Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
arrow_back View All Dates
Friday, September 18
 

08:00 CEST

Registration & Badge Pick-Up
Friday September 18, 2026 08:00 - 17:20 CEST

Friday September 18, 2026 08:00 - 17:20 CEST
Onyx Lounge (Ground Level)

09:00 CEST

Keynote: Welcome - Welcome - Angie Jones, Vice President of Developer Experience, The Agentic AI Foundation
Friday September 18, 2026 09:00 - 09:10 CEST

Speakers
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
Friday September 18, 2026 09:00 - 09:10 CEST
Auditorium (Ground Level)

09:10 CEST

Keynote to be Announced
Friday September 18, 2026 09:10 - 09:20 CEST

Friday September 18, 2026 09:10 - 09:20 CEST
Auditorium (Ground Level)

09:25 CEST

Keynote: Agents as Actors: Harnessing the Power of Agentic Infrastructure - Idit Levine, Founder & CEO, Solo.io & Keith Babo, Chief Product Officer, Solo.io
Friday September 18, 2026 09:25 - 09:35 CEST
Harnessed agents have become the dominant interaction and runtime pattern for agentic AI. Claude Code, Codex, and a fast-growing field of open source harnesses integrate models with MCP tools, skills, and plugins. These harnesses provide sandboxed execution, scoped environment access, and human-in-the-loop controls on the desktop. The industry's next shift is already underway: moving harnessed agents from the desktop onto shared infrastructure, where security, observability, and governance are consistent across every agent interaction. In this talk, we will explore how open source infrastructure can deliver secure, scalable harnessed agents beyond the desktop.
Speakers
avatar for Idit Levine

Idit Levine

Founder & CEO, Solo.io
Idit Levine is the founder and CEO of Solo.io, where she is dedicated to simplifying agentic AI and empowering organizations to embrace cloud-native technologies. With a strong background in distributed systems and cloud infrastructure, Idit is passionate about transforming complex... Read More →
avatar for Keith Babo

Keith Babo

Chief Product Officer, Solo.io
Keith Babo is the Chief Product Officer at Solo.io, where he leads product strategy and execution, enabling enterprises to build and scale the next generation of cloud-native and agentic infrastructure for AI-driven applications. Prior to Solo.io, Keith held leadership roles in product... Read More →
Friday September 18, 2026 09:25 - 09:35 CEST
Auditorium (Ground Level)

09:35 CEST

Keynote: Dexter Horthy, CEO and Co-Founder, HumanLayer
Friday September 18, 2026 09:35 - 09:45 CEST

Speakers
avatar for Dexter Horthy

Dexter Horthy

CEO and Co-Founder, HumanLayer
Dex is CEO and co-founder at HumanLayer, building an agentic IDE and collaboration platform that helps teams solve hard problems in complex codebases without devolving into slop. Dex coined the term context engineering in April 2025, has keynoted two AI Engineer conferences, and his... Read More →
Friday September 18, 2026 09:35 - 09:45 CEST
Auditorium (Ground Level)

09:50 CEST

Keynote: Three Doors to One Tool: MCP vs WebMCP vs CLI - Frédéric Barthelet, CTO & Co-founder, Alpic & Dominic Farolino, Software Engineer, Google
Friday September 18, 2026 09:50 - 10:00 CEST
Agents can reach a tool through at least three doors today: an MCP server, a WebMCP browser page, or a plain CLI. They overlap, they compete, and the discourse around them runs hot. This talk cuts through it.

We map the three surfaces along the axes that actually matter: where the code runs (backend, browser, model context, shell), who holds state and auth, latency and trust boundaries, and how much UI context survives the handoff. Then we get practical: a decision framework for picking the right surface per use case, the cases where you genuinely want two stacked together, and the anti-patterns that appear when you pick wrong.
Speakers
avatar for Frédéric Barthelet

Frédéric Barthelet

CTO & Co-founder, Alpic
avatar for Dominic Farolino

Dominic Farolino

Software Engineer, Google
I work on agentic web platform APIs in Chrome!
Friday September 18, 2026 09:50 - 10:00 CEST
Auditorium (Ground Level)

10:00 CEST

Coffee Break
Friday September 18, 2026 10:00 - 10:20 CEST

Friday September 18, 2026 10:00 - 10:20 CEST
Solutions Showcse - Diamond Lounge

10:00 CEST

Solutions Showcase
Friday September 18, 2026 10:00 - 15:30 CEST

Friday September 18, 2026 10:00 - 15:30 CEST
Diamond Lounge (Ground Level)

10:20 CEST

Agentic AI and Hybrid Architecture - Redefining 100+ Applications at Scale - Pradheepa V, adidas AG
Friday September 18, 2026 10:20 - 10:45 CEST
At adidas Europe Market Tech, a lean team of architects and engineers are making a big difference, transforming 100+ applications by embedding AI agents into everyday workflows. We leverage AI with clear purpose to shape a new operating model to drive end-to-end efficiency and productivity at enterprise level.

In this session, we share our transformation journey, challenges we addressed and its impact on business, people & process. On the technical stack, we will enlighten you on:
– Production proven patterns for running AI tools in parallel, speedy deployment-ready applications, architecture reasoning and how we are accelerating our path to realising our north star.
– How we benefit from a hybrid AI architecture: cloud models for high-value reasoning, paired with locally hosted LLMs for implementation. How we balance cost, latency and efficiency at scale.
– What way architecture agents enable continuous, scalable visibility across complex application landscapes - turning static data into meaningful insights.

Ultimately, the way “Through sport, we have the power to change lives”, we believe “Through AI, we have the power to change the tech landscape to stay future-ready”
Speakers
avatar for Pradheepa V

Pradheepa V

Europe Market Tech Architecture Lead, adidas AG
Pradheepa Vijayaraghavan is a solution architect and engineering leader at adidas Germany, with 21+ years of international experience across Europe, the Americas, and Asia-Pacific. She has led mission-critical platforms in e-commerce, FinTech, automotive, and enterprise technology... Read More →
Friday September 18, 2026 10:20 - 10:45 CEST
Auditorium (Ground Level)

10:20 CEST

Pull Requests Are Dead, Long Live Peer Review - Dylan Ratcliffe, Overmind
Friday September 18, 2026 10:20 - 10:45 CEST
When AI writes 80–90% of the code on a team, peer review breaks. The pull request is produced by a machine you can't argue with, and the reviewer is auditing a diff instead of talking to a peer. Review has stopped feeling like collaboration, and most of us have started hating it.

We rebuilt how we deploy AI-assisted development in production. Human review moved off the diff and onto the plan: the intent written before any code gets generated. Engineers review the thinking they care about and let the agent fill in the gaps. When the PR lands, CI runs the usual checks plus an automated comparison against the approved plan. Only deviations route back to the original reviewer.

This is a case study in integrating AI into a real SDLC without breaking accountability, quality, or culture. I'll walk through what broke, what we automated, and what stayed human: an in-house MCP server for plan review in the IDE, deviation-checking on every PR, and cultural bets (everyone operates as a team lead; no questions until working code; customer context radiated to the whole team).

We massively improved our velocity and our lead time, and our engineers love the job again.
Speakers
avatar for Dylan Ratcliffe

Dylan Ratcliffe

Founder & CEO, Overmind
Before founding Overmind, Dylan spent 6 years in the trenches helping companies adopt DevOps at Puppet. Hey got frustrated seeing smart people and good products not being used to the best of their ability because of fear of change, so he started Overmind.
Friday September 18, 2026 10:20 - 10:45 CEST
G102 + G103 (Level 1)

10:20 CEST

Potential Issues for Cross-domain Multi-hop API Calls and Their Solution Proposal - Takashi Norimatsu, Hitachi, Ltd.
Friday September 18, 2026 10:20 - 10:45 CEST
When an MCP server calls an API server requiring an access token in a different domain, elicitation in URL mode is defined by the MCP. Furthermore, token exchange is also used in real-world use cases. We describes the security and operational issues associated with these two methods and proposes solutions.

Elicitation in URL mode may cause user swapping. Moreover, even if an authorization server performing the initial authorization securely perform it by following MCP spec, the well-known attacks may succeed if the other authorization server performing the external authorization does not care about security.

