertain. From a sustainability perspective, the MCP gateway was becoming a big risk.

In this talk you’ll learn how Spotify successfully rebased its highly custom MCP gateway use case onto OSS technologies, while retaining deep integration into Spotify’s infrastructure management plane, service discovery, and microservice ecosystem. Hear how kgateway, the Envoy proxy, kro, and the Gateway API were used to build the new MCP gateway, enabling it to be better sustained by the right teams contributing their specific expertise.
Speakers
RK

Reinoud Kruithof

Senior SRE, Spotify
avatar for Yannick Epstein

Yannick Epstein

Senior Software Engineer, Spotify
Yannick Epstein is a Senior Engineer in Spotify’s Core Infrastructure group, where he works on systems that manage traffic and communication between backend services. He led the discovery and engineering effort for Spotify’s custom xDS control plane and the company’s dynamic... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
Emerald Room (1st Floor)

13:40 CEST

15:00 CEST

Welcome Back - Manik Surtani, CTO, Agentic AI Foundation
Friday September 18, 2026 15:00 - 15:05 CEST

Speakers
avatar for Manik Surtani

Manik Surtani

CTO, Agentic AI Foundation

Friday September 18, 2026 15:00 - 15:05 CEST
Auditorium (Ground Floor)

15:05 CEST

Keynote: Three Doors to One Tool: MCP vs WebMCP vs CLI - Frédéric Barthelet, CTO & Co-founder, Alpic & Dominic Farolino, Editor of the WebMCP Specification & Software Engineer, Google
Friday September 18, 2026 15:05 - 15:15 CEST
Agents can reach a tool through at least three doors today: an MCP server, a WebMCP browser page, or a plain CLI. They overlap, they compete, and the discourse around them runs hot. This talk cuts through it.

We map the three surfaces along the axes that actually matter: where the code runs (backend, browser, model context, shell), who holds state and auth, latency and trust boundaries, and how much UI context survives the handoff. Then we get practical: a decision framework for picking the right surface per use case, the cases where you genuinely want two stacked together, and the anti-patterns that appear when you pick wrong.
Speakers
avatar for Frédéric Barthelet

Frédéric Barthelet

CTO & Co-founder, Alpic
Fred is a passionate opinionated builder. He's been in the infrastructure space, and in particular in serverless technologies.

He built Lift and Revant to help people ship infrastructure and reduce their newly generated cost...

He's now building with Alpic the missing infrastructure layer for the new agentic internet where AI consume services instead of human. He's working full time on Skybridge, a new open-source framework to build ChatGPT and MCP Apps



... Read More →
avatar for Dominic Farolino

Dominic Farolino

Software Engineer, Google
I work on agentic web platform APIs in Chrome!
Friday September 18, 2026 15:05 - 15:15 CEST
Auditorium (Ground Floor)

15:20 CEST

Keynote: Why Organizations Need an AI Control Plane for Security and Governance - Sheng Liang, Co-Founder & CEO, Obot AI
Friday September 18, 2026 15:20 - 15:30 CEST
How can organizations secure and govern AI agents they do not fully trust? MCP gateways can intercept and filter tool calls, but that alone is not enough. Organizations also need complete visibility into agent activity, consistent policy enforcement, and centralized control. In this talk, we explain how to move beyond MCP gateways and build an AI control plane for enterprise-wide security and governance.
Speakers
avatar for Sheng Liang

Sheng Liang

CEO, Obot AI
Sheng Liang is cofounder and CEO of Obot.ai. Previously, Sheng founded and served as CEO of successful open source software companies, including Rancher Labs and Cloud.com, and served in executive roles at SUSE and Citrix. He started as an engineer at Sun Microsystems, where... Read More →
Friday September 18, 2026 15:20 - 15:30 CEST
Auditorium (Ground Floor)

15:45 CEST

Giving Your Agentic Coding AI a Security Brain - Liran Tal, Snyk
Friday September 18, 2026 15:45 - 16:10 CEST
AI can generate a week’s worth of code before lunch and just as quickly ship SSRF, RCE, and path traversal vulnerabilities into prod. Rules and “/security-review” prompts aren’t enough: they’re costly, brittle, and non-deterministic. Run them three times, get three answers. Meanwhile, who vets hallucinated npm packages as the agent installs them? Oh you’re running the agent with “--dangerously-skip-permissions”? Color me surprised, sigh.

