AGNTCon + MCPCon North America: The AI Agents Conference
""

Poster Presentations

Posters will be available to view in the Solutions Showcase throughout the event.

Poster Presenters will be available for discussions during the Attendee Reception October 22, 2026 – 5:45 – 7:00 PM PDT

Most production agents are running on what amounts to a god-mode API key: broadly scoped, long-lived, and shared across teams. When the agent acts on a user’s behalf, “who triggered this” and “who executed this” collapse into one unanswerable question. The security review queue becomes the bottleneck on every release.

This session presents a zero-trust identity pattern that gives agents a first-class, governable place in your identity stack. We cover: (1) why IAM systems designed for users and services break down when the principal is an autonomous agent; (2) the OAuth Subject vs. Actor claim distinction that captures the human-to-agent-to-tool chain at every hop; (3) Intersection Authorization, where effective permissions are computed dynamically; (4) immutable audit lineage; (5) how this composes across different frameworks (CrewAI, LangGraph, LlamaIndex) and protocols (MCP, AGENTS.md, custom).

Attendees leave with a deployable identity pattern, the math their security team needs to verify it, and lessons from rollouts in regulated industries.

Presenters:

  • Jayanth Rajashekariah — Director of Engineering, Identity and Access, DataRobot

View in the Schedule

Most agentic systems today rely on the model to orchestrate execution by chaining tool calls together. This works for simple tasks, but breaks down as workflows get longer, more data is passed around, and new tools are added. This leads to agents that are expensive, unreliable, and hard to operate.

The answer is clear: use code to do the tool call orchestration instead. The challenge with current approaches (like MCP CodeMode) is that agents write and run arbitrary code in production. That creates security and operations problems that relegates this class of agents to the sandbox, or a developer’s machine.

Not anymore.

In this talk, Adam Terlson introduces and demonstrates a different approach: have the agent produce a static, declarative Finite State Machine (called a Charter), then interpret that Charter as code instead. The agent is up to 99% more context efficient, is able to effectively use 1000s of tools, and has many other benefits.

See for yourself how this architecture can make agents far more capable, reliable, observable, and secure at global scale—no sandbox required!

Presenters:

  • Adam Terlson — Chief Technology Officer, Chief Architect, BlueFolders

View in the Schedule

Most MCP tooling is built by developers, for developers. But if agentic AI is going to matter beyond writing code, someone has to figure out what it looks like for everyone else.
AgentOne is an open-source desktop AI agent built for people who will never write a prompt template or configure an MCP server by hand. Building it forced me to rethink assumptions the agent ecosystem takes for granted: How do you present tool approval to someone who doesn’t know what a tool is? How does MCP server discovery work when your user just wants things to work? What does trust look like when the operator and the end user are the same non-developer?
This talk shares what I learned building AgentOne: the UX patterns, the architectural decisions, and the open questions we still haven’t answered. The goal is to bring a perspective the ecosystem needs: what happens when MCP meets real users.

Presenters:

  • Elijah Pettit — Founder & Full-Stack Developer, AgentOne

View in the Schedule

Hosted MCP servers usually give you two knobs: broad OAuth scopes upstream, and tool exposure at deploy time.

Your engineers may be allowed to do almost anything GitHub permits. Their agents should not. You might want an agent to open a pull request, but leave merging to a human. If you do not operate the hosted server, you cannot add that distinction there.

This talk shows how to close that gap with an identity-aware bridge. Pomerium sits in front of a hosted MCP server, handles OAuth for the user, evaluates per-tool and per-identity policy on each MCP call, and audits tool names and arguments. The interesting part is applying a proven proxy pattern to MCP so authorization happens at runtime, not deploy time.

I will demo this live against GitHub’s hosted MCP server, with the audit log visible. The agent opens a pull request. Then we flip one policy toggle and the same agent is blocked from merging, without changing the client, server, or GitHub permissions.

GitHub is the marquee demo, but the pattern is broader: add policy and audit controls for hosted MCP servers you don’t own.

Presenters:

  • Nick Taylor — Developer Advocate, Pomerium

View in the Schedule

Most agent stacks treat memory as storage: vector databases, summary tables, episodic logs, retrieval pipelines. The store answers what the agent saw. It does not answer where a particular memory came from, how confident the chain that produced it actually is, what depends on it, or what should happen when a request to forget arrives.
Long-running agents need that second set of answers. Without them, low-confidence input becomes high-confidence output along chains the agent never inspects, exceptions generalize into rules, and forget requests leave derivative memories untouched.
This talk advocates for a separate trust layer that sits between the agent and the memory store, independent of the agent framework and the backing store. A framework that’s built on provenance walks across writes, confidence that cascades along the chain, forget operations and isolation guarantees when agents share state. An MCP server makes the layer accessible to any compliant client. The talk covers the design, and an open-source reference implementation.

Presenters:

  • Ratnopam Chakrabarti — Sr. Solution Architect, Agentic AI and Open Source, Amazon Web Services
  • Mahalingam Sivaprakasam — Senior Solutions Architect, AWS

View in the Schedule

Local agentic workflows on workstation-class systems create a new serving problem: not every step in an agent session needs the same model, but switching models at the wrong moment can break the workflow.
This talk presents a Mixture-of-Models design using vLLM Sleep Mode, where one model stays hot while others are hibernated and restored on demand, enabling practical multi-model serving on a single workstation.
The presentation centers on Session-Aware Agentic Routing (SAAR), recently introduced in vLLM Semantic Router for long-horizon agents.
SAAR adds session memory, hard locks around active tool loops and non-portable provider state, safe reset boundaries, and switch economics so routing decisions preserve continuity rather than optimize each turn in isolation.
In public results, SAAR reduced model switches by 79.29%, eliminated 3,836 unsafe switches, and reduced estimated cost by 78.71%.
The key takeaway is that for local agent systems, the challenge is not just model selection, but preserving tool-state continuity while making multi-model execution practical and reliable.