Token exchange may cause information leaks, fraudulent access token use, and availability problems.

In both methods, there are two access tokens: for accessing the MCP server, for accessing the API server. To detect user swapping, it is needed to ensure that both users bound with the first and second token are the same. However, even if the same user registered in both different domains, their user identifiers are usually different. Therefore, simply matching them exactly is not effective.

We describe these issues and propose their solutions.
Speakers
avatar for Takashi Norimatsu

Takashi Norimatsu

Chief OSS Specialist, Hitachi, Ltd.
Takashi Norimatsu, PhD in Engineering, Chief OSS Specialist, Hitachi, Ltd. is a maintainer of Keycloak. He has been implemented and contributed security features like Financial-grade API (FAPI) security profiles, Passkeys, Model Context Protocol (MCP) support. He leads Keycloak's... Read More →
Friday September 18, 2026 10:20 - 10:45 CEST
Emerald Room (Level 1)

10:20 CEST

Workshop: Keep Infrastructure Out of Your AI Agents: The Agent Gateway Pattern - Lin Sun, Solo.io
Friday September 18, 2026 10:20 - 11:55 CEST
As AI agents move into production, engineering teams face a growing set of challenges. How do you secure and govern MCP servers without modifying them? Route and fail over across multiple LLM providers? Enforce rate limits, access controls, and governance policies? Observe agent traffic, and scale operations across environments?

Rather than embedding these capabilities into every agent, MCP server, and application, organizations can adopt a single architectural pattern: the agent gateway.

An agent gateway acts as a unified control plane for AI systems. It can function as an MCP gateway, LLM gateway, inference gateway, and traditional API gateway, centralizing security, observability, routing, resilience, and policy enforcement across agents, tools, models, and services.

In this hands-on workshop, you'll learn how to secure and federate MCP servers without code changes, route and fail over LLM traffic across providers, enforce authentication and usage policies, and gain end-to-end visibility into agent interactions. Through practical exercises, you'll see how a single gateway layer simplifies operations while enabling secure, scalable, and governable AI systems.
Speakers
avatar for Lin Sun

Lin Sun

Head of Open Source, agentgateway contributor, kagent, Istio and kgateway maintainer, Solo.io
Lin is the Head of Open Source at Solo.io, co-chair of KubeCon + CloudNatibeCon 2026. She actively contributes to AAIF and CNCF projects. She is the author of “Sidecar-less Istio Explained” and “AI Agents in Kubernetes”, and holds more than 200 patents.
Friday September 18, 2026 10:20 - 11:55 CEST
G106 + G107 (Level 1)

10:55 CEST

From "Works on My Prompt" To Production SLOs: Building Agent Observability - Manik Khandelwal, Microsoft
Friday September 18, 2026 10:55 - 11:20 CEST
hen we shipped an AI agent powered by Cosmos DB's MCP server internally at Microsoft, it passed every test we threw at it—until real users found creative ways to break it. The agent would silently degrade: returning plausible-but-wrong query results, calling tools in inefficient loops, or burning through token budgets without completing tasks. Traditional monitoring showed green dashboards while users filed complaints. We needed observability designed for agents.

This talk presents the observability and evaluation stack I built to make agent failures visible, measurable, and catchable before users notice—combining OpenTelemetry instrumentation, LLM-as-judge evaluation, and automated regression gates in CI/CD.
Speakers
avatar for Manik Khandelwal

Manik Khandelwal

Senior Software engineer, Microsoft
Manik Khandelwal is an Engineer at Microsoft and a core maintainer of the Azure Cosmos DB Node.js SDK. He builds tools that make modern apps more scalable and intelligent—using AI, real-time data, and JavaScript.
Friday September 18, 2026 10:55 - 11:20 CEST
Auditorium (Ground Level)

10:55 CEST

From MCP Playground To Org-Wide Infrastructure: Lessons From Building Booking.com's Agent Foundry - Anushka Bhandari, Booking.com
Friday September 18, 2026 10:55 - 11:20 CEST
Most MCP talks stop at the gateway. This one starts there.
The barrier to contributing has never been lower — agents write code, PMs ship tools, designers prototype integrations. But newcomers don't carry the institutional knowledge from a 2am production incident: the performance edge cases, the security gotchas, the failure modes that only show up under real load.
Most MCP projects die between proof of concept and production. The gap isn't technical, it's organizational. Who owns the servers? Who reviews contributions? How does a UX designer, PM, and autonomous agent share the same infrastructure without ten different logins?
Booking.com's Agent Foundry closed that gap. A two-tier MCP gateway with 20+ org-wide servers (Grafana, Honeycomb, Atlassian, Slack, GitLab). One OAuth flow for humans and agents alike. A skills registry with AI-reviewed contributions. Composable profiles that bundle MCPs and skills into workflow-specific harnesses.
Every skill one team contributes compounds value for every team that follows.
We'll share what the architecture got right, what broke, and what a small team can realistically own at this scale.
Speakers
avatar for Anushka Bhandari

Anushka Bhandari

Software Engineer, Booking.com
Anushka Bhandari is a Software Engineer at Booking.com Amsterdam and Founding Engineer of Agent Foundry : the company's org-wide agentic AI platform, built from hackathon to production. Before Booking.com: Databricks, Goldman Sachs, IIIT Delhi. Outside work she skis, cycles, and can't... Read More →
Friday September 18, 2026 10:55 - 11:20 CEST
G102 + G103 (Level 1)

10:55 CEST

Outcome Engineering: Why Your Agentic Architecture Doesn't Matter (Yet) - Kierra Dotson, Further
Friday September 18, 2026 10:55 - 11:20 CEST
The open agentic ecosystem is technically brilliant and strategically incomplete. Engineers across the enterprise are deploying multi-agent systems, integrating MCP, and building sophisticated context infrastructure — and yet the majority of it never reaches production at scale, fails to earn sustained organizational investment, or generates no measurable competitive value. This stems from looking at model and tool selection as the outcome instead of business value produced.

Outcome Engineering is the discipline of designing agentic systems backward from competitive strategy, instead of forward from technical capability. It is the difference between building impressive infrastructure and building systems that are indispensable. It is the difference between an agent that gets demoed and an agent that gets shipped. And it is the difference between an engineer who just builds things and an engineer who changes what a business is capable of.

This session challenges a widely held belief in the engineering community: that deploying the most advanced agentic architecture is the end goal. It is not. The end goal is winning disproportionately because your AI systems are connected to proprietary data, embedded in proprietary workflows, and architected around prioritized business goals and competitive positions that cannot be replicated by any organization running the same off-the-shelf stack.

This session will expose the critical disconnect between how engineers build agentic systems and how those systems actually survive contact with business reality. We will cover how to map technical architecture directly to strategic outcomes — why proprietary data and institutional knowledge are the most defensible moats in the agentic era, and what it actually takes to build systems the business cannot afford to turn off.

Attendees will leave with a clear framework for reverse-engineering their agent architecture from the outcome back to the infrastructure. Ultimately, the engineers who define this era will be the ones who build systems so embedded in how the business wins that replacing them becomes a risk no one is willing to take.

Speakers
KD

Kierra Dotson

Director of AI Strategy and Governance, Further

Friday September 18, 2026 10:55 - 11:20 CEST
G104 + G105 (Level 1)

10:55 CEST

ID-JAG: Solving OAuth Sprawl for Enterprise AI Agents - Joey Orlando, Archestra.AI & Aaron Parecki, Okta
Friday September 18, 2026 10:55 - 11:20 CEST
Enterprise AI agents are moving from demos into production, and auth is becoming a blocker. Demo agents can connect to tools with OAuth, but real enterprise agents may need SaaS services for thousands of employees. Per-user, per-service consent does not scale.

This session explains ID-JAG, the Identity Assertion JWT Authorization Grant pattern behind MCP's Enterprise-Managed Authorization extension. ID-JAG turns an existing SSO login into centrally governed, auditable access to approved MCP servers, without repeated OAuth prompts.

We'll cover the production problem, protocol flow, and lessons from implementing ID-JAG support in Archestra, one of the first MCP clients to support it. We'll also discuss what identity provider support enables.

Attendees will leave with a model for production agent auth: one SSO login, centralized policy, scoped MCP-native access tokens, fewer consent screens, and a cleaner security review story.

We'll close with the missing piece: SaaS provider adoption. To unlock enterprise deployments, authorization servers need to support this flow so agents can access approved business systems without key-sharing, manual credentials, or one-off integrations.
Speakers
avatar for Joey Orlando

Joey Orlando

Co-Founder, Archestra.AI
Co-Founder of Archestra.AI - previous engineer on the Grafana IRM team. Active member of the MCP contributors community, currently involved in the Enterprise and tool annotation working groups.

Prior to software, worked as a biochemist for several years :)
avatar for Aaron Parecki

Aaron Parecki

Director of Identity Standards, Okta
Aaron Parecki is Director of Identity Standards at Okta and active in multiple standards development organizations, including IETF, OpenID Foundation, W3C, and MCP. He is an editor of several other OAuth specifications, and has been influential in shaping how MCP has adopted OAuth... Read More →
Friday September 18, 2026 10:55 - 11:20 CEST
Emerald Room (Level 1)

11:30 CEST

Agents Can Pay. Can They Prove It? - Diego Zuluaga & Saurabh Goyal, Open Mobile Hub
Friday September 18, 2026 11:30 - 11:55 CEST
This is the EUDI Wallet architecture, running inside an agent, 18 months before the Dec-2026 mandate.

Every "agent that verifies you" or "agent that pays" demo skips the hard part: how does an AI agent request a real, government- or bank-grade credential from your device, on any phone, any wallet, Android or iOS, and prove who authorized it?

We'll run the full chain live. An MCP server renders a verifier inside Claude and ChatGPT; the W3C Digital Credentials API requests a credential over OpenID4VP; FIDO caBLE carries it cross-device to your phone; the wallet returns an mdoc or SD-JWT credential held in hardware (StrongBox, TEE, Secure Enclave); an AP2 mandate binds your intent.

Identity is the headline, age, membership, passport, healthcare, with payments as one example. And it's not a stage trick: it's an open-source Digital Credential MCP server, soon to be released and donated, that you can clone, point at your own credential, and ship. Built on open standards, across every platform, with UCP & ACP conformance on the roadmap.

Here are some examples of the demos we're planning to showcase: https://github.com/dzuluaga/mcp-apps-shopping-demo
Speakers
avatar for Diego Zuluaga

Diego Zuluaga

Lead, Open Mobile Hub (Linux Foundation), Open Mobile Hub
Leads agentic commerce on Multipaz (OpenWallet Foundation's mdoc credential library, what Google Wallet runs on) and heads Open Mobile Hub under the Linux Foundation. Represents Futurewei in the Agentic AI Foundation (Agentic Commerce, Identity & Trust working groups), alongside Mastercard... Read More →
avatar for Saurabh Goyal

Saurabh Goyal

Senior Director, Open Mobile Hub, Open Mobile Hub
Saurabh is a Senior Director at OMH with 20 years of experience in the technology industry. In his current role, he is focused on developing the agentic ecosystem and contributing to Open Source Projects.
Prior to his current role, Saurabh worked with Google for 10.5 years, where... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
G104 + G105 (Level 1)

11:30 CEST

I Was the Bottleneck, Not the Agent - Vincent Ysmal, Datadog
Friday September 18, 2026 11:30 - 11:55 CEST
Running 4 to 8 parallel agent coding sessions sounds like a superpower. It nearly broke me.

I was spending more time switching context to check what each agent had done than I would have spent writing the code myself.

Manual testing, staging deployments, code reviews just to understand what the agent had built: I had become the bottleneck.
The agents were fast. I wasn't.

This talk is about how our team redesigned the workflow around one principle: the agent should be able to prove its own work. That means agents that deploy themselves, run their own test suites, watch CI and fix failures, and produce PRs with enough evidence that a reviewer can approve with confidence, without reading every line.
I'll share what it concretely took to get there, and where humans still need to stay in the loop and why.
Speakers
avatar for Vincent Ysmal

Vincent Ysmal

Senior Software Engineer, Datadog
I'm a Senior Software Engineer at Datadog, working on AI-powered developer tooling. Before that, four years leading R&D at IQVIA France, and two decades building platforms at startups across fintech and insurtech. I've been obsessed with developer workflows since long before AI made... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
G102 + G103 (Level 1)

11:30 CEST

Governance You Can Run: Checkable Properties for Production Agents - Seshu Tolety, Siemens
Friday September 18, 2026 11:30 - 11:55 CEST
Most agent governance lives in documents nobody can enforce. The agent ships, the policy sits in a wiki, and no one can answer the question that matters in production: is this running system compliant right now?
This talk presents governance built the other way around, as properties you can check on a live agent system rather than promises on a slide. We decompose any agentic system into a small three-object model, define properties that are individually testable against a running deployment, and rank failure modes into the handful of Tier-1 risks that actually cause incidents. Regulatory mappings (EU AI Act, ISO/IEC 42001, GDPR) fall out as a consequence of satisfying those properties, not as the starting point.
You leave with a vendor-neutral framework you can apply to your own agents the same week, independent of stack or model provider.
Speakers
avatar for Seshu Tolety

Seshu Tolety

Director - Agentic AI, Siemens
Visionary technology leader | 20+ years engineering transformation at global scale.

Architect of high-performing teams, cloud platforms, IoT, and Agentic AI strategies. I turn legacy systems into resilient delivery engines and engineering cultures into innovation powerhouses.

N... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
Auditorium (Ground Level)

11:30 CEST

Economies of Scale for MCP and Agents: Why You Need an Identity Broker - Magnus Jungsbluth & Jan Brennenstuhl, Zalando SE
Friday September 18, 2026 11:30 - 11:55 CEST
Drawing from lessons of how to scale an enterprise to thousands of microservices, we make the case that pushing concerns to the infrastructure for agentic systems should be a no-brainer when planning to scale agentic systems.
This talk explores how Zalando tackled this challenge by building and open-sourcing our own agentic identity broker as part of our broader agentic platform initiative. We will share how it supports delegation chains across third-party and in-house applications, integrates with the CNCF project agentgateway and how it allows us to keep these pesky authentication / authorization concerns on the infrastructure and keep MCP servers and agents simple.
We will dive into the technical mechanics, how it integrates into a larger enterprise and allows us to apply just enough governance to stay ahead of the game. We will cover practical applications and limitations of dynamic client registration.
A closing outlook will illustrate how tool approvals and human-in-the-loop can be enforced centrally without agent authors or MCP authors having to build anything. Practical examples of CIBA and intent-based access will complete the session.
Speakers
avatar for Magnus Jungsbluth

Magnus Jungsbluth

Senior Principal Engineer, Zalando SE
Magnus has been working for over two decades in software engineering with a strong focus on security and cryptography. At Bundesdruckerei he led a platform team for trust center applications. Since joining Zalando he leads initiatives to build more platform capabilities around security... Read More →
avatar for Jan Brennenstuhl

Jan Brennenstuhl

Principal Software Engineer, Zalando SE
Jan Brennenstuhl is a Principal Engineer and product-minded security enthusiast with a proven track record of building identity solutions for millions of users while balancing UX and security in high-stakes revenue funnels. Currently focused on making the agentic SDLC more secure... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
Emerald Room (Level 1)

12:05 CEST

Governed Agent Autonomy: Building a Control Plane for Agentic Systems - Nnenna Ndukwe, Qodo AI
Friday September 18, 2026 12:05 - 12:30 CEST
We see how quickly AI coding tools and agent harnesses are improving. But how can the surrounding system keep that autonomy governable once an agent starts planning, executing tools, changing files, and consuming budget on a team’s behalf?

In this talk, I break down a technical case study based on a real AI coding control-plane architecture and show how serious systems structure autonomy through explicit boundaries: plan gates, permission controls, trust review, independent verification, and runtime observability. I will walk through the patterns and production-grade examples, explain why telemetry and quota tracing are integral to code governance, and show why integrity failures can still happen even with strong coding workflows.

This session gives engineering leaders and practitioners a framework for evaluating AI coding tools. The goal is to achieve agent governance that teams can trust, audit, and scale.
Speakers
avatar for Nnenna Ndukwe

Nnenna Ndukwe

AI Developer Relations Engineering Lead, Qodo AI
Nnenna Ndukwe is a Developer Relations Engineering Lead and Software Engineer, passionate about AI. With 9+ years in industry, she's a global AI community architect championing engineers to build in emerging tech. She studied Computer Science at Boston University and is a proud member... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
G102 + G103 (Level 1)

12:05 CEST

When Agents Run Healthcare: Building Reliable Agentic Systems in Highly Regulated Environments - Janosch Woschitz, BARMER
Friday September 18, 2026 12:05 - 12:30 CEST
The public statutory health insurance system in Germany faces a dual challenge: demographic change is creating a shortage of skilled professionals while operational pressure continues to rise due to an aging population. Healthcare organisations must therefore automate high-volume processes without compromising reliability, governance, or trust.

This session presents BARMER’s journey from governed data and analytics platforms to production-oriented agentic systems supporting real operational workflows. Rather than focusing on isolated chatbots or copilots, it explores how agentic systems can be embedded into core enterprise processes in highly regulated environments.

The talk highlights key design patterns including workflow orchestration, agent runtime separation, observability, and human-in-the-loop escalation. It also demonstrates why many early agent architectures fail under regulatory constraints and what changes are required to meet enterprise standards for compliance, auditability, and resilience.
Speakers
avatar for Janosch Woschitz

Janosch Woschitz

Senior AI Architect, BARMER
Janosch Woschitz is a Senior AI Architect at BARMER’s AI innovation unit, BARMER KI, where he builds scalable AI/ML platforms and production-grade agentic systems for healthcare. With a background in software engineering, distributed systems, and enterprise AI architecture, he has... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
Auditorium (Ground Level)

12:05 CEST

Testing Agents and Their Tools: Offline Evaluation, Synthetic Tasks, and A/B Experiments - Ksenia Bobrova, GitHub
Friday September 18, 2026 12:05 - 12:30 CEST
A three-layer evaluation strategy for AI agents and their tools, from experience operating across multiple LLM providers and runtimes.

Offline evaluation: designing benchmark suites with curated requests, expected tool selections, and arguments. Computing precision, recall, F1 scores, confusion matrices for tool mix-ups, and argument hallucination rates to pinpoint description problems.

End-to-end benchmarks: multi-tool flows where the agent chains several calls to complete a task, catching integration regressions that single-tool evaluation misses.

Production A/B experiments: a case study of tool search experiments across OpenAI and Anthropic through staged rollouts. Challenges we hit: caching bugs under real traffic, tool discovery failures, and data skew making early results inconclusive. How we decided whether to advance, pause, or roll back.

These layers compensate for each other's blind spots, forming a testing pyramid that enabled us to safely ship changes to MCP and agent across model providers. Attendees leave with a reusable playbook for testing MCP servers, agents, and running A/B experiments.
Speakers
avatar for Ksenia Bobrova

Ksenia Bobrova

Senior Software Engineer, GitHub
I'm currently focusing on building AI agents and tooling around it.
Friday September 18, 2026 12:05 - 12:30 CEST
G104 + G105 (Level 1)

12:05 CEST

MCP Apps and the Nearly Headless Web - Liad Yosef, MCP Apps
Friday September 18, 2026 12:05 - 12:30 CEST
MCP Apps are the last piece in moving toward a new web - one that's "nearly" headless. Autonomous agents, not humans, will interact with most websites through MCP, APIs, and other data channels. Websites and browsers become obsolete, replaced by personal assistants that orchestrate tasks on our behalf. In rare cases, agents will fall back to browser capabilities to navigate sites that aren't yet agent-ready.
But we'll still need the last mile.
Some moments still require human eyes and human input: choosing a seat at a venue, completing a check-in, reviewing a 3D model, verifying intent on important decisions. This is where MCP Apps come in - letting tools, websites, and services send composable, interactive chunks of UI directly to agents, exactly when needed, maintaining brand and identity.
We'll explore the full cycle of this nearly headless web: the infrastructure required to support autonomy and trust, the new UI layer, and how assistants are becoming the new browsers.
MCP Apps redefine the web's interface. Headless, but with a human eye at the end.
Speakers
avatar for Liad	Yosef

Liad Yosef

Co-creator, MCP Apps
Liad Yosef is the co-author and maintainer of MCP Apps on the MCP Steering Committee. He is the co-builder of MCP-UI, and previously AI Lead in Shopify's CEO office. Liad is currently a co-founder and CTO, building the future of agentic interfaces at Ora. Liad is a web enthusiast... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
Emerald Room (Level 1)

12:05 CEST

Workshop: Harness Engineering: Building the System Around Your AI Coding Agent - Ji Darwish, Lunatech
Friday September 18, 2026 12:05 - 13:40 CEST
AI coding agents feel like magic. It is easy to assume there is something exotic inside, some secret sauce that makes agents reliable. Well, there isn't, the core of every AI coding agent is dead simple: send a message to a model, parse tool calls, execute them, feed the results back, repeat. Everything else (context management, permissions, observability, safety guardrails) is engineering layered on top of it that we should be building.

In this deep dive, we build that engine from scratch (in Java!), live on stage. Not to build the best agent, but to understand how the pieces fit together. We point it at a real codebase, and watch what happens. It compiles. Tests pass. And it violates every convention the team agreed on. So we iterate. We add context, constraints, and feedback, and at each step we examine what changed, why it helped, and what it maps to in the tools you already use.

The goal is a mental model. By the end, you will understand the components inside the AI coding tools you use every day, what you can layer on top to get smoother results and safer expectations, and where the honest limits still are, the gap no amount of engineering has closed yet.
Speakers
avatar for Ji Darwish

Ji Darwish

Software Engineer, Lunatech
Ji is a Software Engineer at Lunatech with a background in Computer Science & Engineering from TU Delft and a recently completed MSc in Artificial Intelligence from Utrecht University. With years of experience in software development, he focuses on solving real-world software and... Read More →
Friday September 18, 2026 12:05 - 13:40 CEST
G106 + G107 (Level 1)

12:40 CEST

Stateless Agents, Stateful Worlds: Designing for Interruption - Arul Kumaran, Luracast / Portel
Friday September 18, 2026 12:40 - 13:05 CEST
Anthropic just announced MCP is going stateless. Most agent frameworks assume long-running, uninterrupted sessions. Real deployments face forced interruptions every hour: rate limits, auth refreshes, network partitions, process restarts, the laptop lid closing. When a session dies mid-task, most agents start over. That is not a model problem. It is a runtime design problem.

This talk covers the patterns that make agents resumable: idempotent tool calls that can safely re-execute, checkpoint-first execution that captures decisions before side effects, explicit continuation tokens that let a new session pick up an interrupted task, and the specific primitives a TypeScript runtime on Cloudflare Workers exposes to make all of this cheap. Every pattern shown is running in production on Photon, an open-source agentic tool runtime deployed to edge infrastructure.

Attendees leave with a concrete checklist: five changes to their agent architecture that make it survive the real world, not just the happy path.
Speakers
avatar for Arul Kumaran

Arul Kumaran

Founder, Luracast / Portel
Arul Kumaran builds developer infrastructure for the agentic era. He created Photon, a runtime that compiles TypeScript into CLI, web app, and MCP-compatible agent tools simultaneously, and NCP (Natural Context Provider), a meta-MCP unifying 50+ tools behind 2-3 interfaces - cutting... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
Auditorium (Ground Level)

12:40 CEST

Beyond Vibe-Testing: Engineering Deterministic Agent Skills - Shuva Jyoti Kar, Palo Alto Networks
Friday September 18, 2026 12:40 - 13:05 CEST
The AI ecosystem suffers from a critical engineering immaturity: deploying stochastic models via manual "vibe checks." Operating autonomous agents at enterprise scale requires abandoning ad-hoc observation for strict, distributed systems rigor. This session introduces a deterministic, CI/CD-native evaluation architecture for Agent Skills, shifting from indeterministic to reliable software execution.