Well the good news is you don’t have to trade speed for security, let me show you how. This talk shows a concrete, developer-first pattern: learn how to use MCPs & Hooks to give agents real security superpowers. We’ll wire in just-in-time package health checks and deterministic code reviews via pluggable AI components, with clear contextually engineered details for your agent. You’ll leave with a better understanding of the security dangers relying on agentic coding tools alone and a reliable and deterministic agentic workflow to make AI coding fast and safely shippable.
Speakers
avatar for Liran Tal

Liran Tal

Director of Developer Relations, Snyk
Liran Tal is an AI Security researcher, a seasoned Node.js developer, and a secure coding expert focused on hardening agentic workflows and the Model Context Protocol (MCP). He discovers and discloses CVEs in MCP servers and AI frameworks, and publishes research on tool poisoning... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
G104 + G105 (1st Floor)

15:45 CEST

How we Reclaimed Significant Engineering Capacity at Salesforce with AI Agents - Axel Uhlig, Salesforce
Friday September 18, 2026 15:45 - 16:10 CEST
We built and deployed an AI Agent at Salesforce designed to triage production alerts using service logs. After months of iteration, we achieved an accuracy level that earned the trust of our DevOps personnel. Today, the agent reclaims approximately 20% of weekly engineering capacity for the teams using it.

Here are our top 5 takeaways for building agents that perform consistently at high accuracy:
1. Specialization beats generalization: For high-accuracy tasks, purpose-built solutions outperform generic models every time.
2. Provide "Proof of Work": Make it effortless for humans to verify the agent's logic. Transparency builds trust.
3. Minimize friction: We used Slack as the primary interface. Don't require local setups to boost adoption and usage
4. Build in public: Operating in shared channels allows for seamless human-agent cooperation (and agent-to-agent orchestration).
5. Hosted > Local: Local scripts are great for individuals, but standardized, team-wide automation requires a hosted environment to scale.
Speakers
avatar for Axel Uhlig

Axel Uhlig

Software Engineer, Salesforce
Specialized in developer productivity, like building internal agents using LangChain or large scale Bazel migrations.
Friday September 18, 2026 15:45 - 16:10 CEST
Auditorium (Ground Floor)

15:45 CEST

Evaluating Agents at Scale: From 50 Examples to a Production Flywheel - Bauke Brenninkmeijer, Orq.ai
Friday September 18, 2026 15:45 - 16:10 CEST
LLM agents are reaching production faster than teams can evaluate them. A data-analysis agent that runs the right query but reports the wrong number, or returns the right number via a trajectory full of fabricated tool calls, passes superficial testing and fails in production.

This talk walks through evaluating such an agent end-to-end. Our running example: a data-analysis agent answering questions over a business dataset. We show how to grade three dimensions that agent evaluation requires and single-shot LLM evaluation ignores: final response, trajectory, and state changes.

We cover the full lifecycle:

1. Bootstrapping evaluation from 50 hand-reviewed examples when you have no labels.
2. Aligning an LLM-as-a-judge to human judgment with the same rigor you'd apply to outsourced annotators: dev/test splits, inter-rater agreement, Cohen's kappa.
3. Scaling to continuous online evaluation with CI integration, error analysis, and prompt optimization driven by natural-language feedback.

