AGNTCon + MCPCon North America 2026

Table of Contents

Basics

Field Value
Dates <2026-10-22 Thu>–<2026-10-23 Fri> (workshops <2026-10-21 Wed>)
Location San Jose, California — San Jose McEnery Convention Center
Host The Linux Foundation
URL events.linuxfoundation.org
Format Two co-located conferences, multi-track (11 rooms)
Scale 163 sessions, 164 speakers, 19 keynotes; 21 MCPCon-track, 6 workshops

About

Two co-located Linux Foundation conferences run as one event. AGNTCon covers building, evaluating, and operating AI agents; MCPCon is dedicated to the Model Context Protocol — the open standard for connecting agents to tools and data. The program spans multi-agent systems, interoperability and standards, evals and testing, reliable agent systems, enterprise adoption, agentic commerce, and open-source ecosystem health.

The overlap with this site's standing threads is direct: MCP tooling (code-graph MCP survey), agent orchestration, and identity/authorization for agents (Aaron Parecki of Okta on identity standards; David Soria Parra of Anthropic on MCP).

Keynotes

  • Welcome to AGNTCon + MCPCon North America — Angie Jones (10-22 09:00)
  • Opening Remarks — Mazin Gilbert (10-22 09:05)
  • Keynote: Manik Surtani, CTO, Agentic AI Foundation — Manik Surtani (10-22 09:15)
  • Keynote: Tokenomics: Energy to Intelligence to Value — J.R. Storment (10-22 09:25)
  • Keynote: David Soria Parra, Technical Staff, Anthropic — David Soria Parra (10-22 09:30)
  • Keynote: Building the Human-Agent Workplace — Bradley Axen (10-22 09:40)
  • Keynote: Dawn Song - UC Berkeley — Dawn Song (10-22 14:55)
  • Sponsored Keynote: The Anything Trap: What to Build When Agents Can Build Everything — Lena Hall (10-22 15:10)
  • Sponsored Keynote: Agents as Actors: Harnessing the Power of Agentic Infrastructure — Idit Levine, Keith Babo (10-22 15:20)
  • Keynote: The Agentic Web - Sarah Drasner, Distinguished Engineer, Google — Sarah Drasner (10-22 15:25)
  • Welcome Back & Awards — Mazin Gilbert (10-23 09:00)
  • Keynote: Mark Collier, Executive Director, PyTorch Foundation — Mark Collier (10-23 09:20)
  • Keynote: Thomas Dohmke, Co-Founder & CEO, Entire — Thomas Dohmke (10-23 09:25)
  • Sponsored Keynote: Coding Agents need Deterministic Correctness — Shadaj Laddad (10-23 09:40)
  • Keynote Sessions to be Announced (10-23 09:45)
  • Keynote: Tim O'Reilly, Founder and CEO of O’Reilly Media, Inc. — Tim O'Reilly (10-23 09:55)
  • Keynote: Chi Wang, Senior Staff Research Scientist, Google DeepMind — Chi Wang (10-23 15:05)
  • Keynote Sessions to be Announced (10-23 15:15)
  • Keynote: Paul Conyngham, Founder, Gamgee Technologies — Paul Conyngham (10-23 15:30)

Curated picks

A curated slice keyed to this site's standing concerns — object-capability security, provenance, contract/invariant, blast radius, governance, and refutation-first framing. Tier 1 is the center of that register; Tier 2 is strong-adjacent. Verified against the Sessionize export; overlay rationale is editorial.