By adhering to the formalized capability standards defined by agentskills.io, we will deconstruct the transition from subjective testing to hermetic, code-driven audits. Attendees will learn to engineer scenario matrices that enforce strict cognitive boundaries via negative testing—guaranteeing agents safely reject out-of-scope triggers. We will demonstrate isolating execution within sandboxed environments to capture pristine telemetry: deterministic tool-call structures, system exit codes, and exact token utilization.

Crucially, we address the anti-pattern of relying on "LLM-as-a-judge" for critical path assertions. Instead, we architect a framework grading system invariants via AST parsing and JSON Schema enforcement to achieve instantaneous, hallucination-immune evaluation.
Speakers
avatar for SHUVA JYOTI KAR

SHUVA JYOTI KAR

Principal Engineer, Palo Alto Networks
Shuva is a Principal Engineer at Palo Alto Networks building secure enterprise AI platforms. An author of two upcoming books: Engineering the Data Agent Control Plane (O'Reilly) and Agent Skills in Action (Manning), an open-source contributor and former OpenDaylight committer, his... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
G104 + G105 (Level 1)

12:40 CEST

From API Catalogs To Agent Catalogs: Solving MCP Server Discovery With Open Resource Discovery - Vyshnavi Gadamsetti & Sebastian Wennemers, SAP SE
Friday September 18, 2026 12:40 - 13:05 CEST
As MCP servers multiply, the ecosystem is hitting the fragmentation problem APIs hit a decade ago: every server is a point-to-point integration with no shared way to discover or describe it. Live introspection over a connected session does not scale to the catalogs, registries, and gateways that need to reason about thousands of servers without starting each one up. Open Resource Discovery (ORD) solved this for APIs, events, and data products. Each resource publishes a static, machine-readable description at a well-known endpoint. Aggregators crawl those descriptions and build catalogs that registries and gateways can query without connecting to the resource. Recent ORD work applies the same shape to agents and the MCP servers they depend on, scoping the dependency to the tools and prompts an agent uses. The same pattern fits MCP. The talk walks through a Server Card design that serves tools, prompts, and resources alongside metadata from a well-known endpoint, so registries and gateways can reason about a server before any agent connects. The design has been contributed into the open MCP community via SEP-2127, with a public renderer and playground demonstrating it end-to-end.
Speakers
avatar for Vyshnavi Gadamsetti

Vyshnavi Gadamsetti

Software Development Architect, SAP SE
Vyshnavi Gadamsetti is a software architect at SAP, where she has worked for 14 years across enterprise software. Earlier in her career, she worked at PwC. Her current work spans MCP (Model Context Protocol), ORD (Open Resource Discovery), agent extensibility and governance, and the... Read More →
avatar for Sebastian Wennemers

Sebastian Wennemers

Chief Architect, SAP SE
Sebastian Wennemers has 15+ years of experience in building and architecting solutions that need a solid metadata foundation. He is currently driving SAPs metadata story that grounds the AI strategy.
Friday September 18, 2026 12:40 - 13:05 CEST
Emerald Room (Level 1)

12:40 CEST

Agents Talking To Agents: MCP, A2A, and the Reality of Multi-Agent Orchestration in Production - Willem Berroubache, Orange
Friday September 18, 2026 12:40 - 13:05 CEST
Building a multi-agent system in a notebook is straightforward
Running one on production infrastructure, where a wrong handoff triggers a real incident, is a different problem entirely.

This talk shares hard-won lessons from deploying autonomous agents using both MCP and A2A protocols in a large-scale, regulated environment.
We move past the happy path and focus on what actually breaks: agents that lose task context mid-chain, trust boundaries that collapse during agent-to-agent delegation, tool conflicts between concurrent agents, and orchestration failures that only surface under real load.
We walk through three patterns that emerged from this work. How to split responsibilities between MCP and A2A so each protocol does what it is actually good at. How to scope agent authority using MCP server boundaries without creating coordination bottlenecks. And how to design agent-to-agent handoffs that degrade gracefully when part of the chain fails mid-task.

No toy examples. No vendor pitches. Concrete decisions, the tradeoffs behind them, and what we would change today. Attendees leave with patterns they can apply the next day, regardless of their agent framework.
Speakers
avatar for Willem Berroubache

Willem Berroubache

AI for Security Project Manager, Orange
I work as Stream manager for 5G Core security monitoring & APIs at Orange.
Before that, I have managed innovative 5G projects involving Edge Computing and k8s in collaboration with Google.
I have conducted studies and PoCs on Edge Computing, automated and deployed 5G NF, and pro... Read More →
Friday September 18, 2026 12:40 - 13:05 CEST
G102 + G103 (Level 1)

13:15 CEST

Agent-Smith: Never Send a Human To Do a Machine’s Job - Glenn ten Cate, The Linux Foundation & Jorge Carvalho, Nedap
Friday September 18, 2026 13:15 - 13:40 CEST
Most AI security agents are wrappers around fixed scripts. Agent-Smith takes a different approach: reusable skills encode security methodology, while the model determines how to investigate, chain tools, validate findings, and select its next action.

This session presents the architecture and lessons behind Agent-Smith, an open-source, MCP-enabled autonomous penetration-testing agent spanning web, cloud, Active Directory, source-code review, threat modeling, and AI red teaming and more. We will examine MCP tool exposure, methodology-as-code, autonomous skill chaining, model portability, ephemeral Docker sandboxes, and server-side controls for cost, execution time, and tool calls.

A practical demonstration will show Agent-Smith progressing from reconnaissance to a verified finding, reproducible proof of concept, remediation guidance, and code patch. Attendees will leave with concrete patterns for building capable agents without sacrificing isolation, observability, human oversight, or control.

“Never send a human to do a machine’s job.”
Speakers
avatar for Glenn ten Cate

Glenn ten Cate

Senior Cybersecurity trainer, The Linux Foundation
Glenn Ten Cate is a cybersecurity expert and trainer at the Linux Foundation with more than 20 years of experience as an ethical hacker, educator, and offensive security practitioner. He previously co-created and led the Security Knowledge Framework, an open-source flagship project... Read More →
avatar for Jorge Carvalho

Jorge Carvalho

Application Security Engineer, Nedap
Jorge Carvalho is an Application Security Engineer at Nedap with a passion for building secure software and exploring the security implications of emerging technologies. Much of his expertise has been developed through self-directed learning, hands-on research, and practical experience... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
Auditorium (Ground Level)

13:15 CEST

From Vibes To Data: Evaluating Agents on Your Real Work - Ville Hellman, Datadog
Friday September 18, 2026 13:15 - 13:40 CEST
Frontier labs are spending billions making agents better at SWE-Bench. But how much of your engineering work actually looks like SWE-Bench? At Datadog we kept seeing agents that crushed public benchmarks fail on our codebase: missing our conventions, reaching for the wrong internal libraries, technically correct but doing the work the wrong way.

To get past demos and gut feel, we built an evaluation platform that measures agents on tasks drawn from our real work, and gave our platform teams a way to encode best practices as evals. Teams shipping skills, steering docs, agent harnesses, and MCP servers can now see whether their changes actually moved the needle.

In this talk I'll share how SOTA and open-weight models actually compare on real work, what their cost-performance profiles look like, tooling decisions that can shift token usage by 10% or more, and how a surprisingly small eval suite can produce stable signal.

You'll leave with a clearer way to think about model choice as a tradeoff between performance you actually need and tokens you're willing to spend, and a sharper sense of what makes an eval keep paying off over time instead of becoming a one-off exercise.
Speakers
avatar for Ville Hellman

Ville Hellman

Staff Engineer, Datadog
Ville is a Staff Engineer in Datadog's AI DevX group, where he builds evaluation infrastructure for the agents and tooling Datadog engineers use every day. He writes on AI-augmented engineering, AI literacy, and developer experience to make what's coming next easier for others to... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
G104 + G105 (Level 1)

13:15 CEST

Beyond Chatbots: Agentic UI With Open Standards - Manfred Steyer, ANGULARarchitects
Friday September 18, 2026 13:15 - 13:40 CEST
Integrating agentic AI into the UI easily leads to ad hoc integrations, tight coupling to backend technologies, and vendor lock-in. So how do we design scalable, maintainable interactions between agents and users?