We also cover what we got wrong in earlier iterations and what we'd do differently today.
Speakers
avatar for Bauke Brenninkmeijer

Bauke Brenninkmeijer

AI Research Engineer, Orq.ai
Bauke is an AI Research Engineer with a background in data science and computer science. After working at several startups, I spent 5 years building ML systems at ABN AMRO and ING — from real-time streaming frameworks to RAG-based document processing.Now at orq.ai, I focus on AI... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
G106 + G107 (1st Floor)

15:45 CEST

Attribution by Design: Skills, MCP, and Where Provenance Gets Built In - Ola Hungerford, Model Context Protocol
Friday September 18, 2026 15:45 - 16:10 CEST
Agents increasingly draw on specialized human knowledge at inference time, and the infrastructure delivering it is converging around Skills, MCP, and very often a mix of the two. That makes these standards a decision point: provenance either travels with the knowledge or its absence becomes the default.

The MCP community is standardizing two complementary efforts: Interceptors (deterministic hooks in clients, servers, and gateways) and how, why, and when to serve Skills over MCP. This talk shows how the two fit together to standardize attribution for human expertise and other content encoded as Skills and related inference-time formats.

The talk showcases two examples:
- An attribution gateway that validates and records authorship in a centralized control plane
- A standardized client-side hook to log and credit authors when Skills are invoked
Speakers
avatar for Ola Hungerford

Ola Hungerford

Principal Engineer, Nordstrom
Ola Hungerford is a Principal Engineer at Nordstrom and a maintainer and community moderator for the Model Context Protocol. She leads AI enablement initiatives while contributing to MCP’s specification, developer tooling, documentation, and community governance. Ola comes from... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
Emerald Room (1st Floor)

15:45 CEST

The Serving Layer Is the Agent's Bottleneck - Swapnil Tiwari, AWS
Friday September 18, 2026 15:45 - 16:10 CEST
I've spent the past year tuning open-source inference stacks (vLLM, SGLang) for production agent systems. The same failure modes keep appearing, and they all live in the serving layer.

Biggest one: KV cache thrashing. Agents rebuild thousands of tokens of system prompt + tool schemas every turn. Prefix-aware caching fixes this in six lines of config. I've measured 55-65% latency reduction on turn 2+ across twelve deployments. Almost nobody enables it.

Second: batch-of-one paralysis during tool-calling loops. Each LLM call is a single request, GPU 80%+ idle. Disaggregated prefill/decode with continuous batching unlocks 3-5x throughput. Requires ~40 lines of change in most agent frameworks.

Third: agent latency is bimodal (short tool-selection turns vs long reasoning turns). A single timeout threshold wastes GPUs or kills valid turns. Two-tier serving handles both.

Open configs. Real numbers from workloads I instrumented. If you're building agents and haven't looked below the orchestrator, this fills the gap.
Speakers
avatar for Swapnil Tiwari

Swapnil Tiwari

GenAI Solutions Architect, AWS
GenAI Solutions Architect specializing in LLM inference optimization for agentic workloads. Helped 50+ teams redesign serving infrastructure, with documented 5-10x cost reductions. Built inferenceengineering.tech (open-source, 2K+ users). Conduct security assessments on MCP deployments... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
G102 + G103 (1st Floor)

16:20 CEST

Autonomous Organisations: Starting Small - Floris Fok, Prosus
Friday September 18, 2026 16:20 - 16:45 CEST
What does it take to let AI agents run a real business? Before handing over an entire restaurant, our team started with something much smaller: a network of vending machines.

In this session, we'll share what we've learned by giving AI agents responsibility for real world operational decisions, including pricing, inventory management, and marketing. The vending machine serves as a practical testbed for exploring how autonomous organizations behave under real customer demand, where mistakes have real consequences but the risks remain manageable.

We'll discuss how this work evolved from simulated restaurant environments into live deployments, what worked, what failed, and why small scale experiments are the fastest path toward larger autonomous operations. We'll also look ahead to the next phase, including autonomous restaurants and the role robotics may play.

