# Open Source in Finance Forum New York — Schedule

Machine-readable mirror of the schedule page. Generated 2026-09-19.

- Source: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/
- Sessions: 74 across 2 days
- Times are the event's local times, exactly as published. Timing and rooms are subject to change.
- Each session links back to the schedule page, which opens that session's details.

## Tracks

- Hot Topics (11)
- AI Risk Management & Developer Controls (8)
- AI Implementation & Engineering (8)
- AI Governance, Risk & Security (7)
- Cultivating the Culture & Business Strategy (6)
- Platform Engineering & The Connective Tissue (6)
- Scaling & Governing AI Workflows (5)
- Breaks + Meals + Special Events (5)
- Fluxnova Con - Fluxnova Core & Architecture (4)
- Fluxnova Con - Fluxnova Enterprise Case Studies (4)
- Keynote Sessions (3)
- Fluxnova Con - Fluxnova Architecture & Multi-Agent (3)
- Registration & Badge Pick-up (2)
- Sponsor Showcase (2)

## Wednesday, November 4, 2026

### 12:00 PM–7:20 PM · Registration & Badge Pick-up

- Room: 2nd Floor Entrance
- Track: Registration & Badge Pick-up
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311941

### 1:00 PM–2:30 PM · Keynote Sessions To Be Announced

- Room: Hall 1
- Track: Keynote Sessions
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311943

### 2:30 PM–7:00 PM · Sponsor Showcase

- Room: Hall 2
- Track: Sponsor Showcase
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311973

### 2:40 PM–3:15 PM · Fluxnova Killer Demo : Orchestration & Automation in Action

- Room: Hall 1
- Speakers: Harish Malavade
- Track: Fluxnova Con - Fluxnova Core & Architecture
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1283330

Join a live demo on how to Design, Deploy, Execute & Monitor end to end business process.
1. Fluxnova Modeler : Design and Deploy BPMN(Workflow) and DMN (Rules)
2. Fluxnova Engine/API : Execute the steps in process orchestrating with System, Human and AI
3. Fluxnova Control Center : Realtime monitoring and insights into Process execution

### 2:40 PM–3:15 PM · TD Bank's Fluxnova Journey

- Room: Hub 1
- Speakers: Mark Paulsen
- Track: Fluxnova Con - Fluxnova Enterprise Case Studies
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1277278

Fluxnova is an open source BPM (Business Process Management) which provides automation, orchestration, and agentic capabilities to accelerate the modernization of Financial Institutions workflows and end-to-end processes.

Maintained by some of the biggest Banks in the world, and managed by FINOS, it is the personification of the phrase, "Collaborate on the Core. Compete on the Edges".

But, how do you get started? And how do you scale? And how do you operationalize support and disaster recovery for critical business processes? And how do you start leveraging agentic capabilities?

This session will help address some of the challenges by looking at TD Bank's Fluxnova journey over the past year. It will cover what went well. What didn't. Lessons learned. And the roadmap ahead.

### 2:40 PM–3:15 PM · Orchestrating CDM with Fluxnova

- Room: Hub 2
- Speakers: Marc Gratacos, Manuel Martos
- Track: Fluxnova Con - Fluxnova Architecture & Multi-Agent
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1292118

This project demonstrates how the Fluxnova Platform can automate and orchestrate an end-to-end validation and qualification workflow for Common Domain Model (CDM) trading events.

The solution manages the process from trade selection and connection to external validation services through to result processing, user review and approval. Built using the Business Process Modeling and Notation (BPMN), configurable forms, and API integrations, it combines automation with human oversight at key decision points.

Its modular and extensible architecture supports different validation and qualification services, making the workflow adaptable to multiple business use cases. The project shows how combining CDM and Fluxnova can reduce manual effort, improve process efficiency and provide greater transparency and control across complex trading workflows.

### 2:40 PM–3:15 PM · Trusting Agentic Workflows: Embedding Agent Evaluation into Fluxnova

- Room: Hub 3
- Speakers: Vincent Caldeira, David Ogle
- Track: Scaling & Governing AI Workflows
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295773

Large Language Models enable workflows to handle tasks that were previously impossible to automate, but they also introduce new challenges around quality, governance, and trust. How do you confidently deploy agentic workflows when outcomes are inherently non-deterministic?

In this session, we demonstrate how Fluxnova's Agentic Subprocess capability can be combined with an open-source evaluation framework to create observable, governed, and continuously improving agentic workflows.

Using a financial services use case, we show how evaluation can be integrated throughout the workflow lifecycle: during development to validate behaviour before deployment, during execution through runtime evaluation and policy checks, and after execution using workflow traces to identify opportunities for improvement.

Attendees will see how Fluxnova combines deterministic workflow orchestration with adaptive AI capabilities, enabling organisations to blend traditional process control with agentic decision-making while maintaining transparency, auditability, and human oversight. The session includes practical implementation patterns and architecture guidance.

### 2:40 PM–2:55 PM · When the Agent Writes the Code: Enforcing Architecture Governance in the Age of AI-Generated PR

- Room: Hub 4
- Speakers: Marc Daniel Registre, MBA
- Track: AI Risk Management & Developer Controls
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1274771

For years, architectural conformance in regulated firms was enforced by an unstated control: a human in code review who knew the system and wrote at human speed. AI coding agents remove both halves - they don't know your declared architecture, and they generate change faster than any review board can inspect. The control didn't get weaker; it got bypassed.
This talk argues that telling an agent about your architecture is not the same as enforcing it. Advisory context still drifts; only a deterministic, non-bypassable gate that reconciles code against a declared model holds. Using FINOS CALM as the architectural source of truth, I'll walk through how to reconcile what an agent actually built, across files, through indirection, against what the architecture permits, and why the verdict must be sound, three-valued, and honest about what it can't determine.
Attendees leave with a pattern for making architectural governance enforceable at PR time in an agent-driven SDLC, using open standards, with an audit trail a regulator accepts.

### 3:00 PM–3:15 PM · AI for Quality Hardening Up and Down the Ladder of Abstraction

- Room: Hub 4
- Speakers: Henry Garner
- Track: AI Risk Management & Developer Controls
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1287735

FINOS' OSERA project is an important and timely signal of how seriously the industry should take the risk of AI exploiting software vulnerabilities.

The same capability also cuts the other way: AI is an excellent bug hunter, and bugs exist at many levels of abstraction. The kind you find depends on the level you are working at. Hunt at the level of syntax and you catch syntax bugs, while the deeper weaknesses in a system's design stay hidden.

AI works better when it has more than raw source to reason about. Henry will show how to create additional representations of your code, from behavioural summaries to code property graphs.

He'll highlight the recent research, together with open source tools and principles his team has applied at scale inside a large financial institution to harden software quality, and catch bugs hiding in brittle code, fragile designs and imprecise domain logic.

He'll also talk about the approaches that didn't work so well, and the unexpected challenges faced along the way.

### 3:25 PM–4:00 PM · From Open-Source Project to Enterprise Product: The NatWest Fluxnova Journey

- Room: Hall 1
- Speakers: Riyaz Patel
- Track: Fluxnova Con - Fluxnova Core & Architecture
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294701

This talk explores how NatWest has applied product management disciplines to turn Fluxnova from an open-source project into a sustainable enterprise capability. It will cover how we define its role, prioritise investment, enable adoption, create reusable engineering patterns and connect community development to internal business outcomes. The session will show why treating open source as a product improves adoption, strategic control, engineering reuse and long-term value.

### 3:25 PM–4:00 PM · Fluxnova: Enterprise Performance & Camunda 7 Compatibility

- Room: Hub 1
- Speakers: Ryan Johnston, Rob Stevens
- Track: Fluxnova Con - Fluxnova Enterprise Case Studies
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294779

Organizations evaluating a migration from Camunda 7 to Fluxnova often ask these questions:

- Will it perform at enterprise scale?
- Is it truly a drop-in replacement?
- What does a production deployment look like?This session answers those questions by walking through a real-world performance and deployment effort performed using Fluxnova on AWS.

We'll present the benchmarking methodology, summarize the resulting enterprise-class performance characteristics, discuss how Fluxnova maintains compatibility with existing Camunda 7 applications, and examine the AWS deployment architecture used during testing.

Beyond the benchmark numbers themselves, attendees will leave with a practical reference architecture that can be adapted for their own production environments, along with lessons learned from designing, deploying, and operating Fluxnova in the cloud.

Whether you're evaluating Fluxnova for a migration or planning a new deployment, this session provides practical guidance for running Fluxnova confidently in production.

### 3:25 PM–3:40 PM · Accelerating AWS Service Approval with Agentic Plugin and FINOS Common Cloud Controls

- Room: Hub 3
- Speakers: Aditi Pendharkar, Ilya Epshteyn, Aryan Desai
- Track: Scaling & Governing AI Workflows
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1296941

Regulated financial institutions spend months approving cloud services through manual security reviews, control mapping, and threat analysis. These workflows are auditable, repetitive, and ripe for agentic decomposition.

We open-sourced an agentic plugin—the Service Approval Accelerator on AWS—that maps cloud service controls against an organization's customized control objectives, including FINOS Common Cloud Controls (CCC). The tool ingests AWS service threat models to enrich control assessments.

Built as a composable MCP-compatible plugin, it allows customers to ingest customized control objectives. It works with any agentic client—Kiro, Claude Code, GitHub Copilot, Codex—giving institutions flexibility to extend it with organization-specific requirements.

In this session, AWS and a bank co-presenter (to be confirmed) will walk through: the decomposition pattern that turns monolithic approval workflows into lightweight agentic modules; how FINOS CCC mappings are consumed and customized; how AWS service threat models feed richer outputs; and results showing reduction from multiple months to 1-2 weeks for service approval.

### 3:25 PM–3:40 PM · Enabling Secure and Compliant Open Source Contributions with Git Proxy

- Room: Hub 4
- Speakers: Juan Escalada
- Track: AI Risk Management & Developer Controls
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1287568

Open Source helps organizations deliver business value, reduce costs, and stay nimble in the face of AI-driven innovation. However, in highly regulated industries such as financial services, direct contribution to upstream projects is often restricted by default.

Git Proxy makes it easier for firms to contribute to open source projects while meeting security, legal and compliance requirements.

Join us in this workshop where we will learn how to use Git Proxy to:

- Apply vulnerability, secret, license and approval checks to every push
- Define who can push, approve, and interact with specific repositories or remotes.
- Provide audit evidence by capturing intercepted Git operations and storing them in your database of choice.
- Build plugins and processors for firm-specific legal, security or compliance requirements.

### 3:45 PM–4:00 PM · From Memory Budget to Cost Per Token: Serving Agentic Traffic with Large Open Weight Models

- Room: Hub 3
- Speakers: Yuchen Fama, Ashish Kamra
- Track: Scaling & Governing AI Workflows
- Labels: Advanced
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295320

When your source code can't leave the perimeter, self-hosting stops being a cost comparison. What's left is a sizing problem, and most people size it wrong because they size it like chat.

A coding agent re-reads an enormous context every turn and writes back very little. The follow-on is where the money is. When every session reopens the same prefix, cache hit rate isn't a metric — it's the invoice.

Prefill is compute-bound, decode is bandwidth-bound. Disaggregate them so one long prefill doesn't stall everyone else's tokens. And a prefix only counts as a hit if it's still resident, which HBM won't do at agent scale — tier KV down to host memory and NVMe, route to the replica holding the blocks, and you trade a recompute you can't afford for a fetch you can.

Fix interactivity at thirty tokens per second per user, measure sustained throughput, and cost per million tokens falls out. We'll show ours alongside frontier API pricing.

We'll walk the deployment on a cluster of H200s and publish the sizing model so you can run your own numbers. Everything is open — weights, manifests, benchmarks, configs, and a guide in the llm-d repo.

### 3:45 PM–4:00 PM · Showing Contributions on VSCode Plugin and a Session on Validating Architecture with CALM

- Room: Hub 4
- Speakers: Rohith Ashok, Shivaji Byrapaneni
- Track: AI Risk Management & Developer Controls
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1297051

We would like to share how Fidelity is augmenting the CALM project by contributing a new VSCode Plugin. In addition Fidelity is using CALM to validate their architecture documents in real time using the CALM schema.

### 4:00 PM–4:30 PM · Break

- Room: Hall 2
- Track: Breaks + Meals + Special Events
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311936

### 4:30 PM–5:05 PM · Fluxnova Agentic - Open Standards, Orchestrated Agents

- Room: Hall 1
- Speakers: Pieter Schutte, Riyaz Patel
- Track: Fluxnova Con - Fluxnova Core & Architecture
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294737

An overview of the Agentic and other Al standards supported by Fluxnova, showcasing how FINOS Fluxnova's deterministic workflow capabilities brings Control, Observability and Audit Traceability to Complex Agentic Workflows.

### 4:30 PM–5:05 PM · One Project, Three Perspectives: What Contribution Looks Like from Every Side

- Room: Hub 1
- Speakers: Jyoti Sahu, Apurva Gandhi
- Track: Fluxnova Con - Fluxnova Enterprise Case Studies
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295332

Most talks about enterprise open source are told from one angle. But there are three very different experiences happening around the same project.

This session brings together three people who all have a stake in Fluxnova but experience it completely differently.
An enterprise engineer who uses Fluxnova but hasn't contributed upstream, sharing why the barrier still feels high and what would actually change that.

An enterprise engineer who actively contributes to Fluxnova, navigating enterprise process on one side and open source community expectations on the other. What it feels like to have your PR reviewed by someone who has no idea why it took three weeks to get internal sign-off.

A community contributor talking about what it's like working alongside enterprise contributors. Do corporate PRs feel different? What do they wish enterprise engineers understood about how open source communities work?
The goal isn't to point fingers. It's the honest conversation that usually doesn't happen because these three people are rarely in the same room.

If you've ever wondered what the person on the other side of your PR is actually thinking, this one's for you.

### 4:30 PM–5:05 PM · Governing the Agentic SDLC: Driving Agentic Development with FINOS CALM

- Room: Hub 3
- Speakers: Matthew Bain, Aaron Searle
- Track: Scaling & Governing AI Workflows
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294558

Agentic coding tools will happily generate confident, syntactically correct, architecturally catastrophic code. In a regulated institution that isn't a bug; it's a risk event. Every bank is solving it the way it once solved SDLC controls: alone, with home-grown guardrails that duplicate effort and drift apart. The new FINOS SDLC Common Controls Catalog gives the industry a shared language for the controls. The missing piece is making them machine-enforceable when the developer is an AI agent. FINOS CALM is the key.

An agent is only as good as its context. CALM expresses your system topology (services, interfaces, channels, pipelines) as a machine-readable model an agent consults before it writes any code. Architecture as code becomes context engineering: specs reference CALM nodes, and agents build not just what you want but how you want it. The same model closes the governance loop: drift happens one reasonable assumption at a time, and CALM conformance checks in CI catch it, producing the evidence the Catalog asks for. This talk walks through a controlled agentic SDLC end to end (model, spec, agent, gate, evidence) and makes the case for building it once, together, in the open.

### 4:30 PM–4:45 PM · Operationalizing Security for AI Systems in Financial Services

- Room: Hub 4
- Speakers: Monica Mock-Sipos
- Track: AI Risk Management & Developer Controls
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294136

As agentic AI systems move into production across financial services, operational trust is shifting from static application logic to dynamic platform-level governance. Traditional security models struggle to manage probabilistic orchestration, autonomous tool use, and multi-cluster workflows.

This presentation examines how Kubernetes-native platforms serve as the enforcement layer for identity, policy, attestation, and telemetry. Key topics include workload identity with SPIFFE and SPIRE, continuous policy mediation via service meshes and OPA/Gatekeeper, software provenance with Sigstore and in-toto, and observability for runtime risk detection. Attendees will explore patterns for governing Model Context Protocol flows, agent delegation, and inference orchestration while addressing DORA, data sovereignty, and supply chain security.

Drawing on real-world Kubernetes and open source implementations, the talk shows how these capabilities reduce attack surfaces, enable auditable agent behaviors, and accelerate secure AI adoption. Participants will gain insights for operationalizing FINOS AI Governance initiatives and building trustworthy platforms that scale with autonomous systems.

### 4:50 PM–5:05 PM · De-Risking Enterprise GenAI: Aligning Software Architecture and Compliance on AI Models Licensing

- Room: Hub 4
- Speakers: Alfonso Cancellara
- Track: AI Risk Management & Developer Controls
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295775

Development teams in financial institutions are moving fast to ship GenAI features, treating repositories like Hugging Face as an endless supply of free tools. However, dropping an "Open Weight" model into an enterprise pipeline isn't like importing standard Open Source code. Deceptive terms and "Openwashing" create legal and operational risks that compliance teams usually catch only right before launch.

This session cuts through the marketing noise to establish a realistic baseline for "Open Source AI" and breaks down how architecture and risk teams can evaluate AI models' openness.

Attendees will learn:
- The structural differences between traditional software and AI assets, and the distinct engineering and compliance hurdles they create for regulated firms.
- How to apply frameworks like the OSI Open Source AI Definition (OSAID) to assess true openness before integrating AI models into service platforms.
- How to spot deceptive marketing around "Open Weights" and analyze the operational risks of hidden license triggers or field-of-use bans.

### 5:15 PM–5:50 PM · Agents on a Leash: Deterministic Agentic AI for Financial Services

- Room: Hall 1
- Speakers: Aric Rosenbaum, Harish Malavade
- Track: Fluxnova Con - Fluxnova Core & Architecture
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1292955

Large Language Models (LLMs) offer powerful reasoning and automation capabilities, but their probabilistic nature conflicts with the determinism, explainability and auditability required in financial services. This session presents a practical architectural pattern for agentic AI: LLMs as bounded cognitive components orchestrated by BPM-based workflow engines, such as Fluxnova.

Rather than deploying autonomous agents as opaque black boxes, this approach embeds LLMs within explicit and versioned business process models. BPM orchestration governs control flow, approvals, escalation paths, exception handling, and audit checkpoints, while LLMs are invoked for well-scoped tasks such as document extraction, classification, summarization and recommendation generation. The result is agentic behavior that is powerful yet constrained, flexible and governed.

Every outcome can be traced through a BPM execution graph, showing inputs, policies applied, LLM interactions, and human-in-the-loop decisions. We illustrate this pattern in the context of a financial use case to demonstrate how institutions can safely scale agentic AI while meeting regulatory, risk, and audit expectations.

### 5:15 PM–5:50 PM · Self-Describing by Design: BPMN as the Orchestration Standard for Agentic AI

- Room: Hub 1
- Speakers: Chris Miller
- Track: Fluxnova Con - Fluxnova Enterprise Case Studies
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295884

AI agents need discoverable tools, bounded autonomy, and an audit trail — properties BPMN has standardized for two decades. Because BPMN processes are self-describing, with typed inputs, documented activities, and explicit boundaries, they map naturally onto agentic patterns: processes become tools agents can discover and invoke via MCP, while ad-hoc subprocesses give an LLM room to plan and act inside governed, observable process scopes. This talk explores why BPMN's constructs fit agentic orchestration so well, demonstrated with Fluxnova, the FINOS-hosted open source process engine — agentic workflows your auditors can live with.

### 5:15 PM–5:30 PM · Benchmarking Fluxnova for Financial and Agentic Payment Workflows

- Room: Hub 2
- Speakers: Phillip Eng
- Track: Fluxnova Con - Fluxnova Architecture & Multi-Agent
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295851

Fluxnova needs a repeatable way to detect performance regressions and test financial workflows under load. Its current performance suite provides a useful base, but it lacks a standard test environment, JVM microbenchmarks, financial reference workloads, and release-over-release reporting.

This session proposes a phased, community-led benchmark program. First, define the environment, baselines, metrics, and regression thresholds. Next, add JMH microbenchmarks, embedded and REST tests, database and failure tests, and synthetic capital-markets, payment, and agentic-payment workflows.

The agentic-payment workload will test delegated authority, spending limits, payment initiation, retries, duplicate suppression, timeouts, and audit records. Results will cover latency percentiles, throughput, resource use, database cost, recovery, and correctness.

Attendees will leave with a benchmark structure, an initial workload list, and a contribution plan. The goal is reproducible evidence, not a maximum TPS claim.

### 5:15 PM–5:50 PM · Governance, Controls, & Architecture

- Room: Hub 3
- Speakers: Karl Moll
- Track: Scaling & Governing AI Workflows
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1296248

Karl Moll, technical project advocate at FINOS, explains how FINOS is collaborating across firms and projects to build trust in AI systems for highly regulated industries by connecting governance controls to architecture and deployment. He highlights the problem of many siloed AI governance frameworks with little guidance for operationalization, then outlines a three-project approach: the FINOS AI Governance Framework, Common Cloud Controls, and FINOS CALM. Together, these enable reference architectures, shared compliant patterns, faster compliance review, and continual compliance by ensuring deployed systems match threat-modeled designs. This talk will also explore other FINOS projects (such as Fluxnova) which

### 5:15 PM–5:30 PM · Governance as Simulation: Evaluating AI Governance Risks and Mitigations with Agent-Based Modeling

- Room: Hub 4
- Speakers: Jiaman Li, Ning Wang, Yang Wang
- Track: AI Risk Management & Developer Controls
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295287

Financial institutions increasingly need to evaluate agentic AI systems before production, but AI governance frameworks are usually applied as static checklists, which are harder to envision how the AI governance framework would be applied in real financial institutional environment.

This talk introduces a prototype agent-based modeling environment that translates FINOS AI Governance Framework risks and mitigations into configurable simulation experiments. Users can define a financial-service workflow, select AI agents and human roles, enter deployment context such as model version, hardware, software, data access, orchestration, and approval rules, then choose risks and mitigation controls to test. The simulator runs counterfactual scenarios, such as data drift, authorization bypass, model misalignment, infrastructure failure, or compromised tools, and compares outcomes including policy violations, detection time, operational delay, human workload, customer harm, and resilience. The goal is to demonstrate how “governance as simulation” could complement governance as documentation and governance as code, while creating a foundation for a future open-source FINOS project.

### 5:35 PM–5:50 PM · Blending Determinism and Non-Determinism in Financial Workflows

- Room: Hub 2
- Speakers: Tom Stavert
- Track: Fluxnova Con - Fluxnova Architecture & Multi-Agent
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295769

As financial institutions increasingly experiment with AI agents, they face a fundamental challenge: how can non-deterministic systems be safely incorporated into business processes that must remain auditable, explainable, and compliant with regulatory requirements?

The industry is often presented with a false choice between traditional deterministic workflows and autonomous agents. In practice, the most effective solutions combine both approaches. Deterministic workflow orchestration provides structure, governance, and control, whilst agentic components introduce flexibility, adaptability, and intelligent decision-making where it adds the greatest value.

This session explores architectural patterns for blending deterministic and non-deterministic execution within financial workflows. Using the open-source workflow orchestration platform Fluxnova as a practical example, we examine where agentic behaviour can be safely introduced, and how workflow orchestration can provide the guardrails required in regulated environments.

Attendees will leave with a framework for designing business processes that balance innovation with governance, enabling the responsible adoption of AI agents.

### 5:35 PM–5:50 PM · Who's Checking the AI? SDLC Controls for Agentic Coding Pipelines

- Room: Hub 4
- Speakers: Alex Kantor
- Track: AI Risk Management & Developer Controls
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1281022

AI agents can now write, review, and merge code. That means signatures come from bots, reviewers are LLMs, and ticket approvals happen faster than any human can read them. The compliance controls we relied on when humans wrote every line, things like code review, ticket linkage, test evidence, and deployment approvals, weren't designed for that.

This talk shares what we learned building an end-to-end agentic coding pipeline against the FINOS SDLC Controls Framework. We'll cover which controls held up, which needed rethinking, where facts had to be separated from judgement, and how compliance-as-code turned the audit trail from a lagging artefact into a merge gate.

The focus is on practical, transferable patterns: fingerprinting tickets so agents can't retroactively change what they were told to build; running multi-model review so a single LLM can't silently pass its own work; making control decisions explainable to an auditor without a human in every loop.

Aimed at engineering leaders and compliance teams grappling with AI-generated code in regulated finance.

### 5:50 PM–7:00 PM · Networking Reception + Booth Crawl

- Room: Hall 2
- Track: Breaks + Meals + Special Events
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311971

## Thursday, November 5, 2026

### 8:00 AM–5:50 PM · Registration & Badge Pick-up

- Room: 2nd Floor Entrance
- Track: Registration & Badge Pick-up
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311940

### 9:00 AM–10:30 AM · Keynote Sessions To Be Announced

- Room: Hall 1
- Track: Keynote Sessions
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1324978

### 10:40 AM–11:10 AM · Break

- Room: Hall 2
- Track: Breaks + Meals + Special Events
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311937

### 10:40 AM–3:50 PM · Sponsor Showcase

- Room: Hall 2
- Track: Sponsor Showcase
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311974

### 11:10 AM–11:45 AM · Know Your Codebases - Using CALM to Represent Software Estates

- Room: Hall 1
- Speakers: Denis Urusov, Paul Groves
- Track: AI Governance, Risk & Security
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1297049

A presentation on Citi's CALM adoption

### 11:10 AM–11:25 AM · From HPC to AI: Building an Open Compute Fabric for Financial Services

- Room: Hub 1
- Speakers: James Calise
- Track: AI Implementation & Engineering
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1317756

As financial institutions move from traditional HPC workloads to increasingly compute-intensive AI, they need infrastructure that delivers performance without sacrificing openness and portability. This session explores how an open compute fabric can bridge HPC and AI, enabling financial institutions to modernize infrastructure, support hybrid environments, and accelerate innovation. We’ll examine how open technologies and cloud infrastructure can provide the performance, interoperability, security, and flexibility required for the next generation of financial services workloads.

### 11:10 AM–11:45 AM · From Consumption to Contribution: Insights from the 2026 State of Open Source in Finance

- Room: Hub 2
- Speakers: Tosha Ellison, Hilary Carter
- Track: Cultivating the Culture & Business Strategy
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1296615

Following the official release of the 2026 State of Open Source in Financial Services Report, this session will break down the report's overarching findings, unpack emerging industry trends, and explore how global financial institutions are maturing their open source strategies.

We'll cover the report findings, including:
-Strategic Value, ROI & Contribution: What is driving adoption, how leading teams are demonstrating clear ROI, and why firms are stepping up to actively contribute to and sustain critical infrastructure.
-The AI Frontier & Developer Workflows: How the rise of open LLMs, AI coding tools, and autonomous agentic workflows are shaping software development, governance, and compliance.
-Operational Resilience & Legacy Debt: Navigating tightening regulatory standards, supply chain security, and the collective effort to eliminate redundant maintenance and legacy technical debt across the industry.
-Open Standards & Systemic Interoperability: How shared data models, code-based policies, and open standards can deliver market-wide alignment and reduce mutual costs.

### 11:10 AM–11:45 AM · Data Management Strategies for Implementing AI and the FINOS CDM

- Room: Hub 3
- Speakers: Thomas Healey, Pavan Palle
- Track: Platform Engineering & The Connective Tissue
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295073

Capital-markets applications operate across numerous systems and financial products, each representing data through different and often inconsistent business semantics. Without a common semantic reference, introducing AI can amplify this ambiguity, making AI-generated results less reliable for processes that require deterministic outcomes. The FINOS CDM can provide that reference: supporting mappings between application data models, supplying business context to AI models, and enabling AI-generated outputs to be validated against governed business concepts and firm policies.
The speakers will present practical strategies for adopting this approach across the enterprise, covering integration architecture, semantic mapping, data ownership, model extensions, validation, and governance. Attendees will leave with a framework for deciding where the CDM should sit within their enterprise architecture and how it can support more reliable, explainable, and governable AI.

### 11:10 AM–11:25 AM · Preparing Banks for Quantum Computing Risks: Open Source Strategies for Post-Quantum Readiness

- Room: Hub 4
- Speakers: Mark Paulsen
- Track: Hot Topics
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1276100

The Linux Foundation, FINOS, and others in the open source community have already created strategies and patterns that are enabling regulated enterprises to manage the increased open source and software supply chain scrutiny of regulators and auditors.

Strategies and patterns that enable an open discovery and transparency of shared risks across the core ecosystem, and the ability to leverage regulations to drive positive change, can also be applied to quantum-readiness journeys.

### 11:30 AM–11:45 AM · PROV and SHACL: The Two Standards That Make Agent Code Auditable

- Room: Hub 4
- Speakers: Lee Faus
- Track: Hot Topics
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1278803

Financial services firms can't take an agent's word for what it did. DORA and the EU AI Act require evidence a regulator's tooling can walk without your team reconstructing it by hand. This talk covers the two standards that make that possible.
W3C PROV gives us provenance vocabulary examiners already recognize: every agent turn is an activity, associated with an agent acting on behalf of a person, recording what it used and what it generated. SHACL is the gate deciding what's allowed into that chain, written in the same RDF the graph serializes to.
We'll show how Atomic treats both as policy, not documentation. PROV activities are generated automatically at every agent turn, so provenance isn't something a team bolts on after the fact. SHACL shapes are the enforcement layer itself: a change that doesn't satisfy the shape doesn't transition to done, full stop. The gate doesn't grade whether a decision was good. It enforces that the decision, the author, and the evidence all exist and resolve to real nodes before anything ships.

### 11:55 AM–12:30 PM · Zero Trust AI Across the Capital Markets Compute Chain

- Room: Hall 1
- Speakers: Andrew Martin, Erick Bourgeois
- Track: AI Governance, Risk & Security
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295679

Regulated systems depend on combinatorial trust: software assembled from third-party dependencies, workloads deployed across shared grids, and AI agents trusted to operate on sensitive systems.

Without continuity of security context, attested software could still run with excessive privileges, just as isolated workloads may delegate undue authority to an agent.

In this talk, we zero out implicit trust using contextual, audit-ready cryptographic metadata.

Drawing on production implementations of capital markets grid compute with FINOS 5-Spot, and supply-chain and AI-runtime hardening, we follow one workload from source to production and show how to:

- Prove what was built, by whom, and from which dependencies
- Verify software before execution and bind it to cryptographic workload identities
- Schedule shared compute using isolation and policy rather than inherited trust
- Invoke AI agents with zero standing authority, granting short-lived permission for a defined action
- Connect build, runtime, and agentic evidence into one audit trail

### 11:55 AM–12:30 PM · ISDA AI Agents for CDM & DRR

- Room: Hub 1
- Speakers: David Lee
- Track: AI Implementation & Engineering
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1286215

This session introduces the AI skills and agents ISDA has built for the Common Domain Model (CDM) and Digital Regulatory Reporting (DRR), and shows them running live. CDM and DRR are open-source standards that express financial products and regulatory reporting logic as machine-executable code. Producing and maintaining that code requires expertise across standards, the toolchain, and the underlying regulation. We'll demonstrate agents that understand both CDM and DRR and generate correct implementations for real tasks: modeling financial products and events in CDM, reviewing and interpreting regulatory text, mapping it to the CDM class hierarchy, detecting coverage gaps, producing DRR reporting logic, and supporting analytics on the resulting data. Every output is grounded in a governed knowledge base, so it stays traceable to an authoritative source.

### 11:55 AM–12:30 PM · Mapping from Native Data to CDM - A Stepwise Guide

- Room: Hub 3
- Speakers: Paul Hands
- Track: Platform Engineering & The Connective Tissue
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1286066

Companies already have internal data models, that are used intrinsically and extrinsically in their day to day processes. "Ripping out and starting again with CDM" is both unrealistic, and usually unpalatable. So the problem becomes one of enough CDM adoption to be production ready, while preserving internal processes where necessary. This is going to involve systems communicating to each other in mapped frameworks.

In this session, Dr Paul Hands will begin by expanding on how Ark 51 managed to adopt CDM to production in a manner of months, with pointers on how other companies can follow suit, covering topics like "what do companies thinking about CDM adoption need to consider before getting started on a technical and data sanity level?". The second half will consist of the audience being taken on a slighter deeper dive of an example of how to begin building a mapper internally to go from an in house data structure to CDM format.

### 11:55 AM–12:10 PM · Fluxnova: Reimagining Financial Services Process Orchestration Across Systems, Humans, and AI

- Room: Hub 4
- Speakers: Harish Malavade
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1283325

Journey on the rich features and functionalities that Fluxnova offers for automation, orchestration and acceleration of end to end business processes. This presentation will also highlight how fluxnova integrates with Systems, Humans and AI.
Systems : APIs, applications, microservices, event streams
Humans : advisors, phone reps, operations teams, compliance officers
AI : copilots, agents, decision engines, automation services

### 12:15 PM–12:30 PM · Driving K8/Open Shift Compute Estates via Scaler

- Room: Hub 4
- Speakers: Ritesh Bansal, Jason Kincl
- Track: Hot Topics
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295874

Financial computing is a constant balancing act between fixed on-prem hardware and the sudden compute spikes needed for market close, risk runs, or quantitative models. Getting distributed tasks to run smoothly across both on-premises OpenShift clusters and cloud infrastructure can quickly become an infrastructure headache.

In this talk, we’ll dive into a new Kubernetes backend integration for OpenGRIS Scaler designed to solve that exact problem.

By adding native Kubernetes and OpenShift support directly to Scaler, teams can now seamlessly run high-throughput Python workloads across their existing containerized environments—no custom grid orchestration or code rewrites required. We’ll show how this integration makes it simple to maximize underutilized on-prem hardware first, while still keeping the option to burst into the cloud when demand surges.

We’ll walk through the architecture, share real-world setup patterns, and demonstrate how quant and dev teams can keep their workflows simple while safely scaling grid jobs across hybrid infrastructure.

### 12:30 PM–2:00 PM · Lunch

- Room: Hall 2
- Track: Breaks + Meals + Special Events
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311939

### 2:00 PM–2:35 PM · An Open Source Blueprint for Financial-Grade Kubernetes: Morgan Stanley, Microsoft, and FINOS CCC

- Room: Hall 1
- Speakers: Yash Gandhi, Jack Tracey
- Track: AI Governance, Risk & Security
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294746

Financial institutions build Kubernetes platforms by turning shared security, regulatory and operational requirements into bespoke code. This raises costs, slows adoption and makes
controls harder to prove.

Cloud-native threats target SBOMs, workload identities, management interfaces, container images and configuration weaknesses. Static guidance and manual controls cannot keep pace. Institutions need a maintained, testable blueprint with secure defaults and automated validation.

Morgan Stanley and Microsoft are collaborating on an open source Terraform blueprint for hardened, enterprise-ready Azure Kubernetes Service (AKS) cluster. Intended as an Azure Verified Module, it will offer an adoptable, extensible foundation. Mapping it to FINOS Common Cloud Controls (CCC) will connect shared requirements to deployable configurations and automated evidence.

This session will show how Financial-Grade requirements map to Kubernetes capabilities, standardized Terraform and pipeline validation; how reusable patterns can enhance Microsoft's AKS feature engineering; and how shared engineering can replace bespoke hardening and move compliance from documentation to automated delivery.

### 2:00 PM–2:35 PM · Agentic AI and the Future of Software Development

- Room: Hub 1
- Speakers: Colin Eberhardt
- Track: AI Implementation & Engineering
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1281567

AI is rapidly changing the nature of software development. In just a few years it has moved from autocomplete, to pair programmer, to workflow participant, and now toward autonomous contributor. This talk explores what that shift means for developers, teams, and organisations as the cost of generating code falls dramatically.

The hard part of software development is moving away from writing code and toward deciding what should be built, shaping the systems that produce it, and validating that outcomes are correct. Practices such as code review, upfront specification, team structure, and standardised process all need to evolve for a world where AI can generate more software than humans can manually inspect.

This session offers practical principles for the agentic era: shaping systems over writing code, product thinking over delivery thinking, validating outcomes over reviewing code, fast feedback over upfront certainty, and continuous transformation over one-time change.

### 2:00 PM–2:35 PM · The Border Is Porous: What Open Source and InnerSource Can Learn from Each Other

- Room: Hub 2
- Speakers: Peter Smulovics, Mimi Flynn, Elspeth Minty, Mark Paulsen, Rob Moffat
- Track: Cultivating the Culture & Business Strategy
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1293920

Open source and InnerSource are often treated as two distinct operating models: one facing the outside world and the other focused within the enterprise. In reality, the most interesting challenges (and opportunities) exist at the border between them.

This panel brings together industry practitioners working across open source, InnerSource, OSPOs, engineering governance, and enterprise technology to explore what each model can learn from the other. We will discuss how open source practices such as transparent decision-making, contributor pathways, maintainership, and community building can strengthen internal collaboration, and how enterprise InnerSource experience can help organizations become better open source participants.

The discussion will also tackle the difficult questions: When should an organization contribute upstream, maintain an internal extension, or fork? What processes, controls, incentives, and organizational structures unintentionally prevent effective InnerSource? And how can companies build a continuum where code and ideas can move more naturally between internal and external communities?

### 2:00 PM–2:35 PM · TraderX is now Ready For Business

- Room: Hub 3
- Speakers: Dov Katz
- Track: Platform Engineering & The Connective Tissue
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1282024

After adopting spec base development, we were finally able to solve a three year-old challenge and now have 14 different variations of our TraderX repo for developers to interact with an integrate with. This will allow for comprehensive learning in multiple phases of the life-cycle of this project and rapid innovation, by introducing more nodes to our learning graph. This makes the perfect hackathon project, at the perfect time, at the crossroads of major FINOS portfolio growth and Agentic developer tools. Come learn how you can get set up in minutes and how this can help you on your FINOS project journey.

### 2:00 PM–2:15 PM · The Software Supply Chain Isn't Being Hacked. It's Being Manipulated.

- Room: Hub 4
- Speakers: Brian Fox
- Track: Hot Topics
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295194

For years, software supply chain attacks were about getting malicious code into repositories.

Today they're about getting developers to choose it.

AI has dramatically accelerated how software is discovered, evaluated, and adopted. Attackers have responded by targeting the decision-making process itself through impersonation, developer-focused malware, and attacks designed to influence dependency selection before software ever reaches production.

This talk presents research into how software supply chain attacks have evolved from mass distribution into precision influence campaigns and why traditional security models that focus on vulnerabilities after software has been chosen are increasingly too late.

The next frontier isn't securing code. It's securing how software gets chosen.

### 2:20 PM–2:35 PM · OpenGRIS: Scaling Financial Compute Across On-Premise and Multicloud Resources

- Room: Hub 4
- Speakers: Travis Liles
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294924

Using financial workload examples, the talk will examine how an institution can use OpenGRIS to submit and scale jobs across local machines, bare metal, HPC environments, and multiple clouds. It will cover task decomposition, capability-based allocation, policy-driven scheduling, worker-manager patterns, and the operational visibility required for a regulated environment.
Attendees will gain a practical view of how an open scheduling standard can reduce infrastructure coupling, improve compute utilization, and let teams scale existing Python analytics workloads without rewriting them for each execution platform.

### 2:45 PM–3:20 PM · The Last Mile of Cloud Controls: Using AI to Operationalize FINOS CCC

- Room: Hall 1
- Speakers: Maxime Coquerel
- Track: AI Governance, Risk & Security
- Labels: Beginner
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294134

Adopting an open control framework is only the beginning. The difficult last mile is applying it consistently to real cloud architectures inside a regulated financial institution.

This session presents a grounded AI control-advisor pattern based on practical experience with FINOS Common Cloud Controls. Starting from an architecture description, the workflow identifies relevant capabilities, retrieves CCC threats and controls, maps them to private internal requirements, and generates traceable recommendations, evidence requests, policy-as-code opportunities, and questions for missing context.

A live demonstration compares a manual review with the AI-assisted workflow, highlighting where AI accelerates analysis, where mappings remain ambiguous, and where human judgment and risk ownership remain essential.

Attendees will leave with a reusable pattern for architecture reviews, control validation, and policy-as-code without exposing confidential policies or delegating risk acceptance to AI.

### 2:45 PM–3:20 PM · Look to AI for your Financial Reporting Needs in an AI World

- Room: Hub 1
- Speakers: Kathy Gibbs
- Track: AI Implementation & Engineering
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1293036

The enterprise landscape is currently navigating an "AI Inflection Point" where traditional data architectures struggle to meet the velocity and complexity required for autonomous AI agents and workflows. Organizations frequently fall victim to the "Frankenstein Stack"—a fragmented infrastructure of separate vector databases, complex ETL pipelines, and third-party orchestration frameworks that often results in high TCO, significant security risks, and project failure. MariaDB Server with Grid Gain, an in-memory computing platform, serves as a robust foundation for rapid innovation and testing. In this presentation, Kathy will discuss the way to increase AI-readiness by optimizing distance calculations for high-dimensional vectors and matryoshka embeddings, as well as discussing how RAG (Retrieval-Augmented Generation) applications scale with maximum efficiency and zero latency penalty. We can then use these processes to create reports and find fraud detection.

### 2:45 PM–3:20 PM · From Tokens to Tokenomics: Optimizing AI Costs with Open Source

- Room: Hub 2
- Speakers: Aric Rosenbaum, Jennifer Bowman
- Track: Cultivating the Culture & Business Strategy
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295640

As organizations scale their AI initiatives, the hidden costs of foundational models can quickly become a barrier to innovation. "From Tokens to Tokenomics" explores how businesses can move beyond the "one-size-fits-all" approach by implementing a hybrid architecture strategy. This session provides solutions patterns to identify the right architecture for the right use case, balancing performance, governance, cost and efficiency.

We will introduce a maturity model for AI adoption, demonstrating how enterprises can adopt new hybrid architectures including closed-weight models and open-weight models to optimize internal infrastructure for specific use cases. Through concrete use cases, attendees will learn how to design flexible, high-performance architectures that deliver measurable business value while maintaining operational control and governance. Whether you are an executive planning your mid-year budget, an AI Platform Engineer, an AI Engineer, optimizing or consuming inference. session offers the quantitative, real use cases to bring insights to build a scalable and efficient AI stack.

### 2:45 PM–3:20 PM · Fulfilling the TraderX Vision

- Room: Hub 3
- Speakers: Judah Diament, Yaakov Seif, Alex Neugroschl
- Track: Platform Engineering & The Connective Tissue
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294757

TraderX's Goals are to enable quick construction of scenario-specific trading systems via radical reuse and to provide an open trading system on which to demo new components. Our students efforts demonstrated TraderX's achieving both goals and highlight a rich set of future possibilities.

One student built a new set of TraderX states which implemented common functional & non-functional requirements of production trading systems. Functional features added include: historical tick store, pre-trade risk, T+N & reconciliation for post-trade, limit-order book, & order matching. Non-functional features added include: low-latency matching engine via LMAX disruptors (~6M ops/s throughput), FIX 4.4 order entry, scalability & consensus via Aeron & Raft, journal durability, deterministic replay, TCA benchmarks. All deployable as local containers or on GKE.

A second student is building a market risk engine using Python & JAX to identify the optimal balance between accelerating risk engines via AI chips (e.g. Google's TPU) and the numeric precision required for risk, which was then integrated with the enhanced TraderX.

### 2:45 PM–3:00 PM · What Got Us Here Won't Get Us There: Unleashing Breakthrough Use Cases with Tokenization

- Room: Hub 4
- Speakers: Eran Barak
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1293046

The infrastructure most banks run today was built for a different era of cash and batch cycles, not for digital assets, programmable money, agentic transactions, or settlement outside banking hours. The demands on that core are changing quickly: customers and counterparties increasingly expect to transact with tokenized deposits, stablecoins, and digital assets safely and within existing compliance frameworks. No institution will replace its core overnight.

This session makes the case that tokenized deposits are a practical entry point banks are taking for modernization—extending existing systems rather than replacing them—and that over time this new infrastructure carries a growing share of the business. Eran Barak will walk through emerging institutional use cases, such as rapid securities settlement, conditional escrow, automated regtech, agentic payments, the gap between today's rails and tomorrow's requirements, and how we could make the transition possible. The talk closes with the interoperability standards work underway within Linux Foundation Decentralized Trust (LFDT), where financial institutions are collaborating to connect their systems over the rails of the future.

### 3:20 PM–3:50 PM · Break

- Room: Hall 2
- Track: Breaks + Meals + Special Events
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311931

### 3:50 PM–4:05 PM · Innovation vs. Risk: Open Source, IP Strategy, and Governance in Financial Services

- Room: Hall 1
- Speakers: Keith Bergelt
- Track: AI Governance, Risk & Security
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1273667

As financial institutions and FinTech companies rapidly scale AI-driven, cloud-native solutions, Open Source Software (OSS) is core to their modern infrastructure. However, accelerating innovation introduces complex challenges: software supply chain security, AI governance, OSS licensing obligations, patent assertion risks and heightened regulatory scrutiny.

How do leading financial institutions stay competitive while safely managing these risks?

Led by Keith Bergelt, CEO of the Open Invention Network, this session explores the critical intersection of patent strategy and OSS growth. Through real-world case studies, attendees will learn how top financial firms are evolving their OSPO and governance frameworks to protect and empower their technology investments.

Key takeaways:

•Strategies to navigate the intersection of OSS licensing, patent risk, and Intellectual Property (IP) management.
•Best practices for evolving OSPO frameworks to address IP risk
• Frameworks for balancing open-source collaboration with legal considerations
• Learn about community-driven defense models that support Open Source growth & innovation

### 3:50 PM–4:05 PM · Who Owns AI in Production?

- Room: Hub 1
- Speakers: Preeti Gupta
- Track: AI Implementation & Engineering
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294986

Moving an AI solution into production is no longer just a data science or engineering challenge. As AI systems evolve through model updates, prompt changes, and shifting business contexts, ownership can become fragmented across engineering, platform, security, risk, and business teams. Who is accountable when AI behavior changes in production?

This session introduces an AI Production Readiness Framework from an Enterprise Architecture perspective. Attendees will learn how to define clear ownership, establish continuous evaluation, and apply controls such as backtesting, shadow deployments, drift monitoring, and release governance for AI and agentic AI systems. Rather than focusing on model development, the session addresses what enterprises need to operate AI safely, reliably, and at scale.

Using lessons from regulated financial services, this talk provides a practical blueprint for moving beyond AI pilots to production-ready AI.

### 3:50 PM–4:05 PM · There's no CVE for Burnout

- Room: Hub 2
- Speakers: Brian Warner
- Track: Cultivating the Culture & Business Strategy
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295880

By this point most financial institutions have mature processes for managing open source licenses and vulnerabilities, and both are well served by commercial tools. However, a third category of risk is harder to measure: the viability of the projects themselves.

License changes and public community disputes are visible events. The slow decline of a small, widely-reused project usually isn't. Would you know if the maintainer of a library six levels deep in your dependency tree was being overwhelmed? Would you know if a single organization was responsible for keeping a critical dependency alive? And what could you do about it if you did?

This session presents a practical method for spotting trouble deep in the stack: start from your data, rank what is actually critical, then read the community health signals that tend to precede trouble. Brian will share some examples of how Fidelity puts this into practice. The result is a need-based approach to contribution that directs engineering effort toward the projects your software supply chain actually depends on.

### 3:50 PM–4:05 PM · The Vulnerability Race is Changing. Is Open Source Ready?

- Room: Hub 4
- Speakers: Dan Lorenc
- Track: Hot Topics
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294821

Open source runs the global financial system, and AI just changed how quickly it can be attacked. Frontier AI models can now discover and chain exploitable vulnerabilities in mature open source software in hours–a task that used to take skilled researchers weeks. Remediation hasn't kept pace: once a vulnerability is disclosed, attackers can weaponize it within days, often faster than institutions can test and deploy a fix. The result is a widening gap between attack speed and defense speed. Closing it requires coordination, not faster individual response.

In this panel, Dan Lorenc, alongside 2-3 members of the Athena coalition, will explore why this gap can't be closed by any one institution alone. Using Athena–an industry coalition coordinating AI-era vulnerability response–as a working model, panelists will discuss how technology companies, financial institutions, and infrastructure providers can shrink remediation time and protect the open source infrastructure the global economy runs on. Attendees will leave with concrete insight into the governance, operations, and cross-industry coordination needed to prepare for AI-driven attacks that outpace traditional patch cycles.

### 4:10 PM–4:25 PM · Governing Agentic AI in Financial Services: Practical Methods for Navigating Responsible Innovation

- Room: Hall 1
- Speakers: Swapnil Dambe
- Track: AI Governance, Risk & Security
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1293184

As financial institutions adopt Agentic AI, the challenge is not just about whether the technology works. It's also about how to deploy it responsibly within existing governance frameworks, regulatory expectations, and internal risk policies.

This lightning talk explores practical methods for integrating governance into every stage of the AI lifecycle, enabling organizations to innovate while maintaining compliance and operational resilience. Drawing on real-world experience implementing governance for emerging technologies in regulated environments, the session will examine how organizations can assess AI risks, establish decision frameworks, define accountability, and operationalize policy requirements without slowing innovation.

The presentation will also highlight how open-source initiatives such as the FINOS AI Governance Framework (AIGF) provide reusable guidance that helps financial institutions adopt AI consistently and responsibly.

Participants will leave with actionable governance practices that can help accelerate AI adoption while building trust with regulators, executives, risk teams, and customers.

### 4:10 PM–4:25 PM · The AI Platform Engineer’s Playbook: Operationalizing Agentic Workflows at Scale with Gateway

- Room: Hub 1
- Speakers: Valentina Rodriguez Sosa, Chris Ferreira
- Track: AI Implementation & Engineering
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1291413

As organizations move Agentic AI initiatives from experimentation to production, the challenge shifts from "how to run a model" to "how to provide AI as a reliable, governed service." Fragmented AI deployments often lead to uncontrolled infrastructure costs, security silos, and inconsistent developer experiences.
This presentation explores how to operationalize Agentic AI on a hybrid cloud foundation, aligned with the FINOS AI Governance Framework. We will showcase how to integrate an AI Gateway (leveraging Kuadrant/Envoy and Authorino) to enforce granular RBAC, rate limiting, and cost-tracking policies, transforming abstract FSI governance requirements into machine-readable, policy-as-code enforcement for Platform Engineering teams to bring GitOps approach into scalable solution. Beyond gateway-level controls, we will dive into securing the agentic stack itself: implementing SPIFFE/SPIRE to provide cryptographically verifiable identities for AI systems, eliminating static secrets. Finally, we will demonstrate how platform teams can bridge developer agility with rigorous production standards, building an enterprise-grade AI hub that adheres to industry-wide open standards.

### 4:10 PM–4:25 PM · The Anatomy of Control

- Room: Hub 2
- Speakers: Toby Weston
- Track: Cultivating the Culture & Business Strategy
- Labels: Any
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294435

We have been working on the FINOS SDLC Common Controls standards project to define the common set of risks and mitigation common to all software delivery.

This session goes one level deeper to discuss the mechanics and skeletal structure of controls when implementing. We talk about Rego as the core to policy as code and how evaluation via OPA can connect disparate systems to pass trusted attestations to the expression engine.

This all coalesces in a unified evidence format translating policy-as-code to audit readable natural language. We take the audience through a worked example of a Baker making cupcakes that must be demonstrably allergen free.

### 4:10 PM–4:25 PM · Handling Speed Safely: Why Software Controls Are The Product

- Room: Hub 3
- Speakers: Aaron Searle
- Track: Platform Engineering & The Connective Tissue
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1265145

In this session we will discuss taking an engineering approach to the evolution of and management of software controls within regulated entities. Enabling greater speed while maintaining and even improving safety along the way.

### 4:10 PM–4:25 PM · Open Resource Broker: A Unified API for Cloud Capacity Provisioning in HPC

- Room: Hub 4
- Speakers: Flamur Gogolli
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295563

Provisioning compute capacity in the cloud should be as straightforward as defining what you need, not where and how to get it. Yet HPC engineers face inconsistent, provider-specific APIs, incompatible provisioning models, and duplicated integration logic across schedulers and clouds. Open Resource Broker (ORB) solves this with a unified, open-source API and abstraction layer for provisioning cloud capacity anywhere.

ORB integrates seamlessly with IBM Spectrum Symphony HostFactory to standardize capacity requests, tracking, and release. Its modular design supports additional schedulers and multiple cloud providers beyond the initial AWS implementation. ORB supports CLI, REST, SDK and MCP APIs for consistent scaling across diverse HPC environments.

We'll demonstrate ORB's architecture, end-to-end provisioning, and resiliency patterns including retries, idempotent operations, and failure recovery. We'll also cover extensibility for new schedulers and cloud APIs.

Built for large-scale financial HPC grids, ORB is now donated to FINOS under Apache 2.0 for open governance. Attendees will learn proven strategies to make HPC capacity management more portable, automated, and sustainable.

### 4:35 PM–4:50 PM · The Missing Control Layer for AI Agents

- Room: Hall 1
- Speakers: Cornelia Davis
- Track: AI Governance, Risk & Security
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1329509

LLMs can deliver enormous value—but their inherent nondeterminism creates real challenges in regulated environments. Building a capable agent is only part of the job. To deploy it with confidence, you also need a controlled execution environment: one that governs tool calls, constrains inputs and outputs through strongly typed interfaces, records a complete history of agent actions, and ensures work can recover rather than being left half-completed.

In this session, we’ll explore the execution layer that turns an agent from a promising prototype into an observable, auditable, and resilient production system. You’ll come away with a better understanding of the operational controls needed to move AI agents from prototype to safe, resilient production systems.

### 4:35 PM–4:50 PM · Governance, Compiled: Turning the AI Governance Framework into Running Controls

- Room: Hub 1
- Speakers: Paul Merrison
- Track: AI Implementation & Engineering
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1294405

The FINOS AI Governance Framework catalogues AI risks and mitigations, but a risk ID in YAML doesn't stop an agent calling a tool it shouldn't, and a mitigation page doesn't produce evidence a supervisor will accept. This talk shows the missing layers, built and working on open source. Decompose: every AIGF mitigation broken into 239 discrete actions, mapped to maturity levels and use-case risk tiers, turning "adopt the framework" into a sequenced roadmap. Enforce: two mitigations compiled into running controls - deterministic inference for AIR-OP-6 (from 16,000+ LLM calls: why temperature zero isn't a control, why the same Basel III capital figure can change with the batch it lands in, and the per-model acceptance test that fixes it, demonstrated live on real Pillar 3 filings) and a human-in-the-loop approval gate enforced at a policy decision point. Evidence: every control decision emits an OpenTelemetry GenAI span and a signed, offline-verifiable receipt, rolled into an evidence pack keyed to AIGF risk IDs and their regulatory crosswalks. Audit evidence produced by the control itself, not reconstructed after the fact — governed AI you can prove, not assert.

### 4:35 PM–4:50 PM · Creating an Enterprise Open Source Standard in a Regulated Financial Institution: Lessons Learned

- Room: Hub 2
- Speakers: Hari Vattappilli
- Track: Cultivating the Culture & Business Strategy
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1279517

Building an Open Source Standard within a large financial institution is much more than writing policy documents... it requires balancing innovation, developer experience, security, legal obligations, regulatory expectations, and operational realities.
This session shares TD Bank's journey in designing and implementing an enterprise Open Source Standard and the governance framework required to support it. Through a retrospective lens, we will discuss how cross-functional teams from Engineering, Security, Risk, Legal, Compliance, Architecture, and the Open Source Program Office (OSPO) collaborated to establish a common approach for open source consumption, contribution, licensing, inventory management, and risk management.
Attendees will gain practical insights into stakeholder engagement, governance design, implementation challenges, organizational change management, and lessons learned while introducing open source controls at scale. The presentation will also highlight what worked, what did not, and what we would do differently if starting again today.

### 4:35 PM–4:50 PM · Bridging On-Chain and Off-Chain Finance: Integrating FINOS CDM with Smart Contracts and DLT Oracles

- Room: Hub 3
- Speakers: Thomas Healey
- Track: Platform Engineering & The Connective Tissue
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295117

This workshop explores how FINOS CDM can bridge traditional financial infrastructure and distributed ledgers. Participants will examine an architecture in which a CDM execution service operates as a computational oracle, converting external observations and off-chain instructions into standardized business events that can be validated and consumed by smart contracts. Through a worked financial-instrument lifecycle, the workshop will evaluate what should execute on-chain, what should remain off-chain, and how identity, trust, state synchronization, privacy, and model versioning can be managed.

### 4:35 PM–4:50 PM · No Prompt Required: AI Workflows on the FDC3 Desktop

- Room: Hub 4
- Speakers: Chris Watson
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1295830

Every AI protocol released in the last eighteen months has been busy inventing infrastructure: how to describe a tool, how to discover what is available, how to ask a human before acting, how to route work between agents. The financial desktop has had all of that for years. FDC3 is not an AI protocol, but as a protocol to put AI on, it is the only mature option on the desk.
This session runs 2026's techniques on that foundation. Small agents join the desktop as ordinary FDC3 applications and listen to the channels the user is already broadcasting on. They work out what is missing, hand work between themselves using intents, and answer by assembling the applications that address it, composed at runtime rather than restored from a saved layout.
Nothing is typed and there is no chat window. The output is a working desktop.
Along the way: why an app directory is a better tool registry than anything the AI protocols have yet, why the intent resolver was a human-in-the-loop approval surface six years before anyone needed one, and the two things FDC3 still cannot do.
Shown live on FDC3 Sail, the FINOS open source desktop agent, using FDC3 for the Web.

### 4:55 PM–5:10 PM · How to Scale Security & Compliance in the Age of AI

- Room: Hub 1
- Speakers: Eddie Knight
- Track: AI Implementation & Engineering
- Labels: Advanced
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1296035

Old defense strategies are working less and new attack patterns are working more — but the ancient principles of cybersecurity have never mattered more. This talk relies on the analysis of multiple data sets to provides listeners with a clear path to success using several emergent tools and guidance from FINOS and the greater Linux Foundation ecosystem.

### 4:55 PM–5:10 PM · Canary Systems for Autoscaling: Safe Experimentation on Shared Compute Infrastructure

- Room: Hub 4
- Speakers: Naman Ahuja
- Track: Hot Topics
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1288376

This talk presents the architecture of a canary/experimentation system for autoscaling shared compute: temporary config overrides with automatic rollback, expired experiment cleanup, CLI-first adoption for auditability, and the state machine that handles edge cases (concurrent deletions, system migration experiments). We'll discuss how this pattern applies to financial HPC grids (OpenGRIS, HTC-Grid) and multi-tenant cloud environments where one bad scaling decision can impact multiple trading desks.

### 5:20 PM–5:50 PM · Closing Keynotes To Be Announced

- Room: Hall 1
- Track: Keynote Sessions
- Link: https://events.linuxfoundation.org/open-source-finance-forum-new-york/program/schedule/?id=1311995