This session shows how open standards like AG-UI, A2UI, and MCP Apps enable a protocol-driven approach to Agentic UI, establishing clear, message-based boundaries that decouple UI, agent logic, and tools. You’ll learn how to apply these standards, leveraging dynamic UI generation, tool integration, and Human-in-the-Loop patterns.

By the end, you’ll understand how to design Agentic UI using open standards and integrate them through clear, protocol-based boundaries.
Speakers
avatar for Manfred Steyer

Manfred Steyer

Trainer and Consultant, ANGULARarchitects
Trainer and Consultant with a focus on Agentic UI and Angular. Google Developer Expert (GDE) for Angular and Trusted Collaborator in the Angular team. Writes for O'Reilly, Hanser, and the German Java Magazine. Regularly speaks at conferences.
Friday September 18, 2026 13:15 - 13:40 CEST
G102 + G103 (Level 1)

13:15 CEST

Spotify’s Bet on MCP and Investment in Open Source - Oliver Soell & Yannick Epstein, Spotify
Friday September 18, 2026 13:15 - 13:40 CEST
Spotify’s workforce went from zero to near universal use of MCP servers in breakneck time. It was only possible due to the MCP gateway - custom code written in a weekend to support the urgent need to expose Spotify’s extensive internal API ecosystem to AI agents.

The MCP gateway rapidly became a victim of its own success; multiple teams were committing significant changes to the codebase, and domain ownership and on-call support for the gateway were somewhat uncertain. From a sustainability perspective, the MCP gateway was becoming a big risk.

In this talk you’ll learn how Spotify successfully rebased its highly custom MCP gateway use case onto OSS technologies, while retaining deep integration into Spotify’s infrastructure management plane, service discovery, and microservice ecosystem. Hear how kgateway, the Envoy proxy, kro, and the Gateway API were used to build the new MCP gateway, enabling it to be better sustained by the right teams contributing their specific expertise.
Speakers
avatar for Oliver Soell

Oliver Soell

Software Engineer, Spotify
Infrastructure at Spotify
avatar for Yannick Epstein

Yannick Epstein

Senior Software Engineer, Spotify
Yannick Epstein is a Senior Engineer in Spotify’s Core Infrastructure group, where he works on systems that manage traffic and communication between backend services. He led the discovery and engineering effort for Spotify’s custom xDS control plane and the company’s dynamic... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
Emerald Room (Level 1)

13:40 CEST

14:50 CEST

Welcome Back - Angie Jones, Vice President of Developer Experience, The Agentic AI Foundation
Friday September 18, 2026 14:50 - 14:50 CEST

Speakers
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
Friday September 18, 2026 14:50 - 14:50 CEST
Auditorium (Ground Level)

14:50 CEST

Keynote: Marlene Mhangami, Senior Developer Advocate, Microsoft
Friday September 18, 2026 14:50 - 15:10 CEST

Speakers
avatar for Marlene Mhangami

Marlene Mhangami

Senior Developer Advocate, Microsoft

Friday September 18, 2026 14:50 - 15:10 CEST
Auditorium (Ground Level)

15:10 CEST

Keynote: Why Organizations Need an AI Control Plane for Security and Governance - Sheng Liang, Co-Founder & CEO, Obot AI
Friday September 18, 2026 15:10 - 15:20 CEST
How can organizations secure and govern AI agents they do not fully trust? MCP gateways can intercept and filter tool calls, but that alone is not enough. Organizations also need complete visibility into agent activity, consistent policy enforcement, and centralized control. In this talk, we explain how to move beyond MCP gateways and build an AI control plane for enterprise-wide security and governance.
Speakers
avatar for Sheng Liang

Sheng Liang

CEO, Obot AI
Sheng Liang is cofounder and CEO of Obot.ai. Previously, Sheng founded and served as CEO of successful open source software companies, including Rancher Labs and Cloud.com, and served in executive roles at SUSE and Citrix. He started as an engineer at Sun Microsystems, where... Read More →
Friday September 18, 2026 15:10 - 15:20 CEST
Auditorium (Ground Level)

15:25 CEST

Keynote: MCP Made Local Models Viable - Rachel-Lee Nabors, Developer Experience, Arize
Friday September 18, 2026 15:25 - 15:35 CEST
By building agentic workflows that brick the moment they lose connectivity, we've circled back to the 1980s: the dumb terminal, the mainframe in someone else's building, intelligence rented by the minute. The first capable models were enormous, so we metered them by the token and shipped our context off-device. Tool bloat forced us to engineer economical harnesses: 50 tools can burn ~70k tokens, and selection quality collapses past a few dozen options. So we built progressive tool discovery, the wrapper pattern, retrieval, and routers that load only the tools a task needs. We engineered the problem down to something consumable by SAGE (Small And Good-Enough) models. On-device, free, private, these smaller models are increasingly capable of running agentic workflows and calling tools.

This talk covers the progress SLMs are making, efforts like DS4, and MCP client and server patterns built for the rise of local model adoption.
Speakers
avatar for Rachel-Lee Nabors

Rachel-Lee Nabors

Developer Experience, Arize
Rachel-Lee Nabors spent the better part of their career on web standards and opensource and has spearheaded developer education at FAANG and startups, on the React Team as well as W3C. Now they work to usher in the Agentic Web with companies like Arcade.dev
Friday September 18, 2026 15:25 - 15:35 CEST
Auditorium (Ground Level)

15:45 CEST

Giving Your Agentic Coding AI a Security Brain - Liran Tal, Snyk
Friday September 18, 2026 15:45 - 16:10 CEST
AI can generate a week’s worth of code before lunch and just as quickly ship SSRF, RCE, and path traversal vulnerabilities into prod. Rules and “/security-review” prompts aren’t enough: they’re costly, brittle, and non-deterministic. Run them three times, get three answers. Meanwhile, who vets hallucinated npm packages as the agent installs them? Oh you’re running the agent with “--dangerously-skip-permissions”? Color me surprised, sigh.

Well the good news is you don’t have to trade speed for security, let me show you how. This talk shows a concrete, developer-first pattern: learn how to use MCPs & Hooks to give agents real security superpowers. We’ll wire in just-in-time package health checks and deterministic code reviews via pluggable AI components, with clear contextually engineered details for your agent. You’ll leave with a better understanding of the security dangers relying on agentic coding tools alone and a reliable and deterministic agentic workflow to make AI coding fast and safely shippable.
Speakers
avatar for Liran Tal

Liran Tal

Director of Developer Relations, Snyk
Liran Tal is an AI Security researcher, a seasoned Node.js developer, and a secure coding expert focused on hardening agentic workflows and the Model Context Protocol (MCP). He discovers and discloses CVEs in MCP servers and AI frameworks, and publishes research on tool poisoning... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
G104 + G105 (Level 1)

15:45 CEST

How We Reclaimed 20% of Engineering Capacity at Salesforce With AI Agents - Axel Uhlig, Salesforce
Friday September 18, 2026 15:45 - 16:10 CEST
We built and deployed an AI Agent at Salesforce designed to triage production alerts using service logs. After months of iteration, we achieved an accuracy level that earned the trust of our DevOps personnel. Today, the agent reclaims approximately 20% of weekly engineering capacity for the teams using it.

Here are our top 5 takeaways for building agents that perform consistently at high accuracy:
1. Specialization beats generalization: For high-accuracy tasks, purpose-built solutions outperform generic models every time.
2. Provide "Proof of Work": Make it effortless for humans to verify the agent's logic. Transparency builds trust.
3. Minimize friction: We used Slack as the primary interface. Don't require local setups to boost adoption and usage
4. Build in public: Operating in shared channels allows for seamless human-agent cooperation (and agent-to-agent orchestration).
5. Hosted > Local: Local scripts are great for individuals, but standardized, team-wide automation requires a hosted environment to scale.
Speakers
avatar for Axel Uhlig

Axel Uhlig

Software Engineer, Salesforce
Software Engineer, mostly working on CI/CD systems using Bazel for C++ code bases.

Previously worked on the Bazel migration of BMW.