Attendees will leave with a practical framework for experimenting with autonomous organizations, along with lessons learned from taking AI agents out of the lab and into the real world.
Speakers
avatar for Floris Fok

Floris Fok

Staff AI Engineer, Prosus
Big hacker leading JetSki at Prosus here. JetSkis are smaller, more disruptive initiatives. Heavy AI/NLP backgrounds. Have coauthored Climate GPT: a Foundational Model. Have an engineering background and started with training LLMs the moment they were released many years ago.
Friday September 18, 2026 16:20 - 16:45 CEST
G104 + G105 (1st Floor)

16:20 CEST

Gating High-Risk Agentic Actions at the Relying Party With Exogenous (Out-of-Band) Inputs - Dominic Forrest, iProov
Friday September 18, 2026 16:20 - 16:45 CEST
A Confused Deputy arises when a trusted system with legitimate authority is induced to use that authority for a high-risk or irreversible action that the Agent's principal did not intend, creating a relying-party (RP) risk of repudiation. The Agent may arrive with valid Tokens, passkeys, inherited session, or tool credentials, even if instructions have been shaped by prompt injection or model miscomprehension. Whilst the request is authenticated, human consent to the means taken is not.

This session develops how RPs can deploy a gatekeeper to distinguish authorised access from authorised actions and produce a legally auditable record. When proving the principal is present and consenting, it assumes that any signal produced by the agent or its device remains endogenous to the compromised context. This requires an exogenous proof that the agent cannot generate, evaluated by the RP before execution.

The talk presents a decentralised, open-source, relying-party pattern that does not require the agent or its operator to have onboarded to or used the scheme. It composes with OAuth, MCP, and passkeys, adding the missing intent boundary for agent-mediated workflows.
Speakers
avatar for Dominic Forrest

Dominic Forrest

Chief Technology Officer, iProov
Dominic is responsible for iProov’s technology vision, strategy, and roadmap including the design and development of its cloud-based infrastructure.

Dominic has over 25 years of experience in senior roles in telecommunications and internet service providers. He joined iProov from mBlox Inc., where as Senior Vice President he oversaw the development and scalability of the platform seamlessly running over 6 billion transitions... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
Auditorium (Ground Floor)

16:20 CEST

Infrastructure Red Teaming With Abliterated Models: What Actually Stops Agent Attacks - Roy Belio, Red Hat
Friday September 18, 2026 16:20 - 16:45 CEST
Safety-aligned models refuse adversarial prompts, so you can't test whether your infrastructure controls actually work, but the models are all still susceptible to jail-breaking.
I removed that variable with an abliterated Qwen3.5 model to get zero refusals and 100% cooperation. Ran full suite of prompts with custom garak probes across three hardening tiers on an OpenClaw agent running in OpenShift.

I found out what worked and what gave false sense of security.
Sandbox isolation dropped credential exfiltration entirely in one step. NetworkPolicy killed cluster escalation. The prompt injection classifier caught encoding-based attacks. Three of four attack categories were fully stopped by Tier 2 (injection classification+isolation).

Memory poisoning was the exception. Probes that instruct the agent to write attacker content into its own memory continued to succeed across all tiers. OWASP added this as ASI06 to its 2026 Agentic Top 10. No deployed control addresses it today.

I'll present the full probe results, the defense configurations, and the open problem current agent architectures don't solve.
Speakers
avatar for Roy Belio

Roy Belio

Senior Software Engineer, Red Hat
Roy Belio is an AI Engineer at Red Hat, where he builds and evaluates proof-of-concept projects, drives open source contributions, and deploys AI/ML infrastructure on OpenShift.
Before Red Hat, Roy spent five years at Microsoft, Infinidat and Checkpoint.
He holds a BSc in Inform... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
G102 + G103 (1st Floor)

16:20 CEST

From Advisory to Autonomous: A Staged Model for Agent Adoption - Milos Mandic, Lleverage
Friday September 18, 2026 16:20 - 16:45 CEST
Most teams shipping agents into production hit the same wall. The build is fast. The adoption is not. A solution that works in three weeks can take three months before operators trust it enough to actually use.

This talk is about closing that gap. Drawing on production deployments across fifteen-plus enterprise clients in logistics, wholesale, manufacturing, insurance, and finance, I'll walk through a four-stage model for moving agents from advisory to full autonomy without breaking trust along the way.