Presenters:

  • Kushal Mittal — AI Solutions Architect, Intel Corporation

View in the Schedule

Most LLM safety work guards the user prompt, but MCP agents are compromised through the tools they already trust: poisoned tool descriptions, instructions hidden in tool responses, rug-pull servers that change after approval, and malicious packages from public registries.

This poster presents ShieldMCP, an open-source (Apache-2.0) transparent proxy that sits between any MCP client and server and validates traffic in 3 stages: description integrity at discovery time, parameter sanitization on every outbound call, and response analysis on the way back – all with zero changes to the agent, the model, or the server.

The defenses operationalize the SAFE-MCP taxonomy developed under the Linux Foundation’s OpenSSF (14 tactics, 80+ techniques). On a reproducible benchmark of 487 attack scenarios and 200 benign tasks across 40 MCP servers, ShieldMCP reduces attack success from 70.9% to 8.6% while preserving 95% of benign task utility, with sub-millisecond median overhead.

The underlying research was published at the ACL 2026 Industry Track and published at the EMNLP 2026 System Demonstrations Track.

Presenters:

  • Saurabh Yergattikar — Member of Technical Staff-2, eBay Inc.

View in the Schedule

Your MCP server passes every test in Claude, then a user runs it in Cursor and it falls apart. Same server, different client, different outcome. Each client supports its own capabilities, manages context differently, provides different LLMs. Working in one client tells you almost nothing about production behavior across clients.

This session makes the case for automated cross-client evaluation: running eval suites against the same MCP server across many client configurations on every code change and deployment. We’ll share what we’ve seen for developers testing across 40,000+ MCP servers and 40,000+ client configurations:

Common ways things break: Why an agent might suddenly pick the wrong tool, mangle your data formatting, or secretly cut off your tool descriptions when switching between different apps.

The metrics to track: How to measure whether the agent actually picked the right tool, sent the right data, and what your exact success rate looks like on each specific client.

How to fix it automatically: How to move past just finding these bugs and start using automation to tweak your prompts and settings until they work flawlessly everywhere, not just on your laptop.

Presenters:

  • Marcelo Jimenez Rocabado — CTO, MCPJam

View in the Schedule

AI agents are moving from demos to production, acting on web apps on behalf of real users and teams. Yet many products fail them in subtle ways—not because the agents are bad, but because the apps were never designed to be operated by anything other than a human eye and mouse.

This talk introduces Agent Experience (AX) as a first-class concern, alongside UX for users and DX for developers, and argues that accessibility and testability standards are its foundation. I’ll cover the common traps—brittle selectors, inaccessible UI patterns, and unstructured interactions—then run a live demo with NASA Open MCT, Playwright MCP, Playwright CLI, and Claude Code, showing how accessible markup and semantic structure measurably improve an agent’s ability to understand, navigate, and act.

You’ll leave with concrete steps to improve accessibility, testability, and agent compatibility in your own products—yielding not just better AI performance, but more robust, maintainable, and human-friendly apps. Because if an agent can’t use your app, often neither can a screen reader.

Presenters:

  • John Hill — Agentic QA Lead, Neubird

View in the Schedule

Most agent failures are discussed as model failures. In production, many of the painful failures happen after the model has already done its job.

A tool-using agent turn crosses several boundaries: the user request, the model server, the tool-call decision, the client or orchestration layer that runs the tool, the structured result returned to the model, the resumed generation path, and the infrastructure that keeps state alive across that flow. Each boundary creates a new place for stale state, replayed tool results, lost context, hidden batching delays, bad routing, or partial failure to show up as a bad user experience.

This talk shares a practical systems model for building reliable MCP-style agent infrastructure. The core idea: treat an agent turn as a traceable transaction, not a single model call. We walk through a reference path where tool execution stays client-side, the inference layer detects tool-call intent, the API layer routes by model and session state, and the serving layer tracks KV cache, device health, shard placement, and queueing delay as first-class signals.

Presenters:

  • Jigar Kuverji Savla — Silicon Architect & Product, AI Inference Systems @ Tensordyne, Tensordyne Inc

View in the Schedule

Most agent systems are built for observability, capturing computational signals like latency and error rates. That holds up fine and dandy until the question inevitably becomes whether specific workflows are worth their cost or whether automation is actually reducing spend…or just moving it somewhere less, well, visible.

The AGNTCon + MCPCon session will help attendees understand:

  1. Where the data models diverge and what that means when you try to answer questions neither system was designed for.
  1. What token spend misses. In production multi-agent systems, tool invocations, external API calls, human review, and downstream service calls typically dwarf token costs and arrive with no link back to the agent execution that triggered them.
  1. Why event-level records matter. Aggregated cost metrics answer questions about averages, but event-level records answer questions about specific executions and specific customers.
  1. What complete instrumentation looks like in production systems, including the specific edge cases in parallel tool calls and async agent chains where standard tracing patterns break down.

Presenters:

  • John D’Emic — Chief Technology Officer, Revenium

View in the Schedule

Sponsors

Diamond

Platinum

Gold

Silver

Startup

Media Partners