Tier 1

  • Engineering Multiagent Systems — Munindar Singh (10-22 10:55, LL21 ABC) Formal interaction protocols with correctness guarantees; commitments/social meaning first-class (Singh, commitment-protocol lineage). Project: shcv/bspl — BSPL commitment-protocol toolkit (Python, MIT, active). Singh has no personal repo; tooling ships under collaborators.
  • Don't Share the Database: Interface Contracts Between Isolated AI Agents — Martin Bliss (10-22 12:40, LL21 ABC) Parnas '72 information hiding: published facades over hidden internals, producer/consumer handshake, refuses to fail silently. Refutation: Could be architecture-astronaut with no enforcement; demand the mechanism that makes silent retrieval failure impossible. Project: no public repo — reads as a concept/architecture talk (speaker identity inferred, not confirmed).
  • Trustworthy Context Is Untrusted By Default — Shub Argha (10-22 13:15, 210 BF) Provenance footers, commit-at-write staleness anchors, write-risk classification, quantified (88.8%->33.3%) with named unmitigated attack classes. Project: speaker is at Arcade.dev (shubcodes); no dedicated repo for these mechanisms (closest: arcade-mcp, an MCP tool framework). Benchmark unpublished.
  • Who, May, Did: Composing Agent Identity with Verifiable Proof of What Agents Actually Do — Steven Mih (10-22 17:30, LL21 ABC) may/did distinction (approved != executed != confirmed); tamper-evident action records referencing identity/consent by digest, anchored on SCITT/COSE. Project: action-state-group — agent-action-capsule (BSD-3), capsule-emit + scitt-cose (Apache-2.0), implementing his IETF SCITT draft-mih-* drafts. Mih: ex-Alluxio/Ahana/Aviatrix.
  • Sponsored Keynote: Coding Agents need Deterministic Correctness — Shadaj Laddad (10-23 09:40, Grand Ballroom) Deterministic simulation + universal properties via Rust types. Invariants-by-construction for agent-authored distributed systems (Hydro). Refutation: 5-min keynote slot: pointer to the work, not the payload. Project: Hydro — correctness-by-construction distributed systems (Apache-2.0, Rust, ~1.3k stars); the old Hydroflow, now DFIR + hydro_lang. AWS-backed (shadaj.me).
  • Your Agent Sandbox Is Built Backwards — Dan Fernandez, Ariadne Conill (10-23 13:20, 210 BF) Object-capability security for agents: zero authority + injected scoped capabilities; lifecycle IS the audit trail. Refutation: If attenuation is enforced only at grant, not at delegation, it's ambient authority with extra steps. Project: Styrolite + Styrojail — namespace sandboxing for untrusted agents (Edera, Apache-2.0, Rust, active). Conill = Alpine/Wolfi (kaniini).

Tier 2

  • Should This Be an AI Agent? A Product Framework for Enterprise Adoption — Takeshwari Kamal (10-22 11:30, LL20 CD) Explicit blast-radius model: permissions, escalation paths, reversibility, failure tolerance. Refutation: PM-framed; lighter on mechanism.
  • Generation-Verification Asymmetry: The Production Failure Pattern Nobody Has Named Yet — Birajendu Sahu (10-22 16:20, LL20 AB) Names generation/verification cost asymmetry as compounding liability. Refutation: Vendor-demo framing; discount accordingly.
  • Bridging Agentic Reasoning and Deterministic Execution — Marcio Klepacz (10-22 17:30, 210 BF) Agent-authored deterministic, replayable DAGs; reason where flexible, execute where reliable.
  • Configured for Autonomy: Making Enterprise Agents Useful and Safe at Scale — Viyat Bhalodia, Casey Silver (10-22 18:05, 210 BF) Capability profiles + sandbox + LLM-judge escalation + replay of policy against past workflows.
  • When Agents Spawn Agents: Securing Recursive Delegation in Multi-Agent Systems — Anishma Mavuram (10-23 11:35, LL20 CD) Recursive delegation, monotonic least-privilege attenuation, confused-deputy. Composes with the capability model. Refutation: Stacks ~8 RFCs; standards-soup risk.
  • The Agentic Orchestration Stack: Durability, Guardrails, and Attestation — Yaron Schneider (10-23 13:20, LL20 CD) Durable execution + cryptographic attestation + provenance (Dapr lineage).
  • Agent Governance Lives in the OS — Alexander Sklar, Roberth Karman (10-23 16:05, LL20 CD) 'Governance is the goal, OS enforcement is the mechanism.' Composes bubblewrap/seatbelt/AppContainer; honest about non-composition.
  • Prove What Your Agent Did: Tamper-Evident Audit Trails for Tool Calls — Vikas Luthra (10-23 16:40, LL20 AB) Merkle-root/hash-chain tamper-evident audit trails, O(log n) single-action verification.
  • Stop Writing Agents, Declare Them: Declarative Agent Architecture in Production — Chris Knuteson (10-23 16:40, 210 BF) AgentSpec-as-contract, narrow waist, governance/resilience/future-proofing by construction.

Slot conflicts

The real decision is slot contention. Notable overlaps among the curated picks:

  • Day 1 17:30 — Who, May, Did (Mih) and Bridging Agentic Reasoning (Klepacz) both run against the Break the Lethal Trifecta workshop. Recommended: skip the workshop, take Who/May/Did then Configured for Autonomy (18:05) back-to-back.
  • Day 2 16:40 — Prove What Your Agent Did (Luthra) vs Stop Writing Agents, Declare Them (Knuteson).

Tracks and topics

Session counts by topic tag (a session may carry more than one):

  • MCPCon — 21
  • Keynote Session — 19
  • Agentic Engineering — 17
  • Enterprise Adoption in Practice — 16
  • Interoperability & Standards — 13
  • Building Reliable Agent Systems — 12
  • Multi-Agent & Distributed Systems — 9
  • Open Source Tools — 9
  • Breaks+Meals+Special Events — 7
  • Demo Theater — 7
  • Human-Agent Collaboration — 7
  • Workshop — 6
  • Evals & Testing — 6
  • Agentic Commerce — 5
  • Registration — 3
  • Solutions Showcase — 2
  • Open Source Community & Ecosystem Health — 2

Full program

From the Sessionize schedule. Line format: time — title — speaker(s) [room | topic | type].