The talk goes deep on a single use case deployed across multiple clients: sales order processing. I'll cover what changed when we moved too quickly between stages and lost trust we had already earned, how we rebuilt it, and the operator-side patterns we now look for before progressing a stage.

The framework is protocol-agnostic. Whether teams are integrating agents through MCP, APIs, or a mix, the trust progression is the same. The talk should be useful for anyone building or deploying agent systems where humans remain in the loop and where adoption, not capability, is the binding constraint on impact.
Speakers
avatar for Milos Mandic

Milos Mandic

Founder & Editor, FDE Hub
Milos Mandic is a Forward Deployed Engineer based in Amsterdam. Over the past year he has shipped AI automation across more than fifteen parallel client engagements in logistics, wholesale, manufacturing, insurance and finance. He writes FDE Hub, a vendor-neutral newsletter on the... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
G106 + G107 (1st Floor)

16:20 CEST

Most MCP Servers are Empty - David Golverdingen, Warmtebouw
Friday September 18, 2026 16:20 - 16:45 CEST
An analysis of 856 tools across 103 MCP servers found 97% of tool descriptions carry a critical smell. But smells aren't the real problem: the data is fine, what's broken is meaning. MCP isn't dead, most servers are empty, calling every endpoint and understanding nothing.

I run nine production MCP servers (50+ tools) at a 300-400 person Dutch HVAC company, used daily by non-developers. A maturity ladder emerged: most just wrap an API; a rare few teach the agent the domain, with the knowledge inside the tool description itself. The same data behind a wrapper versus a self-teaching tool is a different product.

To climb the ladder as you build: scaffold from the API docs, ship something simple, then run Introspective Context Engineering, a loop of Examine, Flag, Validate, Encode, Iterate. An AI explores the data and flags patterns by confidence; a domain expert confirms or kills the uncertain ones in an afternoon. Then telemetry takes over: every call carries a queryIntent, so the logs reveal what the agent thought it was doing, exposing the gap. Fixes take hours, not design cycles.

You'll leave with the maturity model, the discovery method, and a runnable open-source example.
Speakers
avatar for David Golverdingen

David Golverdingen

Senior Engineer & MCP Architect, Warmtebouw
David Golverdingen is a Senior Engineer & MCP Architect at Warmtebouw, a mid-sized Dutch HVAC company. He built and runs its production MCP platform: nine servers, 50+ tools and five MCP Apps that let non-technical staff explore the company's ERP, BIM, building automation and energy... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
Emerald Room (1st Floor)

16:55 CEST

No Central Brain - Fausto Albers, WonderWhy
Friday September 18, 2026 16:55 - 17:20 CEST
Who decides what an agent treats as true? Nothing does, and that is the point. In every system that stays reliable, from a cell to an immune system to a market, correctness isn't assigned by a designer; it's selected. The parts hold competing variants, and an external pressure culls the wrong ones. A more capable part doesn't escape this. It just gets better at exploiting whatever pressure you actually applied.

You can't make the pressure random the way nature does, but you can design it: the goal, the loss, the verifier, the loop the agent runs inside. So stop dictating answers and start shaping the environment that selects them.

We introduce five design laws, each learned by building real-world agents and memory systems that had to stay honest under a pressure they couldn't game.
Speakers
avatar for Fausto Albers

Fausto Albers

Founder, WonderWhy & GenAI R&D Lead, HvA Industrial Digital Twins Lab, WonderWhy AI
Fausto Albers is the founder of WonderWhy, an applied-AI company in Amsterdam, and co-founder of AI Builders Club, a European community for people who build with AI. He trained as a sociologist, then founded successful restaurants and cocktail companies before turning his understanding... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
G102 + G103 (1st Floor)

16:55 CEST

Shipping a Production App in 10 Days: A Real Measurement of AI-Assisted Development - Julien Dubois, GitHub
Friday September 18, 2026 16:55 - 17:20 CEST
We've all seen the AI coding demos. But what does it really cost to ship a production application with an AI agent, and how much time does it actually save?