Currently working for Salesforce, supporting the Hyper Database team to ship their database as part of Tableau and other Salesforce products... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
Auditorium (Ground Level)

15:45 CEST

Attribution by Design: Skills, MCP, and Where Provenance Gets Built In - Ola Hungerford, Model Context Protocol
Friday September 18, 2026 15:45 - 16:10 CEST
Agents increasingly draw on specialized human knowledge at inference time, and the infrastructure delivering it is converging around Skills, MCP, and very often a mix of the two. That makes these standards a decision point: provenance either travels with the knowledge or its absence becomes the default.

The MCP community is standardizing two complementary efforts: Interceptors (deterministic hooks in clients, servers, and gateways) and how, why, and when to serve Skills over MCP. This talk shows how the two fit together to standardize attribution for human expertise and other content encoded as Skills and related inference-time formats.

The talk showcases two examples:
- An attribution gateway that validates and records authorship in a centralized control plane
- A standardized client-side hook to log and credit authors when Skills are invoked
Speakers
avatar for Ola Hungerford

Ola Hungerford

Maintainer, Model Context Protocol
Ola Hungerford is a Principal Engineer at Nordstrom and a maintainer and community moderator for the Model Context Protocol. She leads AI enablement initiatives while contributing to MCP's specification, developer tooling, documentation, and community governance. Ola comes from a... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
Emerald Room (Level 1)

15:45 CEST

The Serving Layer Is the Agent's Bottleneck - Swapnil Tiwari, AWS
Friday September 18, 2026 15:45 - 16:10 CEST
I've spent the past year tuning open-source inference stacks (vLLM, SGLang) for production agent systems. The same failure modes keep appearing, and they all live in the serving layer.

Biggest one: KV cache thrashing. Agents rebuild thousands of tokens of system prompt + tool schemas every turn. Prefix-aware caching fixes this in six lines of config. I've measured 55-65% latency reduction on turn 2+ across twelve deployments. Almost nobody enables it.

Second: batch-of-one paralysis during tool-calling loops. Each LLM call is a single request, GPU 80%+ idle. Disaggregated prefill/decode with continuous batching unlocks 3-5x throughput. Requires ~40 lines of change in most agent frameworks.

Third: agent latency is bimodal (short tool-selection turns vs long reasoning turns). A single timeout threshold wastes GPUs or kills valid turns. Two-tier serving handles both.

Open configs. Real numbers from workloads I instrumented. If you're building agents and haven't looked below the orchestrator, this fills the gap.
Speakers
avatar for Swapnil Tiwari

Swapnil Tiwari

GenAI Solutions Architect, AWS
GenAI Solutions Architect specializing in LLM inference optimization for agentic workloads. Helped 50+ teams redesign serving infrastructure, with documented 5-10x cost reductions. Built inferenceengineering.tech (open-source, 2K+ users). Conduct security assessments on MCP deployments... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
G102 + G103 (Level 1)

15:45 CEST

Workshop: Governing AI Agent Actions: MCP and Beyond - Shannon Williams & Chris Urwin, Obot AI
Friday September 18, 2026 15:45 - 17:20 CEST
Enterprise adoption of the Model Context Protocol is accelerating, and MCP has become the primary way agents connect to enterprise tools and data. But MCP is only part of how agents act. Agents also run CLIs, execute Skills, and generate code that calls APIs directly. Governing MCP well matters. Governing everything else agents can do matters just as much.
Building MCP servers and writing Skills isn't particularly hard. The real challenges are deciding which actions agents are allowed to take, controlling who can take them, and proving it all later. These are architectural questions, and they need answers before agents scale across an organization.

In this workshop, we will:
1.⁠ ⁠Show how to control agent actions with policies that apply across MCP servers, CLIs, Skills, and agent-generated code — including allowlists, access control by users and groups, and human-in-the-loop approvals.
2.⁠ ⁠Explain why enterprises need managed registries for MCP servers and Skills, and how admin review and approval change the trust model.
3.⁠ ⁠Work through audit and compliance requirements: capturing complete logs of agent and tool activity, exporting to enterprise storage, and generating reports.
4.⁠ ⁠Demonstrate how to discover shadow AI — unmanaged agents, MCPs, and Skills already running in your organization — and how to block them or bring them under management.
5.⁠ ⁠Look at token usage and spend visibility by agent, user, and group.
You'll leave with a clear picture of the architectural decisions ahead of you, and a better sense of what your security team will require before signing off on scaling AI agents across your organization.

Speakers
avatar for Shannon Williams

Shannon Williams

President, Obot AI
I am the President and co-founder of Obot AI, and have been building open source software for the last 20 years. Prior to starting Obot, I co-founded Cloud.com (creator of CloudStack) and Rancher Labs (creator of Rancher, k3s, Longhorn, etc). I was a board member of the CNCF for 4... Read More →
avatar for Chris Urwin

Chris Urwin

VP of Field Engineering, Obot AI
Chris Urwin is VP of Field Engineering at Obot AI and a veteran engineering leader. With deep hands-on experience in cloud‑native platforms, Kubernetes, containers, CI/CD, and developer tooling, he builds and scales global technical teams. Chris bridges product, engineering, and... Read More →
Friday September 18, 2026 15:45 - 17:20 CEST
G106 + G107 (Level 1)

16:20 CEST

Autonomous Organisations: Starting Small - Floris Fok, Prosus
Friday September 18, 2026 16:20 - 16:45 CEST
What does it take to let AI agents run a real business? Before handing over an entire restaurant, our team started with something much smaller: a network of vending machines.

In this session, we'll share what we've learned by giving AI agents responsibility for real world operational decisions, including pricing, inventory management, and marketing. The vending machine serves as a practical testbed for exploring how autonomous organizations behave under real customer demand, where mistakes have real consequences but the risks remain manageable.

We'll discuss how this work evolved from simulated restaurant environments into live deployments, what worked, what failed, and why small scale experiments are the fastest path toward larger autonomous operations. We'll also look ahead to the next phase, including autonomous restaurants and the role robotics may play.

Attendees will leave with a practical framework for experimenting with autonomous organizations, along with lessons learned from taking AI agents out of the lab and into the real world.
Speakers
avatar for Floris Fok

Floris Fok

Staff AI Engineer, Prosus
Big hacker leading JetSki at Prosus here. JetSkis are smaller, more disruptive initiatives. Heavy AI/NLP backgrounds. Have coauthored Climate GPT: a Foundational Model. Have an engineering background and started with training LLMs the moment they were released many years ago.
Friday September 18, 2026 16:20 - 16:45 CEST
G104 + G105 (Level 1)

16:20 CEST

Gating High-Risk Agentic Actions at the Relying Party With Exogenous (Out-of-Band) Inputs - Dominic Forrest, iProov
Friday September 18, 2026 16:20 - 16:45 CEST
A Confused Deputy arises when a trusted system with legitimate authority is induced to use that authority for a high-risk or irreversible action that the Agent's principal did not intend, creating a relying-party (RP) risk of repudiation. The Agent may arrive with valid Tokens, passkeys, inherited session, or tool credentials, even if instructions have been shaped by prompt injection or model miscomprehension. Whilst the request is authenticated, human consent to the means taken is not.

This session develops how RPs can deploy a gatekeeper to distinguish authorised access from authorised actions and produce a legally auditable record. When proving the principal is present and consenting, it assumes that any signal produced by the agent or its device remains endogenous to the compromised context. This requires an exogenous proof that the agent cannot generate, evaluated by the RP before execution.

The talk presents a decentralised, open-source, relying-party pattern that does not require the agent or its operator to have onboarded to or used the scheme. It composes with OAuth, MCP, and passkeys, adding the missing intent boundary for agent-mediated workflows.
Speakers
avatar for Dominic Forrest

Dominic Forrest

Chief Technology Officer, iProov
Dominic is responsible for iProov’s technology vision, strategy, and roadmap including the design and development of its cloud-based infrastructure.

Dominic has over 25 years of experience in senior roles in telecommunications and internet service providers. He joined iProov from mBlox Inc., where as Senior Vice President he oversaw the development and scalability of the platform seamlessly running over 6 billion transitions... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
Auditorium (Ground Level)

16:20 CEST

Infrastructure Red Teaming With Abliterated Models: What Actually Stops Agent Attacks - Roy Belio, Red Hat
Friday September 18, 2026 16:20 - 16:45 CEST
Safety-aligned models refuse adversarial prompts, so you can't test whether your infrastructure controls actually work, but the models are all still susceptible to jail-breaking.
I removed that variable with an abliterated Qwen3.5 model to get zero refusals and 100% cooperation. Ran full suite of prompts with custom garak probes across three hardening tiers on an OpenClaw agent running in OpenShift.