Wednesday, Oct 21 — Workshops and pre-event

  • 08:00–12:00 — Registration & Badge Pick-Up [The Hub]
  • 18:00–21:00 — AI Community Bash featuring DE LA SOUL [Concert Venue]

Thursday, Oct 22 — Day 1

  • 07:30–19:05 — Registration & Badge Pick-Up [The Hub]
  • 09:00–09:05 — Welcome to AGNTCon + MCPCon North America — Angie Jones [Grand Ballroom / Keynote Session / Keynote]
  • 09:05–09:10 — Opening Remarks — Mazin Gilbert [Grand Ballroom / Keynote Session / Keynote]
  • 09:15–09:25 — Keynote: Manik Surtani, CTO, Agentic AI Foundation — Manik Surtani [Grand Ballroom / Keynote Session / Keynote]
  • 09:25–09:30 — Keynote: Tokenomics: Energy to Intelligence to Value — J.R. Storment [Grand Ballroom / Keynote Session / Keynote]
  • 09:30–09:40 — Keynote: David Soria Parra, Technical Staff, Anthropic — David Soria Parra [Grand Ballroom / Keynote Session / Keynote]
  • 09:40–09:50 — Keynote: Building the Human-Agent Workplace — Bradley Axen [Grand Ballroom / Keynote Session / Keynote]
  • 09:53–10:03 — Sponsor Activity: Akamai AI Orchestrator — Du'An Lightfoot [Solutions Showcase / Demo Theater / Sponsored Session]
  • 09:55–10:20 — Coffee Break [Solutions Showcase]
  • 09:55–20:00 — Solutions Showcase [Solutions Showcase / Solutions Showcase]
  • 10:05–10:15 — Sponsor Activity: DO NOT give AI agents credentials! — Christian Posta [Solutions Showcase / Demo Theater / Sponsored Session]
  • 10:20–10:45 — Scaling AI Infrastructure Systems at Meta Scale — Neelakshi Soni [210 BF / Agentic Engineering / Breakout]
  • 10:20–10:45 — Stop Vibe-Testing: Run Real Agent Evals — Laurie Voss [210 CG / Evals & Testing / Breakout]
  • 10:20–10:45 — Evolution, not Revolution: How MCP is Reshaping OAuth — Aaron Parecki [LL20 AB / MCPCon / Breakout]
  • 10:20–10:45 — Gotta Catch 'Em All: Agent Skills — Lizzie Siegle [LL20 CD / Agentic Engineering / Breakout]
  • 10:20–10:45 — Don't Merge That: An Agentic Approach to Catching Outages at 10,000 PRs a Week — Joris Bonnefoy [LL21 ABC / Building Reliable Agent Systems / Breakout]
  • 10:20–11:55 — Workshop: The Buzz-Word Is Collaboration 🐝 — Tyler Longwell, Morgan Martin, Wes Billman, Taylor Ho, Bradley Axen, Will Pfleger [LL21 DEF / Human-Agent Collaboration / Workshop / Workshop]
  • 10:55–11:20 — Five Ways to Stop Sabotaging Your Own AI Adoption — Adam Jones [210 BF / Enterprise Adoption in Practice / Breakout]
  • 10:55–11:20 — Generative UI at Scale with A2UI — Alan Blount [210 CG / Human-Agent Collaboration / Breakout]
  • 10:55–11:20 — From DCR to CIMD: MCP Client Identity in Production — Alvaro Inckot [LL20 AB / MCPCon / Breakout]
  • 10:55–11:20 — Interoperable Agent Discovery: AI Catalog, ARD, and the AGNTCY Directory — Luca Muscariello, Junjie Bu [LL20 CD / Interoperability & Standards / Breakout]
  • 10:55–11:20 — Engineering Multiagent Systems — Munindar Singh [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 11:30–11:55 — Sponsored: LLMs Are a Commodity. Choice and Control Aren't. — Don Murray [210 AE / Enterprise Adoption in Practice / Sponsored Session]
  • 11:30–11:55 — There's No Dark Factory Without Better Software Verifiers — Dexter Horthy [210 BF / Agentic Engineering / Breakout]
  • 11:30–11:55 — AP2, UCP and So Many Others.. But What Completes My Payments? — Muskan Jain [210 CG / Agentic Commerce / Breakout]
  • 11:30–11:55 — What Your MCP Server Does When Nobody's Looking — Austin Parker [LL20 AB / MCPCon / Breakout]
  • 11:30–11:55 — Should This Be an AI Agent? A Product Framework for Enterprise Adoption — Takeshwari Kamal [LL20 CD / Enterprise Adoption in Practice / Breakout]
  • 11:30–11:55 — The Sleeper Awakes:Intelligent Hibernation and Wake-Up Strategies for Agent Sandboxes — Zhang Zhen [LL21 ABC / Building Reliable Agent Systems / Breakout]
  • 12:05–12:30 — Sponsored: Beyond MCP: Building an Enterprise Knowledge Layer for Production AI Agents — Jeremy Adams - Casañas [210 AE / Enterprise Adoption in Practice / Sponsored Session]
  • 12:05–12:30 — Skills Assemble: How Superpowered AI Teams Replace Prompt Chaos — Eddie Wassef [210 BF / Enterprise Adoption in Practice / Breakout]
  • 12:05–12:30 — Programmable LLM Inference for Open Agent Infrastructure — Lin Zhong [210 CG / Open Source Tools / Breakout]
  • 12:05–12:30 — Leveraging A2A Protocol to Build Framework Agnostic Multi-Agent System — Sohil Shah [LL20 CD / Interoperability & Standards / Breakout]