This talk answers that with hard numbers from a real, open-source project: BootUI ( https://github.com/jdubois/boot-ui ), a multi-module Java project with roughly 40 deeply-integrated feature panels, an embedded Vue 3 console, ~83,000 lines of code, ~116 test suites, and a full release pipeline. It was built through a tagged 1.0.0 release in about 10 calendar days by a single developer driving the GitHub Copilot coding agent, at a sustained pace of ~20 merged pull requests per day.

Using git history, PR metadata, and code metrics, we reconstruct two timelines: what the project actually took with AI (~80-110 hours of human effort), and a grounded estimate of what the same scope would take a senior developer by hand (~6.5-8.5 months).

You'll leave with a realistic mental model of where AI coding delivers 10x-plus leverage on Java projects, where it doesn't, and the practices that let you safely accept high agent throughput.
Speakers
avatar for Julien Dubois

Julien Dubois

Principal Manager, Developer Relations, GitHub
Julien Dubois is a Java Champion and Principal Manager at Microsoft, where he leads the Java Developer Relations team inside the CoreAI and GitHub organizations. With his team of world-class developer advocates, Julien works directly with the engineering groups to improve how Java... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
Auditorium (Ground Floor)

16:55 CEST

MCP Challenges & Opportunities - Sam Morrow, GitHub; Angie Jones, Agentic AI Foundation; Shaun Smith, Hugging Face; Shub Argha, Arcade
Friday September 18, 2026 16:55 - 17:20 CEST
Join Jeremiah Lowin (Fast MCP), Shaun Smith (fast-agent) and Sam Morrow (GitHub MCP) for a panel on the challenges and opportunities of shipping MCP, hosted by Angie Jones, VP of Developer Experience at the AAIF.

By bringing perspectives from server, SDK and agent harness developers together in the same panel, you’ll see where their experiences align, l where they diverge, where they see the protocol heading and what they’re excited about.
Speakers
avatar for Shub Argha

Shub Argha

Head of Forward Deployed Engineering, Arcade
Shub Argha is the Founding Forward Deployed Engineer @ Arcade.dev. He is a proud Michigan Wolverine with a passion for innovation and entrepreneurship, especially in AI and electronics. In quieter moments, he enjoys the literary works of Michael Chabon.
avatar for Angie Jones

Angie Jones

Vice President, Agentic AI Foundation

avatar for Shaun Smith

Shaun Smith

Open Source Agents / MCP, Hugging Face

avatar for Sam Morrow

Sam Morrow

Staff Software Engineer, GitHub
Sam is a Staff Software Engineer at GitHub, where he leads development of the GitHub MCP server. He works on AI developer tools and helps shape agentic workflows at GitHub. In a past life he was also a professional drummer.
Friday September 18, 2026 16:55 - 17:20 CEST
Emerald Room (1st Floor)

16:55 CEST

The Autonomous Enterprise – Scaling Computer Use With Holo3 and HoloTab - Pierre-Louis Cedoz, H Company
Friday September 18, 2026 16:55 - 17:20 CEST
H Company is the leading agentic AI startup in Europe, based in Paris, specialized in computer use.

The AI landscape is shifting rapidly from passive text generation to active execution. The frontier belongs to Agentic AI, systems that don't just chat, but autonomously navigate digital environments to complete complex workflows.

At H Company, we bridge this gap between frontier research and production-grade deployment. We will explore how H Company built Holo3, our state-of-the-art model family designed specifically for "Computer Use" (GUI perception, planning, and OS navigation). Moving from theory to practice, we will demonstrate how these compact, high-efficiency models power our latest enterprise tools—including HoloTab, our autonomous AI browser companion. Finally, we will unpack the unified infrastructure model required to train, deploy, and scale these agents securely across multi-cloud environments.
Speakers
avatar for Pierre-Louis Cedoz

Pierre-Louis Cedoz

CTO, H Company
Pierre-Louis Cedoz is CTO at H Company, where he leads the research and development of next-generation, action-oriented AI. With an extensive background spanning reinforcement learning, large action models, and advanced machine learning research at institutions like Stanford University... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
G104 + G105 (1st Floor)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -