Reflections on AGNTCon + MCPCon Europe 2026: The best of the big shill?

Reflections on AGNTCon + MCPCon Europe 2026: The best of the big shill?

Juan Caballero, Community Manager at Decentralized Identity Foundation

Last month I had the privilege to represent DIF and the Trusted AI Agents Working Group at AGNTCon + MCPCon Europe 2026 in Amsterdam, a curious kind of trade-show with mostly sponsored content on main stage, swag/demo booths, and endless hallway-track space in a massive convention center in Amsterdam. It was well-attended, somewhat overwhelming, and, at the same time, still somehow cozy and recognizable handmade by a Linux-Foundation org not too much larger than DIF, despite the dollar amounts. This curious tension between massive enterprise deployments and “we’re so early” was palpable in all of the programming, all of the hallway banter, and in every quirky pitch and flyer handed out from the booths: we’re so early, even if mega enterprises are jumping in with both feet.

The mostly sponsored mainstage content was, despite being well-rehearsed and slick and on-topic, wide-ranging and diverse in its foci. For understanding the state of AAIF and MCP, the best starting points were Mazin Gilbert’s professional and comprehensive crash-course on the scope and work of AAIF (which was pitched quite high, to a high-context audience familiar with the ins and outs of corporate open source), Claire Liguori’s pithy explanation of how the newly-stateless MCP can orchestrate massive economies of scale for AWS-scale hyper-hypervisory platforms that can pause and rehydrate agents more like CI processes now, and for the architects thinking at platform-scale, Alpic and Google overviewed the subtle differences between the three developer platforms or “entry points” to MCP.

While these three talks might make frame the core engineering and governance problems at a high level, most of the content on and off the main stage was pitched at the pain points of building an enterprise “agentic platform” (whether internal, external or mixed), with a healthy portion of “buy my product/trust my middleware” woven in. These ranged from the ambitious “everything you need to safely build a platform” (solo.io) to more security and governance focused (obot,) and devex-focused (alpic).

Speaking of developer experience, the “AGNTCon” side of the bill was mostly focused on the nuts and bolts of using agents to write software (or more specifically, best practices for engineering agentic testing and correctness-check loops, without which agentic codegen in any vertical or enterprise context is hopeless pointless at any scale). GitHub gave an overview on how agents are increasingly running CI/CD at, well, planetary scale (as anyone who tracks github outages can tell you), and what patterns and inferences they’re gleaning from this planetary dataset, and sponsors HumanLayer outlined their agent-focused IDE design.  Standouts included Ksenia Bobrova’s nuts-and-bolts testing/observability talk and Julien DuBois’ detailed labor journal of parallelizing and rigorously scrumming a massive agentic “dev team” over 21 days (both representing Github). The most TAAWG-relevant presentation in this category would be Amine Raji from MoIntek AB’s detailed catalog of MCP’s novel cybersecurity footguns. It was great catching up with long-time friend of the podcast Balázs Némethi from agentcommunity.org, but otherwise there didn’t seem to be many independent agentic developers from outside the enterprise context in attendance.

Classic open-source presentations (as opposed to open-core business pitches) were relatively under-represented, but what there was impressive and important.  There were excellent, insight-rich presentations about observing and tracking agents using OpenTelemetry, the newest AAIF project tetrate.io, and the impressively TAAWG-aligned harness Mecatl from Stacklok, which feels like it was written by someone who has been reading our diary. Also of note was the keynote on adapting Linux Foundation contribution patterns and governance to an industry of such a novel shape by AAIF’s Manik Surtani. 

There were surprisingly few talks about IAM topics or merging agentic observability with traditional HR and user cybersecurity, compared to what I would have expected. Aaron Parecki and some collaborators from very large enterprises reported out on how they integrated the new ID-JAG RFC from the OAuth WG to do exactly that (to send back to the Identity Provider for the principle event receipts for each authorization grant taken on its behalf), a kind of report-out on a Very Large production trial for this new pattern of OAuth logging. Scrappy startup AuthPlane wasn’t on stage but did get a booth on the demo floor to promote their lightweight OAuth Server which does its own ID-JAG like binding between agents and their principles, by giving agents an identity more trackable with conventional tooling. Also demoing was Buzz, a project from former DIF member Block that allows for long-lived agents to be organized into directories and dossiers by giving each a private key and thus a non-rotatable did:nostr, which they use to advertise their services over Nostr relays and create DIDComm-like secure channels with users and each other.  The founder of AuthZed, a ReBAC authorization product based on SpiceDB (a community reimplementation of Google’s Zanzibar relationship graph), got some stage time to argue that the principle<>agent relationship is just another kind of relationship best managed centrally in a graph-based ACL.

In summary, there were a lot of products, most of them open source, for managing and tracking agents and securing agentic platforms, and lots of talk about data planes, control planes, and governance mechanisms, a tendency to do cybersecurity at scale that could ungenerously be categorized as “spray and pray”. What was surprisingly scarce on the ground was talk about harness design, constraint-based security, and context-window logging, the most valuable tools yet known for making individual agents behave more predictably and to be able to study after the fact precisely what was in their context when they started malfunctioning (or misbehaving if you’d like to anthropomorphize). If anything, MCP felt like the most enterprise-y enterprise-sales conference I’ve ever attended–right down to its definition of success and its blindspots and externalities.


The Decentralized Identity Foundation (DIF) was established to create an IP-protected environment for decentralized identity-related specifications and open-source code development. DIF promotes the use of DIDs, VCs, and related decentralized identity technologies. DIF maintains more than 270 GitHub repositories that have been contributed or developed by members and working Groups. DIF is committed to fostering an environment where decentralized identity technologies can evolve, mature, and achieve widespread adoption through collaborative effort and strategic partnerships across the ecosystem.

Learn more about Decentralized Identity Foundation (DIF)