  • 12:05–12:30 — Before the Agent Writes Code: Policy-Aware Engines for AI Coding — Nnenna Ndukwe [LL21 ABC / Building Reliable Agent Systems / Breakout]
  • 12:40–13:05 — Sponsored: The Control Plane Your MCP Gateway Forgot — Alex Salazar [210 AE / MCPCon / Sponsored Session]
  • 12:40–13:05 — Where Did All My Tokens Go? Using Agentgateway to Keep Your AI Usage Under Control — Shane O'Donnell [210 BF / Enterprise Adoption in Practice / Breakout]
  • 12:40–13:05 — Between Intent and Execution — Hemanth hm [210 CG / Agentic Engineering / Breakout]
  • 12:40–13:05 — Building Production-Ready Agents with a Regression Test Suite — Yuki Watanabe [LL20 CD / Evals & Testing / Breakout]
  • 12:40–13:05 — Don't Share the Database: Interface Contracts Between Isolated AI Agents — Martin Bliss [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 13:15–13:40 — Sponsored: Why API Modernization is the Prerequisite to AI Governance — Amit Shah [210 AE / Enterprise Adoption in Practice / Sponsored Session]
  • 13:15–13:40 — Trustworthy Context Is Untrusted By Default — Shub Argha [210 BF / Building Reliable Agent Systems / Breakout]
  • 13:15–13:40 — There Is No Loading State: Real-Time Tool Calling for Voice Agents — Amanda Martin [210 CG / Human-Agent Collaboration / Breakout]
  • 13:15–13:40 — MCP Rug Pulls in the Wild: Live Attacks and How to Stop Them — Advait Patel, Charit Upadhyay [LL20 AB / MCPCon / Breakout]
  • 13:15–13:40 — Counting Tokens Before They Hatch: Predicting Agent Costs Before Execution — Kirah Sapong [LL20 CD / Agentic Engineering / Breakout]
  • 13:15–13:40 — Multi-Agent SRE: What Happens When Your Agents Want Opposite Things — Prakshal Doshi, Aditi Mewada [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 13:40–14:55 — Attendee Lunch [Solutions Showcase]
  • 13:40–14:55 — Women + Non-Binary Community Gathering [Solutions Showcase]
  • 13:57–14:07 — Sponsor Activity: Looping to Optimized Models on Custom Silicon — John Liu [Solutions Showcase / Demo Theater / Sponsored Session]
  • 14:33–14:43 — Sponsor Activity: Trust, But Verify: Human-in-the-Loop for Agents That Actually Matter — Michael Liendo [Solutions Showcase / Demo Theater / Sponsored Session]
  • 14:55–15:05 — Keynote: Dawn Song - UC Berkeley — Dawn Song [Grand Ballroom / Keynote Session / Keynote]
  • 15:10–15:15 — Sponsored Keynote: The Anything Trap: What to Build When Agents Can Build Everything — Lena Hall [Grand Ballroom / Keynote Session / Keynote]
  • 15:20–15:25 — Sponsored Keynote: Agents as Actors: Harnessing the Power of Agentic Infrastructure — Idit Levine, Keith Babo [Grand Ballroom / Keynote Session / Keynote]
  • 15:25–15:35 — Keynote: The Agentic Web - Sarah Drasner, Distinguished Engineer, Google — Sarah Drasner [Grand Ballroom / Keynote Session / Keynote]
  • 15:45–16:10 — Sponsored: 5 Ways to Build a Durable Browser Agent in 2026 — Andrew Baker [210 AE / Building Reliable Agent Systems / Sponsored Session]
  • 15:45–16:10 — Stop Running Agents as Service Accounts: User-Scoped Access for Enterprise Tool Calls — Masato Kozuka [210 BF / Enterprise Adoption in Practice / Breakout]
  • 15:45–16:10 — Part Man. Part Machine. All Open Source — Russell Spitzer [210 CG / Open Source Community & Ecosystem Health / Breakout]
  • 15:45–16:10 — The Other Half of MCP Apps: Building a Secure, Self-Hostable Host for Interactive Agent UIs — Mathew Goldsborough [LL20 AB / MCPCon / Breakout]
  • 15:45–16:10 — Cut The Noise: Building a Code Reviewer You Can Trust — Joah Gerstenberg [LL21 ABC / Agentic Engineering / Breakout]
  • 15:45–17:20 — Workshop: Keep Infrastructure Out of Your AI Agents and MCP Servers — Lin Sun, Christian Posta [LL21 DEF / Open Source Tools / Workshop / Workshop]
  • 15:45–15:55 — Sponsor Activity: Building an MCP Server in 7 Minutes — Don Murray [Solutions Showcase / Demo Theater / Sponsored Session]
  • 16:00–16:10 — Sponsor Activity: Beyond models: Open source drives the AI ecosystem — Wesley Chun [Solutions Showcase / Demo Theater / Sponsored Session]
  • 16:20–16:45 — How AT&T Is Building an Agentic Front Door for Enterprise HR — Natalie Gilbert, Sherman Bell, Emily Williams, Hector Tejada, Prateek Baranwal [210 BF / Enterprise Adoption in Practice / Breakout]
  • 16:20–16:45 — Universal Commerce Protocol — Ilya Grigorik [210 CG / Agentic Commerce / Breakout]
  • 16:20–16:45 — Generation-Verification Asymmetry: The Production Failure Pattern Nobody Has Named Yet — Birajendu Sahu [LL20 AB / MCPCon / Breakout]
  • 16:20–16:45 — The Frontend Strikes Back: WebMCP and The Agent-Ready Browser — Ryan Roemer [LL20 CD / Interoperability & Standards / Breakout]
  • 16:20–16:45 — From Pilot to Production: Lessons from Operating Multi-Agent Systems at Scale — Rupal Shirpurkar [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 16:55–17:20 — Connecting the Dots with Context Graphs — Stephen Chin [210 AE / Building Reliable Agent Systems / Breakout]
  • 16:55–17:20 — What Production Knows: Closing the Loop Between AI Agents and the Systems They Build — May Walter [210 BF / Agentic Engineering / Breakout]
  • 16:55–17:20 — How Agents Really See the Web — Liad Yosef [210 CG / Human-Agent Collaboration / Breakout]
  • 16:55–17:20 — One MCP Server, 50 Agents: The Identity Gap OAuth Doesn't Close — Mohit Gurnani [LL20 AB / MCPCon / Breakout]
  • 16:55–17:20 — AGENTS.md is the New CONTRIBUTING.md: A Field Report from One Year of Agent-Friendly Monorepos — Unnati Mishra [LL20 CD / Interoperability & Standards / Breakout]
  • 16:55–17:20 — Anatomy of a Claude Code Plugin, and Lessons Learned on Creating One — Charlie Lin [LL21 ABC / Open Source Tools / Breakout]
  • 17:30–17:55 — From Agent to Infrastructure: The Goose Development Kit — Steve Lee [210 AE / Open Source Tools / Breakout]
  • 17:30–17:55 — Bridging Agentic Reasoning and Deterministic Execution — Marcio Klepacz [210 BF / Agentic Engineering / Breakout]
  • 17:30–17:55 — Beyond Pass/Fail: Measuring the Full Agent Experience — Sean Roberts [210 CG / Evals & Testing / Breakout]
  • 17:30–17:55 — Governing MCP at Scale: Enforcing Agentic Architecture from Code Generation to Merge — Marc Daniel Registre, MBA [LL20 AB / MCPCon / Breakout]
  • 17:30–17:55 — The Autonomous Pipeline: Using Agentic AI to Automate FCRA Compliance from API Spec to Production — Gokul Prabagaren [LL20 CD / Enterprise Adoption in Practice / Breakout]
  • 17:30–17:55 — Who, May, Did: Composing Agent Identity with Verifiable Proof of What Agents Actually Do — Steven Mih [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 17:30–18:45 — Workshop: Break the Lethal Trifecta: Designing Access Boundaries Agents Can't Talk Their Way Past — Zayne Turner, Chris Miller [LL21 DEF / Interoperability & Standards / Workshop / Workshop]
  • 18:05–18:30 — Rethinking CI/CD Release Gates for Agent-native Software — Prathmesh Patel [210 AE / Evals & Testing / Breakout]
  • 18:05–18:30 — Configured for Autonomy: Making Enterprise Agents Useful and Safe at Scale — Viyat Bhalodia, Casey Silver [210 BF / Enterprise Adoption in Practice / Breakout]
  • 18:05–18:30 — Why Domain-specific Agents Are the Future — Justin Schroeder [210 CG / Interoperability & Standards / Breakout]
  • 18:05–18:30 — No New Authority: Publishing and Finding MCP Agents in DNS — Igor Racic, Ingmar Van Glabbeek [LL20 AB / MCPCon / Breakout]
  • 18:05–18:30 — Beyond Static DAGs: Orchestrating AI-Generated Multi-Agent Workflows — Cong Wang [LL20 CD / Multi-Agent & Distributed Systems / Breakout]
  • 18:05–18:30 — Hand the Agent the Clicker — Giovanni Laquidara [LL21 ABC / Agentic Engineering / Breakout]
  • 18:40–19:05 — Two Parallel Paths Or a Glimpse Of The Future? An Overview of the China Agentic AI Ecosystem — Bryan Che [210 AE / Interoperability & Standards / Breakout]
  • 18:40–19:05 — The Restraint Pattern: A Reliability Model for Agents That Act in Public — Bharat Patel [210 BF / Building Reliable Agent Systems / Breakout]
  • 18:40–19:05 — AI Collaboration Maturity: A Framework Beyond Engineering — Dakota Fabro [210 CG / Human-Agent Collaboration / Breakout]
  • 18:40–19:05 — Shipping an MCP Server Nobody Told You How To: PyPI, the Registry, and the Rough Edges — Mesut Oezdil [LL20 AB / MCPCon / Breakout]
  • 18:40–19:05 — Let's Play the Agentic AI Supply Chain Game! — Sarah Evans, Christopher Robinson [LL20 CD / Enterprise Adoption in Practice / Breakout]
  • 18:40–19:05 — Harness Engineering: From MAST's Failure Taxonomy to MCP-Native Multi-Agent Production — Jay Mehta [LL21 ABC / Agentic Engineering / Breakout]
  • 18:55–19:55 — Attendee Reception [Solutions Showcase]

Friday, Oct 23 — Day 2

  • 08:00–17:15 — Registration & Badge Pick-Up [The Hub]
  • 09:00–09:20 — Welcome Back & Awards — Mazin Gilbert [Grand Ballroom / Keynote Session / Keynote]
  • 09:20–09:25 — Keynote: Mark Collier, Executive Director, PyTorch Foundation — Mark Collier [Grand Ballroom / Keynote Session / Keynote]
  • 09:25–09:35 — Keynote: Thomas Dohmke, Co-Founder & CEO, Entire — Thomas Dohmke [Grand Ballroom / Keynote Session / Keynote]
  • 09:40–09:45 — Sponsored Keynote: Coding Agents need Deterministic Correctness — Shadaj Laddad [Grand Ballroom / Keynote Session / Keynote]
  • 09:45–09:50 — Keynote Sessions to be Announced [Grand Ballroom / Keynote Session / Keynote]
  • 09:55–10:05 — Keynote: Tim O'Reilly, Founder and CEO of O’Reilly Media, Inc. — Tim O'Reilly [Grand Ballroom / Keynote Session / Keynote]
  • 10:05–10:25 — Coffee Break [Solutions Showcase]
  • 10:05–15:00 — Solutions Showcase [Solutions Showcase / Solutions Showcase]
  • 10:25–10:50 — 1,149 Hackers Tried to Break Our AI Agent Guardrails. 0 Succeeded. Here's Why. — Uchi Uchibeke [210 BF / Interoperability & Standards / Breakout]
  • 10:25–10:50 — Engineering Agentic Commerce: Universal Cart, UCP, and Secure Payments — Amit Handa [210 CG / Agentic Commerce / Breakout]
  • 10:25–10:50 — The MCP Cold-Start Problem: When Your Agent Has 100 Tools and Has to Pick One — Karthik Karunanithi [LL20 AB / MCPCon / Breakout]
  • 10:25–10:50 — Build, Adopt, Build Around: Production Agents in a Moving Ecosystem — Ethan Lo, Jason Jiang [LL20 CD / Enterprise Adoption in Practice / Breakout]
  • 10:25–10:50 — Schrödinger's Skill: A 50-Client Autopsy of What "SKILL.md Support" Actually Means — Golan Myers [LL21 ABC / Interoperability & Standards / Breakout]
  • 10:25–12:00 — Workshop: Stack It Yourself: Open Infrastructure for AI Agents, from Compose to Cluster — Brian Benz [LL21 DEF / Open Source Tools / Workshop / Workshop]
  • 11:00–11:25 — Patterns for Shifting from MCP as a Basic API to MCP as Agent Integration Interface — James Ward, Alexander Ioffe [210 BF / MCPCon / Breakout]
  • 11:00–11:25 — Beyond LLMs in a Loop: Building Trusted Agents in Regulated Industries — Lucas Beeler [210 CG / Enterprise Adoption in Practice / Breakout]
  • 11:00–11:25 — Protocol Pivoting: How SSRF in MCP Servers Enables Cross-Protocol Lateral Movement — Syed Anas Mohiuddin N/A [LL20 AB / MCPCon / Breakout]
  • 11:00–11:25 — Decentralized Discovery: MCP, Skills, and Beyond with AI Catalog — Tadas Antanavicius [LL20 CD / Interoperability & Standards / Breakout]
  • 11:00–11:25 — Event-Driven Multi-Agent Orchestration: Fast Path, Smart Path, and Everything in Between — David Kjerrumgaard [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 11:35–12:00 — MCP Apps + WebMCP - The Next Era of Interface — Liad Yosef, Dominic Farolino [210 BF / Human-Agent Collaboration / Breakout]
  • 11:35–12:00 — Stop Agents From Leaking Your Secrets - AI Hooks To The Rescue — Dwayne McDaniel [210 CG / Agentic Engineering / Breakout]
  • 11:35–12:00 — Why the Heck Aren't Any Agents Supporting MCP Tasks? — Cornelia Davis [LL20 AB / MCPCon / Breakout]
  • 11:35–12:00 — When Agents Spawn Agents: Securing Recursive Delegation in Multi-Agent Systems — Anishma Mavuram [LL20 CD / Interoperability & Standards / Breakout]
  • 11:35–12:00 — Self-Hosting Agents: What Changes When Models Become Infrastructure — Miriah Peterson [LL21 ABC / Open Source Tools / Breakout]
  • 12:10–12:35 — The Agentic SDLC: How We Shipped AI-Native Software at a Legacy Company — Austin Brown [210 BF / Enterprise Adoption in Practice / Breakout]
  • 12:10–12:35 — Building an Agentic Eval Pipeline: Battle-Tested Lessons with EvalBench — Prerna Kakkar, Kurtis Van Gent [210 CG / Evals & Testing / Breakout]
  • 12:10–12:35 — One Server, Many Apps: A Composable MCP Architecture for Observability — Anirudha Jadhav, Shenoy Pratik Gurudatt [LL20 AB / MCPCon / Breakout]
  • 12:10–12:35 — Auth.md - The Open Protocol for Agentic Registration — Michael Grinich [LL20 CD / Interoperability & Standards / Breakout]
  • 12:10–12:35 — Your AI Agent Installed Malware Because a SKILL.md Told It To — Liran Tal [LL21 ABC / Building Reliable Agent Systems / Breakout]
  • 12:10–13:45 — Workshop: Governing AI Agent Actions: MCP and Beyond — Shannon Williams, Bill Maxwell [LL21 DEF / Enterprise Adoption in Practice / Workshop / Workshop]
  • 12:45–13:10 — Sponsored: Ship Your Most Powerful Agent: 7 Factors for Production Guarantees — Zayne Turner [210 AE / Building Reliable Agent Systems / Sponsored Session]
  • 12:45–13:10 — Shipping Agent Skills Safely: CI/CD, Evals, and Guardrails — Michael Larson [210 BF / Agentic Engineering / Breakout]
  • 12:45–13:10 — Embedding Agentic Payments with x402, A2A and Other Emerging Protocols — Fede Sarquis [210 CG / Agentic Commerce / Breakout]
  • 12:45–13:10 — Your Tool Is in Another Castle: How Five Frameworks Reshape the Same MCP Server — Thierry Damiba [LL20 AB / MCPCon / Breakout]
  • 12:45–13:10 — Why Your Agent Is Failing: Failure Modes from 6,000+ Agent Trajectories — Han Xu [LL20 CD / Evals & Testing / Breakout]
  • 12:45–13:10 — Don't Route What You Can't Redact: Sensitivity-Aware LLM Routing — Christopher Nuland, Grace Ableidinger [LL21 ABC / Open Source Tools / Breakout]
  • 13:20–13:45 — Your Agent Sandbox Is Built Backwards — Dan Fernandez, Ariadne Conill [210 BF / Building Reliable Agent Systems / Breakout]
  • 13:20–13:45 — What Voice Conversations are Teaching Us About Human-Agent Collaboration — Corey Weathers [210 CG / Human-Agent Collaboration / Breakout]
  • 13:20–13:45 — From Pain Points to Production: What We Learned Building MCP-Powered ChatGPT Apps — Nikolay Rodionov [LL20 AB / MCPCon / Breakout]
  • 13:20–13:45 — The Agentic Orchestration Stack: Durability, Guardrails, and Attestation — Yaron Schneider [LL20 CD / Agentic Engineering / Breakout]
  • 13:20–13:45 — Making Swarm Work: Coordination Primitives for Decentralized Multi-Agent Systems — Jodee Varney [LL21 ABC / Multi-Agent & Distributed Systems / Breakout]
  • 13:45–15:00 — Attendee Lunch [Solutions Showcase]
  • 14:50–15:00 — Sponsor Activity: AuthZ for Agents — Aaron Tainter [Solutions Showcase / Demo Theater / Sponsored Session]
  • 15:05–15:15 — Keynote: Chi Wang, Senior Staff Research Scientist, Google DeepMind — Chi Wang [Grand Ballroom / Keynote Session / Keynote]
  • 15:15–15:30 — Keynote Sessions to be Announced [Grand Ballroom / Keynote Session / Keynote]
  • 15:30–15:40 — Keynote: Paul Conyngham, Founder, Gamgee Technologies — Paul Conyngham [Grand Ballroom / Keynote Session / Keynote]
  • 16:05–16:30 — Open Source Has Been Here Before: Sustainability Lessons for Agentic AI — Katherine Druckman [210 CG / Open Source Community & Ecosystem Health / Breakout]
  • 16:05–16:30 — Data Agents over S3: Build the Missing Semantic Layer for Files — Dmitry Petrov [LL20 AB / MCPCon / Breakout]
  • 16:05–16:30 — Agent Governance Lives in the OS — Alexander Sklar, Roberth Karman [LL20 CD / Open Source Tools / Breakout]
  • 16:05–16:30 — How Contexts Fail (and How to Fix Them) — Drew Breunig [LL21 ABC / Open Source Tools / Breakout]
  • 16:05–17:40 — Workshop: Secure Agentic Framework (SAF) for Agentic AI — Sarah Evans, Jautau “Jay” White, Frederick Kautz, Laura Guazzelli [LL21 DEF / Interoperability & Standards / Workshop / Workshop]
  • 16:40–17:05 — Stop Writing Agents, Declare Them: Declarative Agent Architecture in Production — Chris Knuteson [210 BF / Building Reliable Agent Systems / Breakout]
  • 16:40–17:05 — Reading is Free, Spending is Not: What a Minimal Agent Learns Probing Live Ecommerce Endpoints — Francesco Marinoni Moretto [210 CG / Agentic Commerce / Breakout]
  • 16:40–17:05 — Prove What Your Agent Did: Tamper-Evident Audit Trails for Tool Calls — Vikas Luthra [LL20 AB / MCPCon / Breakout]
  • 16:40–17:05 — Agentic Workflows Are Distributed Systems: The Multi-Cloud Production Patterns You Cannot Avoid — Praneeth Kamalaksha Patil [LL20 CD / Multi-Agent & Distributed Systems / Breakout]
  • 16:40–17:05 — From AI Assistants to Trusted SDLC Agents: FINRA’s Agentic Engineering Journey — Geetha Ramachandran [LL21 ABC / Agentic Engineering / Breakout]
  • 17:15–17:40 — From Prompt to Production: Six Months of Running a Claude Agent SDK System in Front of Real Users — Dvir Arad [210 BF / Agentic Engineering / Breakout]
  • 17:15–17:40 — Beyond Scraping: Building Agent-Ready Documentation Layers for MCP and AI Agents — Ayodeji Ogundare [210 CG / Agentic Engineering / Breakout]
  • 17:15–17:40 — From MCP Tool-call to Motor Command: Giving Agents Fleet-scale Control of Real Hardware — Alexander Tsyplikhin [LL20 AB / MCPCon / Breakout]
  • 17:15–17:40 — Context Is the Substrate: Production Patterns for Knowledge-Graph-Backed Agents — Cassie Shum [LL20 CD / Building Reliable Agent Systems / Breakout]
  • 17:15–17:40 — Breaking the Agentic Loop - Multi-Turn Exploits Against Tool-Using AI Agents — Bar Kaduri [LL21 ABC / Agentic Engineering / Breakout]

Speakers

164 speakers across the two conferences. Keynoters are listed above; the full roster and abstracts are on the schedule. Notable by remit:

  • David Soria Parra —
  • Aaron Parecki — Director of Identity Standards, Okta
  • Sarah Drasner —
  • Dawn Song —
  • Tim O'Reilly —
  • Mark Collier —
  • Thomas Dohmke —
  • Chi Wang —
  • Manik Surtani —

Related