I found out what worked and what gave false sense of security.
Sandbox isolation dropped credential exfiltration entirely in one step. NetworkPolicy killed cluster escalation. The prompt injection classifier caught encoding-based attacks. Three of four attack categories were fully stopped by Tier 2 (injection classification+isolation).

Memory poisoning was the exception. Probes that instruct the agent to write attacker content into its own memory continued to succeed across all tiers. OWASP added this as ASI06 to its 2026 Agentic Top 10. No deployed control addresses it today.

I'll present the full probe results, the defense configurations, and the open problem current agent architectures don't solve.
Speakers
avatar for Roy Belio

Roy Belio

Senior Software Engineer, Red Hat
Roy Belio is an AI Engineer at Red Hat, where he builds and evaluates proof-of-concept projects, drives open source contributions, and deploys AI/ML infrastructure on OpenShift.
Before Red Hat, Roy spent five years at Microsoft, Infinidat and Checkpoint.
He holds a BSc in Inform... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
G102 + G103 (Level 1)

16:20 CEST

Observability Meets MCP: Patterns, Gaps, and Standards - Matthias Loibl, Polar Signals
Friday September 18, 2026 16:20 - 16:45 CEST
Almost every observability project and vendor has shipped an MCP server in the past year.
Prometheus, Jaeger, and OpenTelemetry sit next to Grafana, Datadog, Honeycomb, Polar Signals, and a long list of others. This talk puts a few dozen of them side by side: how they handle transport, auth, tool design, and read/write access, and which ones do something genuinely interesting.

The data is what makes observability hard. Time series, distributed traces, and profiles are dense, high-cardinality, and deeply nested, and wrapping a JSON API in a few tools doesn't make any of that easier for an LLM to read. We'll look at how different servers represent these
signals, and what makes one format easy for a model to reason over while another just fills up the context window. We won't be proposing a new standard. The goal is to surface the best implementation patterns the industry has already converged on, so the audience can judge which observability MCP server to adopt (or build a better one themselves).
Speakers
avatar for Matthias Loibl

Matthias Loibl

Director of Cloud, Polar Signals
Matthias Loibl is the Director of Cloud at Polar Signbals. He works on cloud-native observability. He was previously at Red Hat and Kubermatic and maintains many projects, such as Prometheus, Thanos, Prometheus Operator, and Parca. He enjoys working on Distributed Systems with Go... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
Emerald Room (Level 1)

16:55 CEST

No Central Brain - Fausto Albers, WonderWhy
Friday September 18, 2026 16:55 - 17:20 CEST
Who decides what an agent treats as true? Nothing does, and that is the point. In every system that stays reliable, from a cell to an immune system to a market, correctness isn't assigned by a designer; it's selected. The parts hold competing variants, and an external pressure culls the wrong ones. A more capable part doesn't escape this. It just gets better at exploiting whatever pressure you actually applied.

You can't make the pressure random the way nature does, but you can design it: the goal, the loss, the verifier, the loop the agent runs inside. So stop dictating answers and start shaping the environment that selects them.

We introduce five design laws, each learned by building real-world agents and memory systems that had to stay honest under a pressure they couldn't game.
Speakers
avatar for Fausto Albers

Fausto Albers

Founder, WonderWhy & GenAI R&D Lead, HvA Industrial Digital Twins Lab, AI Builders Club, WonderWhy
Fausto Albers works at the intersection of human behavior and production AI systems. He started in sociology and behavioral science, co-founded AI Builders Club, founded WonderWhy, and now leads GenAI R&D at the HvA Industrial Digital Twins Lab. His work focuses on agents that keep... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
G102 + G103 (Level 1)

16:55 CEST

Shipping a Production App in 10 Days: A Real Measurement of AI-Assisted Development - Julien Dubois, GitHub
Friday September 18, 2026 16:55 - 17:20 CEST
We've all seen the AI coding demos. But what does it really cost to ship a production application with an AI agent, and how much time does it actually save?

This talk answers that with hard numbers from a real, open-source project: BootUI ( https://github.com/jdubois/boot-ui ), a multi-module Java project with roughly 40 deeply-integrated feature panels, an embedded Vue 3 console, ~83,000 lines of code, ~116 test suites, and a full release pipeline. It was built through a tagged 1.0.0 release in about 10 calendar days by a single developer driving the GitHub Copilot coding agent, at a sustained pace of ~20 merged pull requests per day.

Using git history, PR metadata, and code metrics, we reconstruct two timelines: what the project actually took with AI (~80-110 hours of human effort), and a grounded estimate of what the same scope would take a senior developer by hand (~6.5-8.5 months).

You'll leave with a realistic mental model of where AI coding delivers 10x-plus leverage on Java projects, where it doesn't, and the practices that let you safely accept high agent throughput.
Speakers
avatar for Julien Dubois

Julien Dubois

Principal Manager, Developer Relations, GitHub
Julien Dubois is a Java Champion and Principal Manager at Microsoft, where he leads the Java Developer Relations team inside the CoreAI and GitHub organizations. With his team of world-class developer advocates, Julien works directly with the engineering groups to improve how Java... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
Auditorium (Ground Level)

16:55 CEST

MCP Challenges & Opportunities - Sam Morrow, GitHub; Angie Jones, Agentic AI Foundation; Shaun Smith, Hugging Face
Friday September 18, 2026 16:55 - 17:20 CEST
Join Jeremiah Lowin (Fast MCP), Shaun Smith (fast-agent) and Sam Morrow (GitHub MCP) for a panel on the challenges and opportunities of shipping MCP, hosted by Angie Jones, VP of Developer Experience at the AAIF.

By bringing perspectives from server, SDK and agent harness developers together in the same panel, you’ll see where their experiences align, l where they diverge, where they see the protocol heading and what they’re excited about.
Speakers
avatar for Sam Morrow

Sam Morrow

Senior Software Engineer, GitHub
Sam is a Senior Software Engineer at GitHub, where he leads development of the GitHub MCP server. He works on AI developer tools and helps shape agentic workflows at GitHub. In a past life he was also a professional drummer.
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
avatar for Shaun Smith

Shaun Smith

Open Source Agents / MCP, Hugging Face
Shaun leads Open Source/MCP at Hugging Face, and is an MCP Steering Committee member serving as a Community Moderator and Transports Working Group. He is also the author of `fast-agent` - one of the few clients with comprehensive protocol support and diagnostic capabilities.
Friday September 18, 2026 16:55 - 17:20 CEST
Emerald Room (Level 1)

16:55 CEST

The Autonomous Enterprise – Scaling Computer Use With Holo3 and HoloTab - Pierre-Louis Cedoz, H Company
Friday September 18, 2026 16:55 - 17:20 CEST
H Company is the leading agentic AI startup in Europe, based in Paris, specialized in computer use.

The AI landscape is shifting rapidly from passive text generation to active execution. The frontier belongs to Agentic AI, systems that don't just chat, but autonomously navigate digital environments to complete complex workflows.

At H Company, we bridge this gap between frontier research and production-grade deployment. We will explore how H Company built Holo3, our state-of-the-art model family designed specifically for "Computer Use" (GUI perception, planning, and OS navigation). Moving from theory to practice, we will demonstrate how these compact, high-efficiency models power our latest enterprise tools—including HoloTab, our autonomous AI browser companion. Finally, we will unpack the unified infrastructure model required to train, deploy, and scale these agents securely across multi-cloud environments.
Speakers
avatar for Pierre-Louis Cedoz

Pierre-Louis Cedoz

CTO, H Company
Pierre-Louis Cedoz is CTO at H Company, where he leads the research and development of next-generation, action-oriented AI. With an extensive background spanning reinforcement learning, large action models, and advanced machine learning research at institutions like Stanford University... Read More →
Friday September 18, 2026 16:55 - 17:20 CEST
G104 + G105 (Level 1)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -