[
 {
  "id": 1,
  "day": "2026-10-13",
  "type": "Keynote",
  "start": "09:10",
  "end": "09:35",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "How AI Agents Change API Interaction Patterns",
  "speakers": [
   {
    "name": "Bill Doerrfeld",
    "title": "Editor in Chief",
    "company": "Nordic APIs"
   }
  ],
  "facets": [
   "agent_readiness",
   "discoverability",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "spec_presence",
   "rate_limit_signal"
  ],
  "why": "Discovery, understanding, integration and traffic, compared for human and agent consumers. The opening frame for the whole Agent Readiness layer.",
  "abstract": "AI agents are the new API consumer type. However, they don’t interact with APIs in the same way as human users. In this opening keynote, I’ll compare traditional human-driven API interaction patterns with emerging agent-driven, LLM-based patterns. We’ll look at how discovery, understanding, integration, API requests, traffic patterns, and other aspects of API consumption differ between these two paradigms. As we’ll see, understanding these differences is critical to designing platform interfaces for the agentic era — both to improve the accuracy and reliability of agent interactions and to safeguard the capabilities agents can access. Through industry case studies and examples, we’ll explore how API consumption is changing and what these shifts mean for API providers, setting the stage for the discussions to come at Nordic APIs Summit 2026.",
  "url": "https://nordicapis.com/sessions/how-ai-agents-change-api-interaction-patterns/"
 },
 {
  "id": 2,
  "day": "2026-10-13",
  "type": "Keynote",
  "start": "09:35",
  "end": "10:00",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Your Next Customer Won’t Be Human: Thinking Beyond Internal AI",
  "speakers": [
   {
    "name": "Jacob Ideskog",
    "title": "CTO",
    "company": "Curity"
   }
  ],
  "facets": [
   "agent_readiness",
   "access_clarity"
  ],
  "agent_readiness_dimensions": [
   "delegated_identity"
  ],
  "why": "No abstract; mapped from the title. External agents as customers, not internal copilots.",
  "abstract": "",
  "url": ""
 },
 {
  "id": 3,
  "day": "2026-10-13",
  "type": "Keynote",
  "start": "10:00",
  "end": "10:25",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Governance in the Age of AI Agents",
  "speakers": [
   {
    "name": "Jeroen Delbarre",
    "title": "Director, Product Line",
    "company": "Axway"
   }
  ],
  "facets": [
   "contract_governance",
   "agent_readiness",
   "accountability"
  ],
  "agent_readiness_dimensions": [],
  "why": "Principles for introducing agents securely, and the role APIs play in governing them.",
  "abstract": "The agentic era is here, and the adoption of AI agents is exploding. However, this comes with risks because of the autonomous nature of these agents. During this session, discover the main principles of AI agents, how they interact with each other and with other applications, what role APIs play, and how to ensure agents are introduced securely.",
  "url": "https://nordicapis.com/sessions/governance-in-the-age-of-ai-agents/"
 },
 {
  "id": 4,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "10:55",
  "end": "11:15",
  "track": [
   "API Strategy and AI-Driven Change"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Why Being “AI-Ready” Is as Much Psychology as Technology",
  "speakers": [
   {
    "name": "Claire Barrett",
    "title": "Founder",
    "company": "APIsFirst"
   }
  ],
  "facets": [
   "accountability"
  ],
  "agent_readiness_dimensions": [],
  "why": "Human factors of AI readiness: alignment, decisions, pace of change. The rubric reads published artifacts, not organisational readiness.",
  "abstract": "For leaders driving or implementing API strategy, it’s easy to focus on the platforms, the tooling, and the governance processes — leaving the human factors as an afterthought. Yet the hard decisions facing integrators and their investments still involve getting clarity and alignment, making hard decisions, and keeping up with the pace of change. This session provides practical ways in which API leaders and teams can get ahead of their AI-readiness plans in ways that make sense to their colleagues and the business drivers that AI is enabling.",
  "url": "https://nordicapis.com/sessions/why-being-ai-ready-is-as-much-psychology-as-technology/"
 },
 {
  "id": 5,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:15",
  "end": "11:35",
  "track": [
   "API Strategy and AI-Driven Change"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Spacetime Crystals and Coherent APIs",
  "speakers": [
   {
    "name": "Gareth Faull",
    "title": "Senior Product Manager",
    "company": "London Stock Exchange Group"
   }
  ],
  "facets": [
   "contract_governance",
   "discoverability",
   "accountability"
  ],
  "agent_readiness_dimensions": [],
  "why": "Duplicated APIs, overlapping capabilities, unclear ownership: measuring organisational coherence through the API estate.",
  "abstract": "For years, we’ve become steadily better at building API platforms, improving governance, security, automation, and developer experience. Yet many organizations still struggle with duplicated APIs, overlapping capabilities, unclear ownership, and competing standards. These aren’t failures of API management — they’re symptoms of something deeper. API platforms provide a uniquely visible window into how organizations make decisions. Every API reflects choices about business goals, ownership, consumers, and technology. By measuring how well those decisions remain connected over time, we can move beyond measuring API quality alone and begin measuring something more fundamental: organizational coherence.",
  "url": "https://nordicapis.com/sessions/spacetime-crystals-and-coherent-apis/"
 },
 {
  "id": 6,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:35",
  "end": "11:55",
  "track": [
   "API Strategy and AI-Driven Change"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "From API Sprawl to Platform: Consolidating IoT Products, Teams, and Business Models",
  "speakers": [
   {
    "name": "Sareh Zimmermann",
    "title": "Business Owner Connected Devices Platform",
    "company": "dormakaba"
   }
  ],
  "facets": [
   "contract_governance",
   "operational_transparency",
   "regulatory"
  ],
  "agent_readiness_dimensions": [],
  "why": "Consolidating sprawl while devices in the field and physical access control keep working: migration and deprecation with real-world stakes.",
  "abstract": "API sprawl is hard in any domain. In IoT device management and access control, it becomes exponentially harder. In our case: APIs responsible for IoT device lifecycle management, access control, and policy enforcement High operational risk when consolidating APIs that directly control real-world access Migration is not just about endpoints—it affects devices already deployed in the field The core problem: Our APIs evolved around teams and products, while devices, customers, and security policies cut across them. Solution: This talk shares how we are re-architecting toward a single API platform for IoT device management and access control—while keeping existing customers and devices operational. The process:",
  "url": "https://nordicapis.com/sessions/from-api-sprawl-to-platform-consolidating-iot-products-teams-and-business-models/"
 },
 {
  "id": 7,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "10:55",
  "end": "11:15",
  "track": [
   "API Security and Testing"
  ],
  "room": [
   "C10"
  ],
  "title": "Securing Your API: The OWASP Top 10",
  "speakers": [
   {
    "name": "Rob Allen",
    "title": "Owner",
    "company": "Nineteen Feet Limited"
   }
  ],
  "facets": [
   "operational_transparency",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity"
  ],
  "why": "Broken authentication and authorisation first. The rubric reads the published security posture and disclosure path, not runtime vulnerabilities.",
  "abstract": "APIs are the foundation of our AI applications today and need to be secure. From broken authorisation and authentication to injection attacks, the OWASP API Security Top 10 identifies the most critical security issues facing APIs today. In this talk, we’ll walk through the items on the list and explore these security flaws and look at how to prevent them. By the end of this session, you’ll have a clear understanding of the most critical API security risks and be equipped with the knowledge to build more secure APIs.",
  "url": "https://nordicapis.com/sessions/securing-your-api-the-owasp-top-10/"
 },
 {
  "id": 8,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:15",
  "end": "11:35",
  "track": [
   "API Security and Testing"
  ],
  "room": [
   "C10"
  ],
  "title": "Verifying REST API Security with Fuzzing",
  "speakers": [
   {
    "name": "Andrea Arcuri",
    "title": "Professor",
    "company": "Kristiania University of Applied Sciences"
   }
  ],
  "facets": [
   "contract_quality",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "error_semantics"
  ],
  "why": "Endpoints missing from the OpenAPI, stack traces in 500s: fuzzing finds where the contract and the implementation disagree.",
  "abstract": "When building a REST API, are you or the quality assurance specialists on your team verifying that access policies are satisfied? For every single endpoint? Is it done every single time a new release of the API is made? What about making sure no error stack trace ends up in 500 status responses in production? What about OPTIONS calls that reveal endpoints not declared in the OpenAPI schema? Did you also remember to check for SQL injection and XSS? What about all the other security properties you should know about and check for? If you already have a comprehensive regression test suite that checks all this, I envy you. Is your employer hiring? If not, open source fuzzers can generate test cases automatically — and no, with no LLM hallucinations. When doing so, they can also automatically check many of these properties and flag them if any errors are found. In this talk, I will discuss examples of security issues and how they can be automatically detected using the open source fuzzer EvoMaster, showing the latest results in API security testing research.",
  "url": "https://nordicapis.com/sessions/verifying-rest-api-security-with-fuzzing/"
 },
 {
  "id": 9,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:35",
  "end": "11:55",
  "track": [
   "API Security and Testing"
  ],
  "room": [
   "C10"
  ],
  "title": "Agent Identity: The Missing Layer in Your API Security Stack",
  "speakers": [
   {
    "name": "Jonas Iggbom",
    "title": "Director of Sales Engineering",
    "company": "Curity"
   }
  ],
  "facets": [
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "dynamic_client_registration",
   "delegated_identity",
   "agent_identity_declared"
  ],
  "why": "Client ID metadata documents: agent identity without a registry, proven by key possession. Where DCR stops scaling.",
  "abstract": "AI agents are calling your APIs. Your API gateway sees the request, your authorization server issues the token. But neither of them knows which agent made the call, whether it’s the same agent as last time, or whether it’s authorized to act on behalf of the user it claims to represent. This session is about the identity layer that agentic systems are currently missing, and the emerging standard that addresses it: draft-ietf-oauth-client-id-metadata-document. We’ll cover why traditional OAuth client registration breaks down at agent scale, how the spec enables dynamic client identity without a registry, and why knowing the URL proves nothing, possession of the private key does. We’ll also cover what the spec doesn’t solve on its own, instance-level identity, the bootstrapping problem, and the gap between where the standard is and where enterprise authorization server support currently sits. The goal is to leave you better equipped to evaluate, design, and challenge the identity layer in any agentic system you are building or buying.",
  "url": "https://nordicapis.com/sessions/agent-identity-the-missing-layer-in-your-api-security-stack/"
 },
 {
  "id": 10,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "10:55",
  "end": "11:15",
  "track": [
   "Designing and Governing Better APIs"
  ],
  "room": [
   "C8"
  ],
  "title": "Your (Bad) API Design is Costing you Tokens",
  "speakers": [
   {
    "name": "Milton Carranza",
    "title": "Associate Director - API Engineering",
    "company": "MSD"
   }
  ],
  "facets": [
   "contract_quality",
   "contract_governance",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "operation_distinctiveness"
  ],
  "why": "A benchmark: the same business API, well and badly designed, costs frontier models 30-77% more tokens. Design quality is now an inference cost.",
  "abstract": "For this talk, I want to present an experimental benchmark exploring how poor API design increases the number of tokens AI models use when generating integration code. I compare two APIs with identical business functionality: 1. A well-designed REST/HAL API with consistent naming, predictable resource paths, and hypermedia links. 2. A poorly designed RPC-style API with inconsistent casing, POST-for-read operations, nested payloads, abbreviations, and no hypermedia navigation. I tested frontier models across OpenAI, Anthropic, and Google families using the same coding task and measured token consumption. The results were consistent across every model: All models used more completion tokens with the bad API. Token overhead ranged from approximately 30% to 77%, the average overhead was around 52%, and GPT-5-mini additionally exposed higher reasoning-token usage, showing that the models literally had to “think harder” when consuming poorly designed APIs. In the talk, I’d show that the largest source of inefficiency is not just inconsistent naming but RPC-style workflows, POST requests for reads, missing hypermedia navigation, and APIs that force models to infer relationships instead of following explicit links. The talk argues that API design now directly impacts AI inference cost, code generation speed, generated code complexity, and reliability of AI-assisted integrations.",
  "url": "https://nordicapis.com/sessions/your-bad-api-design-is-costing-you-tokens/"
 },
 {
  "id": 11,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:15",
  "end": "11:35",
  "track": [
   "Designing and Governing Better APIs"
  ],
  "room": [
   "C8"
  ],
  "title": "Green Architecture: Less Fat, More Impact, More Efficiency! With API Green Score",
  "speakers": [
   {
    "name": "Thierno Diallo",
    "title": "Staff Engineer",
    "company": "Axa France"
   }
  ],
  "facets": [
   "contract_governance",
   "outside"
  ],
  "agent_readiness_dimensions": [
   "pagination_ratio"
  ],
  "why": "Spectral and CI rules for compression, partial fields and mandatory pagination. The energy and carbon per endpoint is something no facet reads today.",
  "abstract": "Have your APIs gained a bit of weight? Do they consume more than necessary? Don’t worry, we’re bringing out the toolbox to give them a Green relooking! In this presentation, we will apply, step by step, the “API Green Score” framework on a real and existing API, using open source tools and concrete metrics. The problem? Not a lack of principles, but the absence of measurable, automatable, and automated rules. Calculate the Green Score, energy consumption, and carbon emissions per endpoint, with aggregation and a reporting dashboard. Implement actionable rules: GZIP/Brotli compression, partial fields, reducing transferred data, mandatory pagination, and more. Automate recalculation and non-regression with continuous integration (CI) pipelines (GitHub Actions, Creedengo, SonarQube, and Spectral). Result? A lighter, faster API, with a reduced environmental impact, and above all, more proactive by monitoring on push and PR. We will show you the gains live (before and after): reduced network traffic, stabilized latency, and optimized cache. And to leave with something concrete, a GitHub repo awaits you with everything needed to reproduce the automated process. Example of dashboard: https://thiernodialloafa.github.io/green-api-workshop-final/",
  "url": "https://nordicapis.com/sessions/green-architecture-less-fat-more-impact-more-efficiency-with-api-green-score/"
 },
 {
  "id": 12,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "11:35",
  "end": "11:55",
  "track": [
   "Designing and Governing Better APIs"
  ],
  "room": [
   "C8"
  ],
  "title": "DevOps-Driven API Governance in Practice",
  "speakers": [
   {
    "name": "Andrzej Jarzyna",
    "title": "API Expert",
    "company": "API Peak"
   }
  ],
  "facets": [
   "contract_governance",
   "operational_transparency",
   "discoverability",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [],
  "why": "Governance in CI/CD: standards checks, breaking-change detection, cataloguing, and treating agents as first-class consumers.",
  "abstract": "API governance is often discussed in terms of guidelines and standards. In many organizations, though, it is still too manual, too slow, or simply arbitrary. In this talk, I will show how to make API governance part of the DevOps process. Using open-source tools and CI/CD pipelines, we can automatically check whether APIs follow company standards, are AI-ready, catch breaking changes early, keep APIs catalogued, and reduce drift between guidelines and what teams actually deliver. I will also show how to put in place a bare-bones, no-fuss governance setup in just a few hours, one that brings value quickly without becoming a big governance initiative. Finally, I will show how to treat AI agents as first-class citizens, so APIs are designed to be understandable and safe to use not only for developers, but also for agent-based consumers.",
  "url": "https://nordicapis.com/sessions/devops-driven-api-governance-in-practice/"
 },
 {
  "id": 13,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:00",
  "end": "13:20",
  "track": [
   "Enterprise Platform Evolution"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "You Don’t Need Kubernetes: How We Scaled Our API Layer Without the Infrastructure Theater",
  "speakers": [
   {
    "name": "Faith Sodipe",
    "title": "Software Developer",
    "company": "Bauer Media Outdoor"
   }
  ],
  "facets": [
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [],
  "why": "Scaling an API layer with boring infrastructure. Mostly internal; little public-surface signal.",
  "abstract": "Somewhere along the way, the industry convinced itself that scaling meant complexity. That if your system was growing, you needed service meshes, container orchestration, and infrastructure that required its own team to maintain. We believed it too, until we didn’t. This talk is the honest story of how we scaled a production Data Ingestion engine and its API layer without reaching for Kubernetes, without over-provisioning, and without building infrastructure that outlived its usefulness before it was even fully deployed. We made deliberate, boring choices and they worked. We will walk through the specific decisions that let us scale with confidence: where we drew the line between what the system needed and what the ecosystem was selling us, how we kept the API surface clean under growing data volume, and what we learned about the real cost of complexity when you are the one maintaining it at 2 AM. This talk is for engineers and architects who are tired of feeling like they are behind because they have not adopted the heaviest tool in the room. Sometimes the most sophisticated thing you can do is know what not to build. You will leave with a practical framework for making infrastructure decisions.",
  "url": "https://nordicapis.com/sessions/you-dont-need-kubernetes-how-we-scaled-our-api-layer-without-the-infrastructure-theater/"
 },
 {
  "id": 14,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:20",
  "end": "13:40",
  "track": [
   "Enterprise Platform Evolution"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "From REST to MCP: 3 Years of Platform Evolution in Finance Tech",
  "speakers": [
   {
    "name": "Marco Bassi",
    "title": "Head of Engineering",
    "company": "Spendesk"
   }
  ],
  "facets": [
   "agent_readiness",
   "developer_ergonomics",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "auth_clarity"
  ],
  "why": "Three years from public REST API to MCP at a finance platform, with real adoption data on what customers actually used.",
  "abstract": "In 2023, we presented Spendesk’s journey to launching a public REST API, enabling customers and system integrators to connect spend management with any external software. Three years later, the platform integration landscape has fundamentally shifted. This session explores our evolution from traditional REST APIs to embracing Model Context Protocol (MCP), positioning Spendesk for an AI-agent-powered future. We’ll share: – The Technical Pivot: How we architected MCP tools alongside our existing API infrastructure, addressing security, authentication, and backwards compatibility challenges – Real Adoption Data: What happened when we gave customers both options – the gap between requested features and actual usage patterns tells a surprising story – Security in the Tool Era: Our approach to securing MCP-based access in regulated finance environments, including lessons learned from early implementations – The Vision: How MCP is reshaping our product strategy and what we believe the future of finance platforms looks like when AI agents become first-class citizens Attendees will leave with practical insights on navigating the shift from request-response APIs to tool-based architectures, real-world adoption metrics, and a framework for deciding when (and when not) to implement MCP alongside traditional APIs.",
  "url": "https://nordicapis.com/sessions/from-rest-to-mcp-3-years-of-platform-evolution-in-finance-tech/"
 },
 {
  "id": 15,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:40",
  "end": "14:00",
  "track": [
   "Enterprise Platform Evolution"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "From 2 Scopes to Global Identity",
  "speakers": [
   {
    "name": "Curtis J. Schofield",
    "title": "Staff Engineer",
    "company": "PagerDuty"
   }
  ],
  "facets": [
   "agent_readiness",
   "access_clarity"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity",
   "consent_identity"
  ],
  "why": "From two scopes to a hundred. Scope granularity is what makes consent and least privilege legible to an agent.",
  "abstract": "This is the story of how an identity replatform made us ready for agents. In 2019, PagerDuty’s identity lived inside a Rails monolith on an aging open source OAuth library. The API had exactly two scopes: read and write. We bucketed every piece of work we could tackle. Reworking authentication and authorization stood out. There was zero appetite for a project without an immediate business case. In winter 2020, what the business wanted was a European region. I pitched a central global identity and applications system serving both regions: the U.S. and Europe. This would let customers anywhere use our entire application pool without partners reworking anything. By the end of 2021, our entire integrations catalog was available to EU customers with zero partner rework. Attendees will follow the journey from two scopes to 100 and learn a few of the extensions we made to control application security.",
  "url": "https://nordicapis.com/sessions/from-2-scopes-to-global-identity/"
 },
 {
  "id": 16,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:00",
  "end": "13:20",
  "track": [
   "Building Agent Interfaces"
  ],
  "room": [
   "C10"
  ],
  "title": "Composable Architecture for AI Systems: APIs, MCP, Skills, Sub-Agents, and Workflows",
  "speakers": [
   {
    "name": "Erik Wilde",
    "title": "OAI Ambassador",
    "company": "OpenAPI Initiative"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "agent_skills"
  ],
  "why": "APIs, MCP, skills, sub-agents and workflows: when a process keeps being rediscovered, it belongs in a deterministic workflow, not a prompt.",
  "abstract": "AI is a powerful tool, but it is not the only tool, and most systems worth building are hybrids of AI and non-AI parts. That line between them doesn’t sit neatly between domains. It runs inside every domain, and it should move as you learn. This talk looks at the mechanisms for connecting across that line: APIs, MCP, agent skills, and sub-agents, as well as at workflows as a way to move the line itself: when an agent keeps rediscovering the same business process, that process belongs in deterministic execution, not in a prompt. You’ll leave knowing which mechanism belongs where, and how to keep shifting work out of AI as your system settles.",
  "url": "https://nordicapis.com/sessions/composable-architecture-for-ai-systems-apis-mcp-skills-sub-agents-and-workflows/"
 },
 {
  "id": 17,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:20",
  "end": "13:40",
  "track": [
   "Building Agent Interfaces"
  ],
  "room": [
   "C10"
  ],
  "title": "MCP vs. CLI vs. API vs. Browser: Choosing the Right Interface for AI Agents",
  "speakers": [
   {
    "name": "Shalev Shalit",
    "title": "Co-Founder & CTO",
    "company": "Willow"
   }
  ],
  "facets": [
   "agent_readiness",
   "developer_ergonomics"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "spec_presence"
  ],
  "why": "Choosing API, MCP, CLI or browser: the most structured, least powerful, most observable interface that can do the job.",
  "abstract": "AI agents are only as useful as the tools they can use. But once agents start acting through real systems, tool choice becomes an architecture decision, a security decision, and a product decision. Should your agent call an API directly? Use an MCP server? Run a CLI command? Drive a browser? Query a database? Ask a human? This talk presents a practical decision framework for choosing the right execution interface for AI agents. We will compare MCP, direct APIs, CLIs, and browser automation across reliability, safety, permissions, observability, ergonomics, and failure modes. The core argument: agents should use the most structured, least powerful, most observable interface that can complete the task. Direct APIs are best for stable product workflows. MCP is powerful for standardizing tool access across many clients. CLIs are useful for developer workflows but risky when they expose broad machine-level power. Browser automation is valuable for legacy systems but should often be treated as a fallback. The goal is to build an agent tool strategy that matches the task, the risk, and the operating environment.",
  "url": "https://nordicapis.com/sessions/mcp-vs-cli-vs-api-vs-browser-choosing-the-right-interface-for-ai-agents/"
 },
 {
  "id": 18,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:40",
  "end": "14:00",
  "track": [
   "Building Agent Interfaces"
  ],
  "room": [
   "C10"
  ],
  "title": "MCP Hands-on: How We Opened Up APIs for AI Agents",
  "speakers": [
   {
    "name": "Andreas Siegel",
    "title": "Software Engineer & IT Architect",
    "company": "pentacor"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality",
   "developer_ergonomics"
  ],
  "agent_readiness_dimensions": [
   "spec_presence",
   "mcp_server",
   "auth_clarity"
  ],
  "why": "An agent on a raw OpenAPI vs the same API behind MCP: where semantic tool descriptions help and where the direct route stays better.",
  "abstract": "AI agents can now access APIs directly via function calling and tool use. With reasoning, an OpenAPI spec, and a bit of hope, this approach can already solve a surprising amount. But how far does it really go when dealing with enterprise systems — and where does it hit its limits? That’s exactly the question we explore. We start by looking at how an AI agent connects directly to an API: Does it find the right endpoints? Does it pass parameters correctly? How reliable are the results? We then introduce the Model Context Protocol (MCP) as an integration layer and show what concretely changes: standardized discovery instead of trial and error, semantic tool descriptions that give the agent real context, and a protocol that addresses aspects like authentication and authorization. MCP is no free lunch, though — the integration effort shifts rather than disappears. Implementing a good MCP server is an architectural challenge in its own right. Drawing on our experience from client projects and our own development work, we show when MCP delivers real value and where the direct API route remains the more pragmatic choice.",
  "url": "https://nordicapis.com/sessions/mcp-hands-on-how-we-opened-up-apis-for-ai-agents/"
 },
 {
  "id": 19,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:00",
  "end": "13:20",
  "track": [
   "Standards, Discovery, & Interoperability"
  ],
  "room": [
   "C8"
  ],
  "title": "Building an AI-Ready Metadata Ecosystem at a Large Enterprise",
  "speakers": [
   {
    "name": "Pavel Kornev",
    "title": "Principal Software Architect",
    "company": "SAP SE"
   }
  ],
  "facets": [
   "discoverability",
   "contract_governance",
   "open_source"
  ],
  "agent_readiness_dimensions": [
   "well_known_catalog"
  ],
  "why": "Open Resource Discovery: decentralised, machine-readable descriptions of APIs, events and AI resources. The catalog problem apis.json also answers.",
  "abstract": "Developers and AI systems share a common challenge: understanding the IT landscape well enough to identify what systems exist, what services and resources they expose, and how to integrate with them. Open Resource Discovery (ORD) addresses this challenge with an open-source standard (governed by the Linux Foundation) for decentralized system descriptions. ORD enables discovery of available APIs, events, data products, and AI resources — along with their contracts and documentation. With ORD, organizations can publish static catalogs of offerings, analyze the IT landscape in real time, and build platforms for software development, data management, and AI.",
  "url": "https://nordicapis.com/sessions/building-an-ai-ready-metadata-ecosystem-at-a-large-enterprise/"
 },
 {
  "id": 20,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:20",
  "end": "13:40",
  "track": [
   "Standards, Discovery, & Interoperability"
  ],
  "room": [
   "C8"
  ],
  "title": "Unlocking Secure Data Sharing with Trusted Research Environments (TREs) and Data Spaces",
  "speakers": [
   {
    "name": "Petteri Kivimäki",
    "title": "CTO",
    "company": "Nordic Institute for Interoperability Solutions (NIIS)"
   }
  ],
  "facets": [
   "regulatory",
   "discoverability",
   "accountability"
  ],
  "agent_readiness_dimensions": [
   "consent_identity"
  ],
  "why": "Trusted research environments and data spaces for sensitive health and public-sector data: discovery, access negotiation, controlled use.",
  "abstract": "The digital transformation of research and innovation ecosystems has resulted in significant growth in the volume, diversity, and distribution of data. In sectors such as healthcare, energy, and public services, this data is highly sensitive and governed by strict regulatory and organisational requirements. Consequently, there is a growing need for infrastructures that enable secure, compliant, and interoperable data sharing and analysis. Trusted Research Environments (TREs) address this need by providing controlled, auditable environments where authorised users can analyse sensitive data without exposing it beyond protected boundaries. In parallel, data spaces are emerging as decentralised frameworks that support data discovery, access negotiation, and exchange through shared standards and governance models, while allowing organisations to retain full control over their data. In this talk, I will discuss how integrating TREs with data spaces can unlock complementary strengths. Also, I will discuss TRE concepts and terminology, give an overview of different governance scenarios, and identify high-level architectural and operational patterns required for technical integration.",
  "url": "https://nordicapis.com/sessions/unlocking-secure-data-sharing-with-trusted-research-environments-tres-and-data-spaces/"
 },
 {
  "id": 21,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "13:40",
  "end": "14:00",
  "track": [
   "Standards, Discovery, & Interoperability"
  ],
  "room": [
   "C8"
  ],
  "title": "Spec-Driven API Design: From Consumer Capability to API Contract",
  "speakers": [
   {
    "name": "Daniel Kocot",
    "title": "Principal Integration Architect",
    "company": "adorsys GmbH&Co. KG"
   }
  ],
  "facets": [
   "contract_governance",
   "contract_quality"
  ],
  "agent_readiness_dimensions": [],
  "why": "Spec-driven design with a shared constitution: the specification as the product artifact and the governance source of truth.",
  "abstract": "This talk introduces spec-driven development as the foundation of an API design-first approach, where the API specification becomes the central product artifact. Using spec-kit and OpenSpec, it demonstrates how a shared constitution (guiding principles) combined with concrete specifications enables consistent, enforceable API definitions. This approach brings Product Owners and developers together around a common source of truth, fostering collaboration and shared ownership of API design. It supports safe and controlled API evolution while enabling scalable API governance—even in environments increasingly shaped by AI-assisted development.",
  "url": "https://nordicapis.com/sessions/spec-driven-api-design-from-consumer-capability-to-api-contract/"
 },
 {
  "id": 22,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "14:20",
  "end": "14:40",
  "track": [
   "Identity & Authorization for Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Supercharging AI Governance with Agent Identities",
  "speakers": [
   {
    "name": "Tyler Ayers",
    "title": "Principal Architect",
    "company": "Google"
   }
  ],
  "facets": [
   "agent_readiness",
   "accountability"
  ],
  "agent_readiness_dimensions": [
   "delegated_identity",
   "agent_identity_declared"
  ],
  "why": "Agent identities, delegation and token exchange as the way to govern AI across clouds and laptops.",
  "abstract": "Organizations are adding AI platforms, models, tools, and agents at a rapid clip. How can organizations keep up and manage AI governance across clouds, laptops, cloudtops, and legacy environments? Join us for an exploration with real examples, best-of-breed architectures, and even some live demos of effective AI governance using agent identities, delegation and token exchanges, and AI proxies.",
  "url": "https://nordicapis.com/sessions/supercharging-ai-governance-with-agent-identities/"
 },
 {
  "id": 23,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "14:40",
  "end": "15:00",
  "track": [
   "Identity & Authorization for Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Securing MCP for Financial APIs: OAuth2, Discovery, and Least Privilege",
  "speakers": [
   {
    "name": "Roberto Bianchi",
    "title": "Staff Software Engineer",
    "company": "Spendesk"
   }
  ],
  "facets": [
   "agent_readiness",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "protected_resource_metadata",
   "auth_clarity",
   "consent_identity"
  ],
  "why": "An MCP server for a regulated finance API: a focused tool set, OAuth2, discovery, least privilege, open-banking discipline.",
  "abstract": "In financial services, technology alone is no longer a differentiator; trust, interoperability, and control are. Open banking raised the bar for how standards must handle identity, privacy, and access control, and MCP should be held to the same standard as it becomes an important interface for AI agents. In this talk, I’ll share how Spendesk approached the design of an MCP service, with security and regulatory discipline as pillars from day one. Rather than exposing a broad API surface, we selected a focused set of tools based on real user needs and practical use cases, then designed the server with least privilege, privacy, and safe interoperability in mind. I’ll walk through the architecture, the main technical decisions, and the bottlenecks we hit when adapting an existing financial API platform to MCP, including discovery, authorization, tool visibility, and execution-time controls. The session will use practical examples to show the tradeoffs behind those decisions and the solutions we chose to maintain a high security bar. Attendees will leave with a reusable blueprint for adopting MCP in other regulated or high-sensitivity environments.",
  "url": "https://nordicapis.com/sessions/securing-mcp-for-financial-apis-oauth2-discovery-and-least-privilege/"
 },
 {
  "id": 24,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "15:00",
  "end": "15:20",
  "track": [
   "Identity & Authorization for Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Register Once, Integrate Everywhere: FAPI 2.0 and a Federated Authorization Foundation for Public-Sector APIs",
  "speakers": [
   {
    "name": "Roland Baum",
    "title": "CEO",
    "company": "umbrella.associates GmbH"
   }
  ],
  "facets": [
   "regulatory",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "auth_scheme_strength",
   "dynamic_client_registration"
  ],
  "why": "FAPI 2.0, sender-constrained tokens and signed software statements for German public-sector APIs. Bound vs bearer, in production.",
  "abstract": "Public-sector API operators rarely know the clients they authorize. Across a federation of hundreds of agencies with decentralized administrative processes, access decisions can no longer rest on acquaintance or bilateral agreements. What takes their place is a rule-based approach: decisions grounded in validated attributes, evaluable locally without a runtime dependency on a central platform. In the project Federal API Authorization Infrastructure, Saxony-Anhalt and FITKO are developing, on behalf of the German IT Planning Council, uniform security requirements and a target architecture built on OAuth 2.0, OpenID Connect, the FAPI 2.0 Security Profile, and AuthZEN. The talk covers the architectural principles we commit to, the decisions and trade-offs behind them — sender-constrained tokens, client authentication, attribute-based authorization, onboarding via signed software statements — and how base services and connecting systems can derive reusable building blocks and realistic migration paths from them. We will share early results from our proof of concept and concrete options for action for operators, developers, and security officers.",
  "url": "https://nordicapis.com/sessions/register-once-integrate-everywhere-fapi-2-0-and-a-federated-authorization-foundation-for-public-sector-apis/"
 },
 {
  "id": 25,
  "day": "2026-10-13",
  "type": "Lightning",
  "start": "14:20",
  "end": "14:35",
  "track": [
   "Demos & Lightning Talks: Day 1"
  ],
  "room": [
   "C8"
  ],
  "title": "Securing Backend Agents",
  "speakers": [
   {
    "name": "Gary Archer",
    "title": "Identity Specialist",
    "company": "Curity"
   }
  ],
  "facets": [
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "delegated_identity",
   "consent_identity"
  ],
  "why": "APIs that authorise agent access at scale, least privilege, and users approving agent operations.",
  "abstract": "There is a lot of hype about quick ways to secure AI agents. But to properly secure AI, enterprises need an architecture that secures all endpoints and protects business resources. In this lightning talk, I first explain a flexible design where APIs can authorize agent access at scale. I also show how to run agents with least privilege and how to enable users to approve agent operations. Enterprises must also plan a separation of people concerns, where infrastructure teams deploy security subsystems. Within such a setup, I will demonstrate secure and productive AI development.",
  "url": "https://nordicapis.com/sessions/agentic-security-foundations/"
 },
 {
  "id": 26,
  "day": "2026-10-13",
  "type": "Lightning",
  "start": "14:35",
  "end": "14:50",
  "track": [
   "Demos & Lightning Talks: Day 1"
  ],
  "room": [
   "C8"
  ],
  "title": "Kong — the AI Control Layer",
  "speakers": [
   {
    "name": "Alexander Jaballah",
    "title": "Solutions Engineer, Nordics",
    "company": "Kong"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency",
   "access_clarity"
  ],
  "agent_readiness_dimensions": [
   "rate_limit_signal"
  ],
  "why": "Vendor demo: security, usage, cost and observability across AI workloads at the gateway.",
  "abstract": "AI adoption is moving from experiments to production, but most teams are struggling with fragmented models, agents, APIs, and governance. In this demo, we’ll show how Kong AI Gateway helps teams move fast while maintaining control over security, usage, cost, and observability across AI workloads.",
  "url": "https://nordicapis.com/sessions/kong-the-ai-control-layer/"
 },
 {
  "id": 27,
  "day": "2026-10-13",
  "type": "Lightning",
  "start": "14:50",
  "end": "15:05",
  "track": [
   "Demos & Lightning Talks: Day 1"
  ],
  "room": [
   "C8"
  ],
  "title": "Federation, Reversed: A Consumer-First Future with Fission",
  "speakers": [
   {
    "name": "David Stutt",
    "title": "Founding Engineer",
    "company": "WunderGraph"
   }
  ],
  "facets": [
   "contract_quality",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [],
  "why": "Consumer-first GraphQL federation: design the API surface first, derive the services from it.",
  "abstract": "GraphQL Federation traditionally takes a bottom-up approach: individual service schemas are defined first, and the final federated API emerges from the federation algorithm. However, GraphQL’s strength is enabling APIs that are designed around what consumers actually need. A bottom-up model can make it harder to intentionally design the federated API surface. In this talk we introduce Fission, a new federation algorithm that enables a consumer-first, design-driven approach to federated GraphQL APIs. We’ll show how Fission lets teams start with API design and derive the services therefrom—flipping the traditional federation paradigm on its head. And best yet: we’ll explain using cake.",
  "url": "https://nordicapis.com/sessions/federation-reversed-a-consumer-first-future-with-fission/"
 },
 {
  "id": 28,
  "day": "2026-10-13",
  "type": "Lightning",
  "start": "15:05",
  "end": "15:20",
  "track": [
   "Demos & Lightning Talks: Day 1"
  ],
  "room": [
   "C8"
  ],
  "title": "Building the Agent Tool Layer: From APIs to Governed MCPs",
  "speakers": [
   {
    "name": "John Gren",
    "title": "Director of Product Management",
    "company": "Gravitee"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "delegated_identity",
   "dynamic_client_registration"
  ],
  "why": "REST APIs into governed MCP tools: which capabilities agents see, agent identity, delegated human access, runtime authorisation.",
  "abstract": "AI agents need tools to act, and enterprises have spent years on tailoring APIs to gain access to enterprise data. The challenge isn’t simply exposing them through MCP. It’s deciding which capabilities agents should see, how they should be composed, and how access is governed when agents start acting on enterprise data. In this session, we’ll follow a simple use case from API to agent. We’ll transform existing REST APIs into reusable MCP Tools, compose them into a purpose-built MCP Server, and make those tools available to an AI agent. Then we’ll add the controls needed for the real world: agent identity, MCP server access registration, delegated human access, and runtime authorization over the data behind each tool. You’ll see how API management, MCP, identity, and authorization come together to create a governed Agent Tool Layer, turning the APIs you already have into secure, composable capabilities built for agents.",
  "url": "https://nordicapis.com/sessions/building-the-agent-tool-layer-from-apis-to-governed-mcps/"
 },
 {
  "id": 29,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "14:20",
  "end": "14:40",
  "track": [
   "Agent Infrastructure"
  ],
  "room": [
   "C10"
  ],
  "title": "Agent Gateway: The One Decision That Eliminates AI Engineering Complexity",
  "speakers": [
   {
    "name": "Lin Sun",
    "title": "Head of Open Source",
    "company": "Solo.io"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency",
   "open_source"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "rate_limit_signal"
  ],
  "why": "The agent gateway pattern: secure MCP servers without changing them, rate-limit LLM traffic, progressive disclosure.",
  "abstract": "As AI systems move from experimentation to production, engineering teams face a growing number of infrastructure decisions. How do you secure MCP servers without modifying them? How do you seamlessly transition and fail over across multiple LLM providers? How do you enforce token rate limits and usage policies for LLMs? How do you govern agent-to-agent and agent-to-MCP communication, control context growth, enforce security policies, observe traffic, and scale operations across environments? Rather than solving each challenge independently, organizations can adopt a single architectural pattern: the agent gateway. Through live demos, Lin introduces the agent gateway pattern and demonstrates how it simplifies AI infrastructure by eliminating the need for teams to repeatedly solve the same cross-cutting concerns. Using agentgateway, an open-source implementation of the pattern, she will show how to secure and federate MCP servers without modifying them, route, fail over, and rate limit LLM traffic across providers, enable advanced capabilities such as code mode and progressive disclosure, and operationalize AI workloads on Kubernetes.",
  "url": "https://nordicapis.com/sessions/agent-gateway-the-one-decision-that-eliminates-ai-engineering-complexity/"
 },
 {
  "id": 30,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "14:40",
  "end": "15:00",
  "track": [
   "Agent Infrastructure"
  ],
  "room": [
   "C10"
  ],
  "title": "API Gateway – The Do’s and Don’ts",
  "speakers": [
   {
    "name": "Memi Lavi",
    "title": "CTO",
    "company": "Polar Technologies"
   }
  ],
  "facets": [
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [],
  "why": "What API gateways are good at and when not to use one. Thin abstract.",
  "abstract": "All major cloud providers offer API gateway service, but we often leave it behind when designing our API strategy. API gateways offer powerful capabilities that can greatly improve the way we design and build our API, and using them wisely can simplify and secure our APIs. In this session we’ll learn about API gateways, what are their major strengths, how to use them, and when they should not be utilized.",
  "url": "https://nordicapis.com/sessions/api-gateway-the-dos-and-donts/"
 },
 {
  "id": 31,
  "day": "2026-10-13",
  "type": "Talk",
  "start": "15:00",
  "end": "15:20",
  "track": [
   "Agent Infrastructure"
  ],
  "room": [
   "C10"
  ],
  "title": "Real-Time or Not Real-Time: Why Your AI Agents Are Only as Good as Their Streaming APIs",
  "speakers": [
   {
    "name": "Ankit Kumar",
    "title": "Head of Developer & Customer Success",
    "company": "Aktivity"
   }
  ],
  "facets": [
   "contract_quality",
   "discoverability",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "event_surface_described"
  ],
  "why": "Agents reasoning on stale data: Kafka topics as governed, discoverable streaming APIs.",
  "abstract": "Everyone is building AI agents. But most of them are reasoning on stale data. Agentic AI depends on data freshness, yet most agents run on REST APIs that are pull-driven and inherently delayed. Streaming APIs are the missing nervous system, but streaming API management has never caught up: no unified governance, no discoverability, no lifecycle management for event-driven data products. Drawing on real-world experience at Aklivity, this talk covers why the REST mental model breaks for agentic AI, what a streaming-native API layer actually looks like, and how to expose Kafka topics as governed, developer-friendly APIs without turning every AI engineer into a Kafka expert. 2. Where traditional API management platforms fall short for event-driven architectures.",
  "url": "https://nordicapis.com/sessions/real-time-or-not-real-time-why-your-ai-agents-are-only-as-good-as-their-streaming-apis/"
 },
 {
  "id": 32,
  "day": "2026-10-13",
  "type": "Panel",
  "start": "16:00",
  "end": "16:25",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Panel Discussion: API Security in the Agentic Era",
  "speakers": [
   {
    "name": "Bill Doerrfeld",
    "title": "Editor in Chief",
    "company": "Nordic APIs"
   },
   {
    "name": "Jacob Ideskog",
    "title": "CTO",
    "company": "Curity"
   },
   {
    "name": "Isabelle Mauny",
    "title": "Field CTO",
    "company": "WSO2"
   },
   {
    "name": "Curtis J. Schofield",
    "title": "Staff Engineer",
    "company": "PagerDuty"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity",
   "delegated_identity"
  ],
  "why": "New threats, and the authentication and authorisation hurdles agents bring.",
  "abstract": "In this main-stage panel discussion, our panel of API security experts will explore what new security challenges APIs and digital platforms face in the age of AI agents. We’ll explore the new threats and consider practices necessary to address new authentication and authorization hurdles.",
  "url": "https://nordicapis.com/sessions/panel-discussion-api-security-in-the-agentic-era/"
 },
 {
  "id": 33,
  "day": "2026-10-13",
  "type": "Keynote",
  "start": "16:25",
  "end": "16:50",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Agents — Viskleken on Steroids",
  "speakers": [
   {
    "name": "Jürgen Schulze",
    "title": "Author & Human Centric Digital Governance Advocate",
    "company": "i-val"
   }
  ],
  "facets": [
   "agent_readiness",
   "accountability"
  ],
  "agent_readiness_dimensions": [],
  "why": "Multi-agent systems as a game of telephone: meaning drifts at every hop. No check reads a chain of agents.",
  "abstract": "Remember Viskleken? You whisper “The cat sits on the mat” into your neighbor’s ear, and 12 giggling children later, it comes out as “The king knits in a hat.” Charming. Harmless. A party game. Now let’s professionalize it. Let’s put it into production. And now, let’s change the setting, the parameters, and the actors while the game is running. Congratulations: You have just built a modern multi-agent system. Agents don’t giggle. My keynote takes the audience on a guided tour through this delightfully dysfunctional playground because every absurd rule of our escalated whispering game maps to a very real, very current engineering problem.",
  "url": "https://nordicapis.com/sessions/agents-viskleken-on-steroids/"
 },
 {
  "id": 34,
  "day": "2026-10-14",
  "type": "Keynote",
  "start": "09:10",
  "end": "09:35",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Rethinking MCP Tools: A Better Way to Connect AI to Enterprise Data with MaintainX",
  "speakers": [
   {
    "name": "Ahmet Soormally",
    "title": "VP of Product",
    "company": "WunderGraph"
   },
   {
    "name": "Adrien Poupa",
    "title": "Senior Software Developer",
    "company": "MaintainX, an Autodesk company"
   },
   {
    "name": "Saif Kurdi-Teylouni",
    "title": "Senior AI Engineer",
    "company": "MaintainX, an Autodesk company"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "operation_distinctiveness"
  ],
  "why": "From an MCP facade over REST, to hand-written tools, to search-and-call, to a capability graph as one machine-readable contract.",
  "abstract": "You want to give AI access to your services, so you put an MCP server on top of them. You pick the operations one agent needs, write a tool for each, write the descriptions, parameter docs, and auth rules. Then you join data across two services, so you write a tool for that too. You just built a backend for frontend, for a consumer who can’t tell you what it needs, till it needs it. In this talk we go through the evolution of MCP tools. From putting an MCP facade on top of your REST API, through to purpose built capabilities tailored for. How to account for toolset management, ACL, cost estimates, development speed. When the tool list becomes unmanageable for an LLM, you use a search and call tool. But what happens when you can represent the capabilities of your organisation as a graph? What does that unlock for your agents? A graph is one contract across the services you already have, in a form a machine can read. Nobody hand-picks what goes in it. It is everything your company can do, in one place. That changes what an agent can ask for. Today the best answer is search tool and call tool. The next generation is prompt and execute. The unit stops being a tool someone wrote in advance, and becomes a capability your graph can satisfy on demand.",
  "url": "https://nordicapis.com/sessions/stop-building-mcp-tools-a-better-way-to-connect-ai-to-enterprise-data/"
 },
 {
  "id": 35,
  "day": "2026-10-14",
  "type": "Panel",
  "start": "09:35",
  "end": "10:00",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Panel Discussion: Designing For The Agentic Experience",
  "speakers": [
   {
    "name": "Gertrude Chilufya",
    "title": "AI Adoption Strategist",
    "company": "Reframe Tech"
   },
   {
    "name": "Erik Wilde",
    "title": "OAI Ambassador",
    "company": "OpenAPI Initiative"
   },
   {
    "name": "Kin Lane",
    "title": "API Evangelist",
    "company": "API Evangelist LLC"
   },
   {
    "name": "Daniel Kocot",
    "title": "Principal Integration Architect",
    "company": "adorsys GmbH&Co. KG"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [
   "spec_presence",
   "openapi_examples"
  ],
  "why": "Design methods, standards and practices for agent consumers. I'm on this panel.",
  "abstract": "AI agents are shifting the way in which APIs are consumed. In this panel discussion moderated by Gertrude Chilufya, API design experts will share how they see the industry shifting, exploring emerging design methods, standards, and general practices to improve how agents interact with APIs.",
  "url": "https://nordicapis.com/sessions/panel-discussion-designing-for-the-agentic-experience/"
 },
 {
  "id": 36,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:30",
  "end": "10:50",
  "track": [
   "Governing Autonomous Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "APIs in the Age of AI: Guardrails, Governance, and Guts",
  "speakers": [
   {
    "name": "Asmo Urpilainen",
    "title": "CTO",
    "company": "Frends"
   }
  ],
  "facets": [
   "contract_governance",
   "agent_readiness",
   "accountability"
  ],
  "agent_readiness_dimensions": [],
  "why": "APIs as policy enforcers when LLMs call them: guardrails, reasoning transparency, governance inside the workflow.",
  "abstract": "As AI reshapes how we build, scale, and interact with systems, APIs are becoming more than just connectors, they’re policy enforcers, safety layers, and value amplifiers. But what happens when generative or agentic AI starts calling your APIs directly? In this talk, Frends CTO Asmo Urpilainen will explore how smart API strategies can prevent AI from becoming a liability. He’ll share real-world lessons from enterprise-scale automation, including how to design APIs for safe LLM access, build in reasoning transparency, and embed governance directly into workflows. This is not just about tech, it’s about rethinking your API strategy for a future where AI is not optional, but integral.",
  "url": "https://nordicapis.com/sessions/apis-in-the-age-of-ai-guardrails-governance-and-guts/"
 },
 {
  "id": 37,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:50",
  "end": "11:10",
  "track": [
   "Governing Autonomous Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "When the Caller Is an Agent: Governing the Agent-to-API Boundary in Enterprises",
  "speakers": [
   {
    "name": "Rinu Dhanaraj",
    "title": "Principal Engineer 1",
    "company": "CVS Health"
   }
  ],
  "facets": [
   "agent_readiness",
   "accountability",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "agentic_access",
   "reversibility_documented",
   "dry_run_mode",
   "delegated_identity"
  ],
  "why": "Govern each agent action by its blast radius, not the caller's identity. Operation-level consequence tiers are what agentic_access classifies.",
  "abstract": "Problem: Adoption of autonomous AI agents through MCP is becoming first-class API consumption, but enterprise API governance was built for human-authored, relatively static integrations. Agents call unpredictably, chain calls, and can amplify a single bad decision across hundreds of downstream requests. Most gateways can reason about a caller’s identity and rate, but not the consequence of a call. Solution: A consequence-tiered governance model that evaluates each agent action by its potential blast radius rather than the caller’s identity alone and assigns a proportionate level of oversight to each tier. I’ll walk through the model on how actions are classified by consequence, how each decision stays accountable and explainable, and how authority is contained when a delegation chain exceeds its mandate. All these as a set of governance principles that apply to any modern API system. Audience takeaways: A tiering scheme you can apply to your own agent traffic, the failure modes that surface only once agents rather than humans are the primary callers, and an honest look at the open problem of delegation soundness versus completeness under partial observability.",
  "url": "https://nordicapis.com/sessions/when-the-caller-is-an-agent-governing-the-agent-to-api-boundary-in-enterprises/"
 },
 {
  "id": 38,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "11:10",
  "end": "11:30",
  "track": [
   "Governing Autonomous Agents"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Cultivating the Right Standards for API Security as AI Agents Take Root",
  "speakers": [
   {
    "name": "Judith Kahrer",
    "title": "Product Marketing Engineer",
    "company": "Curity"
   }
  ],
  "facets": [
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity",
   "protected_resource_metadata",
   "dynamic_client_registration",
   "delegated_identity"
  ],
  "why": "Which parts of the OAuth toolkit agents need, and which new specs they need on top of it.",
  "abstract": "OAuth has become the foundation for modern API security. Over more than a decade experts carefully cultivated the framework by adding new standards, best practices and recommendations to improve authorization for APIs. Now AI agents are taking root in that same ecosystem. More than anything, they expose the gaps in implementations and the OAuth framework: How to authorize actions from software that changes its behavior after the user has granted access? How to enable agents to integrate securely with your APIs and business across trust domains? This talk walks through the challenges in opening APIs to AI agents. It centers around two practical questions: what tools from the existing OAuth toolkit do you actually need to solve them, and what new tools do you need. Attendees will leave with a clearer picture of which emerging specs matter, and how to keep a security posture in “full bloom” as the agentic landscape keeps shifting.",
  "url": "https://nordicapis.com/sessions/cultivating-the-right-standards-for-api-security-as-ai-agents-take-root/"
 },
 {
  "id": 39,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:30",
  "end": "10:50",
  "track": [
   "Securing MCP in the Enterprise"
  ],
  "room": [
   "C10"
  ],
  "title": "How to Secure MCP Architectures for Enterprise Production",
  "speakers": [
   {
    "name": "Kalle Sirkesalo",
    "title": "Field CTO",
    "company": "Eficode"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency",
   "accountability"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "auth_clarity"
  ],
  "why": "From MCP demo to production approval: IAM, data access, human in the loop, supply chain.",
  "abstract": "We have seen the Model Context Protocol (MCP) unlock incredible agentic workflows, but there is a hard truth we always tell our clients: building the technical architecture is the easy part. The gap between “it works perfectly in my demo” and “the enterprise security team approves it for production” is where most MCP projects die. To get your AI agents out of the sandbox and into production, you need to design for security, governance, and enterprise reality from day one. Here is a pragmatic talk on the security considerations and best practices I use for enterprise MCP development. We go through topics like IAM, data access, human-in-the-loop, operational guardrails, supply chain vulnerabilities, and dependency management.",
  "url": "https://nordicapis.com/sessions/how-to-secure-mcp-architectures-for-enterprise-production/"
 },
 {
  "id": 40,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:50",
  "end": "11:10",
  "track": [
   "Securing MCP in the Enterprise"
  ],
  "room": [
   "C10"
  ],
  "title": "Securing the MCP Layer: Discovery, Risk Scoring, and Governance for Agent-to-API Access",
  "speakers": [
   {
    "name": "Baljeet Malhotra",
    "title": "Founder & CEO",
    "company": "TeejLab Inc."
   }
  ],
  "facets": [
   "agent_readiness",
   "discoverability",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [
   "mcp_server",
   "well_known_catalog"
  ],
  "why": "Find the MCP servers you have, map them to the APIs underneath, score their risk. An inventory problem before a security one.",
  "abstract": "As AI agents begin using MCP servers to access enterprise tools, applications, and APIs, organizations face a new governance problem: They often do not know which MCP servers exist, what capabilities they expose, what data they can reach, or which agents are allowed to use them. This talk presents a practical framework for discovering MCP servers, mapping them to underlying APIs, scoring their risk, and enforcing governance controls before agentic workflows reach production. Drawing on my work in API discovery, security, governance, and API risk management at TeejLab, Synopsys, and Black Duck, the session will show how teams can treat MCP servers as first-class enterprise assets rather than experimental connectors. It will cover key risks such as tool poisoning, prompt injection, overpermissioned agents, insecure authentication, shadow APIs, sensitive data exposure, and missing audit trails. Attendees will leave with a practical checklist for building secure agent-to-API access across cloud, SaaS, and internal API ecosystems.",
  "url": "https://nordicapis.com/sessions/securing-the-mcp-layer-discovery-risk-scoring-and-governance-for-agent-to-api-access/"
 },
 {
  "id": 41,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "11:10",
  "end": "11:30",
  "track": [
   "Securing MCP in the Enterprise"
  ],
  "room": [
   "C10"
  ],
  "title": "MCP Is Not a Security Boundary",
  "speakers": [
   {
    "name": "Yossi Eliaz",
    "title": "Principal Engineer & Applied Scientist",
    "company": "Incredibuild"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "auth_scheme_strength",
   "mcp_server"
  ],
  "why": "MCP defines discovery and calls, not access boundaries: scoped credentials, sandboxes and egress brokering.",
  "abstract": "Problem: Teams wiring AI agents into MCP servers often assume the protocol enforces access boundaries, but it doesn’t. MCP defines how agents discover and call tools, not what those tools are allowed to touch, so a single prompt injection or tool-chaining bug can turn into a credential exfiltration path. Solution: This talk breaks down where MCP’s trust model actually ends, walks through real failure modes when agents get more access than intended, and shows practical patterns for sandboxing, credential scoping, and egress brokering that keep the API surface honest. Audience takeaways: Attendees leave with a checklist for auditing their own MCP-connected agent deployments and concrete architecture patterns — credential-free sandboxes, scoped tokens, anomaly monitoring — they can apply to any agent-to-API integration this week.",
  "url": "https://nordicapis.com/sessions/mcp-is-not-a-security-boundary/"
 },
 {
  "id": 42,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:30",
  "end": "10:50",
  "track": [
   "API Reliability & Protection"
  ],
  "room": [
   "C8"
  ],
  "title": "Schema-Based Contract Testing: Preventing API Drift in Practice",
  "speakers": [
   {
    "name": "Dr. Miriam Greis",
    "title": "Principal Integration Architect",
    "company": "adorsys GmbH&Co. KG"
   }
  ],
  "facets": [
   "contract_quality",
   "contract_governance",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [],
  "why": "Schema-based contract testing against OpenAPI drift, with Portman.",
  "abstract": "OpenAPI descriptions are often incomplete or outdated, which makes API drift a common problem. Over time, descriptions and implementations diverge, leading to broken integrations and frustrated consumers. In this talk, we explore how schema-based contract testing helps detect and prevent API drift early, drawing on real-world experience. After a brief introduction on API testing and a comparison of different contract testing approaches, I’ll demonstrate how to implement schema-based contract testing with Portman. Portman is an open source tool that injects contract and variation tests into API collections with minimal configurations in JSON or YAML. The advantages of schema-based contract testing are clear: It’s easy to learn, easy to control, and comes with low maintenance overhead. However, schema-based contract testing is not a silver bullet, so knowing its limits is key. You’ll leave with best practices, common pitfalls, and a clear path to getting started with schema-based contract testing, including the knowledge to decide when this approach is the right fit.",
  "url": "https://nordicapis.com/sessions/schema-based-contract-testing-preventing-api-drift-in-practice/"
 },
 {
  "id": 43,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "10:50",
  "end": "11:10",
  "track": [
   "API Reliability & Protection"
  ],
  "room": [
   "C8"
  ],
  "title": "Beyond Status Codes: Enforcing Process Integrity When AI Agents Call Your APIs",
  "speakers": [
   {
    "name": "Hongliu Cao",
    "title": "Senior Artificial Intelligence Researcher",
    "company": "Amadeus"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality",
   "upsert",
   "accountability"
  ],
  "agent_readiness_dimensions": [
   "reversibility_documented",
   "dry_run_mode",
   "error_semantics",
   "idempotency"
  ],
  "why": "27-78% of 'successful' agent transactions broke a procedure: a 200 OK is not the outcome. Execute, verify, confirm for irreversible writes.",
  "abstract": "AI agents are increasingly consuming APIs autonomously, booking flights, processing refunds, and querying databases without a human in the loop. Current monitoring treats every correct API response as a success. But what happens between calls matters: an agent might issue a refund without first verifying identity, skip a required confirmation step, or hallucinate policy details to the customer while the API dutifully returns 200 OK. We formalize these failures as violations of procedure contracts: typed constraints over agent-API interaction sequences. Each constraint type captures a distinct failure mode. Forbid blocks conditions that must never hold (e.g., communicating data not returned by any prior API call). Order enforces temporal sequencing (e.g., authentication must precede any write). Ground requires that agent statements to users be entailed by actual API responses. Scope restricts operations to authorized boundaries. When we applied these contracts to frontier models on realistic service scenarios, 27–78% of “”successful”” transactions violated at least one procedural constraint. Each model fails differently, and smarter agents make subtler mistakes that are harder to detect and costlier when they reach your customers. Attendees will learn: (1) how to derive procedure contracts for their own APIs using a two-question method (what can go wrong for any operator, and what additionally can go wrong because the operator is an LLM agent), (2) a three-step enforcement pattern for irreversible actions (execute, verify, confirm) and how grounded-response requirements make fabrication structurally impossible, and (3) why gated deployment metrics that reject corrupt successes should replace raw success rates before any agent touches production traffic.",
  "url": "https://nordicapis.com/sessions/beyond-status-codes-enforcing-process-integrity-when-ai-agents-call-your-apis/"
 },
 {
  "id": 44,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "11:10",
  "end": "11:30",
  "track": [
   "API Reliability & Protection"
  ],
  "room": [
   "C8"
  ],
  "title": "The AI-Powered Threat Frontier: Why API Security Is Your Ultimate Defense",
  "speakers": [
   {
    "name": "Martijn Doedens",
    "title": "Principal Enterprise Security Architect",
    "company": "Akamai Technologies"
   }
  ],
  "facets": [
   "operational_transparency",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "rate_limit_signal"
  ],
  "why": "AI-automated attacks against APIs, and AI-driven behavioural defence.",
  "abstract": "As artificial intelligence reshapes software development and attack vectors alike, APIs stand directly in the crosshairs. Adversaries now leverage AI to automate zero-day discovery, craft sophisticated logic attacks, and mimic legitimate traffic at scale. At the same time, AI models rely heavily on API ecosystems, introducing entirely new data exposure risks. This session examines the dual role of AI in API security: how attackers exploit modern API architectures and how defense teams can deploy AI-driven behavioral analytics to stay ahead. Attendees will walk away with actionable strategies to secure both traditional and AI-integrated APIs against the next generation of automated threats.",
  "url": "https://nordicapis.com/sessions/the-ai-powered-threat-frontier-why-api-security-is-your-ultimate-defense/"
 },
 {
  "id": 45,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:30",
  "end": "12:50",
  "track": [
   "Production Agent Systems"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "The Agent Harness: Your New API Gateway",
  "speakers": [
   {
    "name": "Natalia Venditto",
    "title": "Principal Software Engineer",
    "company": "Adobe"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency",
   "upsert"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity",
   "idempotency"
  ],
  "why": "The agent harness has become the gateway: auth, routing, retries and observability that nobody designed.",
  "abstract": "Your API gateway has always been at the front door to your services. It was supposed to always be there. Now your AI agent is out back, hopping fences, calling APIs you didn’t sanction, chaining tools you didn’t anticipate, and somehow, somehow, it’s in production! The agent harness has quietly become your new gateway: handling auth, routing, retries, and observability, but nobody designed it that way. Let’s fix that before your on-call rotation does.",
  "url": "https://nordicapis.com/sessions/the-agent-harness-your-new-api-gateway/"
 },
 {
  "id": 46,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:50",
  "end": "13:10",
  "track": [
   "Production Agent Systems"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "The API Guardrails Behind Safe Multi-Tenant AI Platforms",
  "speakers": [
   {
    "name": "Luca Berton",
    "title": "AI Advisor/Architect",
    "company": "Open Empower"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency",
   "access_clarity"
  ],
  "agent_readiness_dimensions": [
   "rate_limit_signal"
  ],
  "why": "Agent-ready platform APIs on shared infrastructure: tenancy, quota-aware interfaces, telemetry, cost controls.",
  "abstract": "AI agents do not just need model access. They need reliable, well-governed APIs that expose capabilities safely, predictably, and with the right operational guardrails. In practice, most organizations are still building AI on shared infrastructure where isolation, quota management, observability, rollout safety, and performance trade-offs matter as much as inference quality. In this session, I will share lessons from designing multi-tenant AI platforms on Red Hat OpenShift AI with NVIDIA MIG-based GPU partitioning, workload orchestration, and platform controls in regulated enterprise environments. The talk will focus on the API and platform patterns that make AI systems consumable by internal teams, applications, and increasingly by autonomous agents. I will cover common failure modes, including weak tenancy boundaries, poor workload scheduling, brittle upgrades, and APIs that expose models without sufficient policy, telemetry, or cost controls. I will then show a practical blueprint for designing agent-ready platform APIs: clear service boundaries, policy enforcement, quota-aware interfaces, traceable execution paths, and day-2 operational playbooks. Attendees will leave with a concrete checklist to evaluate whether their APIs and underlying platform are actually ready for machine-driven consumption, not just human developers. The goal is to help teams move from isolated AI experiments to secure, reusable, production-grade platform.",
  "url": "https://nordicapis.com/sessions/the-api-guardrails-behind-safe-multi-tenant-ai-platforms/"
 },
 {
  "id": 47,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "13:10",
  "end": "13:30",
  "track": [
   "Production Agent Systems"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Your JWT Is Valid. Should Your API Still Trust It?",
  "speakers": [
   {
    "name": "Thomas Darimont",
    "title": "Principal Consultant",
    "company": "Identity Tailor GmbH"
   }
  ],
  "facets": [
   "agent_readiness",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "auth_scheme_strength"
  ],
  "why": "Shared Signals and CAEP: re-evaluate access when context changes instead of trusting a bearer token until it expires.",
  "abstract": "Modern API security largely revolves around OAuth access tokens: authenticate a client or user, issue a token, and let APIs trust that token until it expires. But what happens when the security context changes while the token is still valid? An account may be disabled, a device compromised, credentials stolen, or a session classified as high risk. In a zero trust architecture, APIs should be able to react to these changes immediately rather than waiting for tokens to expire. This session explores how the OpenID Shared Signals Framework (SSF) and Continuous Access Evaluation Profile (CAEP) can provide an event-driven security layer for APIs. We will look at how identity providers, security systems, API gateways, and resource servers can exchange security signals and continuously re-evaluate access. Using OAuth, Keycloak, and practical API scenarios, we’ll explore how shared signals can bridge the gap between traditional token-based API authorization and continuous zero trust enforcement.",
  "url": "https://nordicapis.com/sessions/your-jwt-is-valid-should-your-api-still-trust-it/"
 },
 {
  "id": 48,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:30",
  "end": "12:50",
  "track": [
   "AI & API Gateways"
  ],
  "room": [
   "C10"
  ],
  "title": "Governing the Agentic Era",
  "speakers": [
   {
    "name": "Johan Dahlstöm",
    "title": "Regional Director, Nordics",
    "company": "Kong Inc"
   }
  ],
  "facets": [
   "contract_governance",
   "accountability",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [],
  "why": "Vendor session: one governance layer across AI workloads at Nordic banks and retailers.",
  "abstract": "The fear that competitors will innovate faster defines the agentic era. But speed alone is a fast way to fail. 95% of AI initiatives go nowhere, margins are eroding, and shadow AI now drives one in five breaches. The problem is fragmentation. This session shows how Kong AI Gateway brings every AI workload under one governance layer, and how leading Nordic banks, retailers, and tech companies are moving from proof of concept to production to platform.",
  "url": "https://nordicapis.com/sessions/governing-the-agentic-era/"
 },
 {
  "id": 49,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:50",
  "end": "13:10",
  "track": [
   "AI & API Gateways"
  ],
  "room": [
   "C10"
  ],
  "title": "What Happens When LLMs and AI Agents Meet Your API Gateway",
  "speakers": [
   {
    "name": "Anupama Sharma",
    "title": "Platform Engineer",
    "company": "ICA Gruppen"
   }
  ],
  "facets": [
   "operational_transparency",
   "agent_readiness",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [
   "rate_limit_signal",
   "auth_clarity"
  ],
  "why": "What a retailer's gateway had to become once LLMs arrived: identity, throttling, schema validation, masking, observability.",
  "abstract": "When curious LLMs and autonomous AI agents knock on your API gateway, expect context-laden chaos. The enterprise gateway must become the governance layer: authenticate identities, rate-limit the party, negotiate schemas, validate payloads, mask secrets, and amplify real-time observability. Add adaptive throttling and dynamic policy enforcement to block prompt injections and data leaks — and evolve faster than the AI tide. In this talk, ICA will show how the AI elephant arrived, what perceptions it triggered, and when (and by what measures) the tech department tackled these challenges with rollout schedules and easy operational guides.",
  "url": "https://nordicapis.com/sessions/what-happens-when-llms-and-ai-agents-meet-your-api-gateway/"
 },
 {
  "id": 50,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "13:10",
  "end": "13:30",
  "track": [
   "AI & API Gateways"
  ],
  "room": [
   "C10"
  ],
  "title": "Evolving From API Gateway to AI Gateway",
  "speakers": [
   {
    "name": "Dan Erez",
    "title": "Chief Architect",
    "company": "Aman Group"
   }
  ],
  "facets": [
   "operational_transparency",
   "access_clarity"
  ],
  "agent_readiness_dimensions": [
   "rate_limit_signal"
  ],
  "why": "Model routing, quota tracking and guardrails on top of a classic gateway.",
  "abstract": "API gateways are an essential part of most systems that expose APIs, with functionality like routing, caching, and security. However, exposing large language model (LLM)-based APIs requires additional functionality, including model routing, quota tracking, guardrails, output formatting, and much more. In this talk, I’ll examine the perfect API gateway and help you choose the best option for your needs.",
  "url": "https://nordicapis.com/sessions/evolving-from-api-gateway-to-ai-gateway/"
 },
 {
  "id": 51,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:30",
  "end": "12:50",
  "track": [
   "Agentic Commerce"
  ],
  "room": [
   "C8"
  ],
  "title": "MCP Monetization",
  "speakers": [
   {
    "name": "Josh Twist",
    "title": "Co-Founder and CEO",
    "company": "Zuplo"
   }
  ],
  "facets": [
   "access_clarity",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "agentic_commerce",
   "mcp_server"
  ],
  "why": "Headless SaaS: charging for the work agent swarms generate over MCP.",
  "abstract": "A new era is arriving to SaaS. You saw Marc Benioff (Salesforce CEO) announce the end of UI and the birth of ‘headless SaaS’. A single user can now generate so much work for your systems via their swarms of agents. It’s time to make money from all those agents using your data and services — let’s talk about monetizing MCP.",
  "url": "https://nordicapis.com/sessions/mcp-monetization/"
 },
 {
  "id": 52,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "12:50",
  "end": "13:10",
  "track": [
   "Agentic Commerce"
  ],
  "room": [
   "C8"
  ],
  "title": "When Agents Become Customers: Building Pay-Per-Use APIs with the Machine Payments Protocol",
  "speakers": [
   {
    "name": "Sumit Amar",
    "title": "Vice President of Engineering",
    "company": "WEX"
   }
  ],
  "facets": [
   "agent_readiness",
   "access_clarity",
   "regulatory"
  ],
  "agent_readiness_dimensions": [
   "agentic_commerce"
  ],
  "why": "HTTP 402 with the Machine Payments Protocol: an agent pays per call with no sign-up and no API key. Plans and sign-up, redone for agents.",
  "abstract": "This session dives deep into building APIs that accept transactional payments using card payment methods and into empowering agents that transact on behalf of users. This session will introduce x402 for comparison but will index on Machine Payments Protocol (MPP) for agentic commerce. The session will demonstrate a reference implementation of powering HTTP status code 402 (Payment Required) with MPP to accept card payments. The session will also cover building clients that work with Stripe’s Shared Payment Tokens (SPTs) to make payments. This mechanism alleviates the need to sign up for a paid API and source API keys.",
  "url": "https://nordicapis.com/sessions/when-agents-become-customers-building-pay-per-use-apis-with-the-machine-payments-protocol/"
 },
 {
  "id": 53,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "13:10",
  "end": "13:30",
  "track": [
   "Agentic Commerce"
  ],
  "room": [
   "C8"
  ],
  "title": "The Business Case for Secure API Access in the Age of AI",
  "speakers": [
   {
    "name": "Sutton Maxwell",
    "title": "Chief Revenue Officer (CRO)",
    "company": "Curity"
   }
  ],
  "facets": [
   "access_clarity",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "auth_clarity"
  ],
  "why": "Identity as a business enabler for exposing APIs to AI: the trust and compliance side of Access Clarity.",
  "abstract": "As AI agents become increasingly involved in business processes, secure API access is becoming a critical foundation for adopting AI safely at scale. Strong identity and access controls can help organizations expose valuable APIs and data to AI systems without sacrificing security, governance, or compliance. This session explores how modern identity approaches can reduce risk while enabling organizations to move faster with new AI-driven use cases. We’ll examine why treating identity as a business enabler, rather than simply a security requirement, is essential in the age of AI.",
  "url": "https://nordicapis.com/sessions/the-business-case-for-secure-api-access-in-the-age-of-ai/"
 },
 {
  "id": 54,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "13:50",
  "end": "14:10",
  "track": [
   "Emerging Agentic Architecture"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "API Standards for AI Agents",
  "speakers": [
   {
    "name": "Lorna Mitchell",
    "title": "API Architect",
    "company": "TM Forum"
   }
  ],
  "facets": [
   "contract_governance",
   "contract_quality",
   "regulatory",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [
   "error_semantics"
  ],
  "why": "Layered standards: shared vocabulary, expected behaviour including errors, and industry specifications as grounding for agents.",
  "abstract": "AI agents are expected to act reliably across domains they’ve never seen, with inadequate documentation and inconsistent experiences. Layered API standards turn our dreams from impossible into achievable: an agreed vocabulary, established expectations of behavior including error cases, and patterns already proven to be effective in the real world. From the conventions that built the web to industry-specific specifications, the standards stack is the grounding and the context that our AI use cases need to succeed. Come and see how your specifications become leverage for AI, not legacy overhead.",
  "url": "https://nordicapis.com/sessions/api-standards-for-ai-agents/"
 },
 {
  "id": 55,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "14:10",
  "end": "14:30",
  "track": [
   "Emerging Agentic Architecture"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "Hide the Broker: A2A Should Stay HTTP, Event-Driven Underneath",
  "speakers": [
   {
    "name": "Swen-Helge Huber",
    "title": "Senior Director, Office of the CTO",
    "company": "Solace"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_quality"
  ],
  "agent_readiness_dimensions": [
   "agent_card",
   "event_surface_described"
  ],
  "why": "Keep A2A request/response over HTTP and put the broker underneath for fan-out and replay.",
  "abstract": "Chain a few agents over synchronous HTTP, and latency, resilience, and fan-out problems arrive on schedule. The obvious fix: give A2A a native MQTT or AMQP binding. Feels right to anyone from the event-driven world. Wrong fix. A2A is inherently request/response. Swap HTTP for a messaging protocol and the conversation doesn’t change, it just drags broker semantics into a contract that doesn’t want them. The broker’s value sits beneath the interface: fan-out, replay, absorbing the speed mismatch between fast models and slow tools. Fan-out earns its keep beyond resilience too: route the same request to agents with different model origins and different primary sources, and you get competing analysis, not one model’s blind spot dressed up as an answer.",
  "url": "https://nordicapis.com/sessions/hide-the-broker-a2a-should-stay-http-event-driven-underneath/"
 },
 {
  "id": 56,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "14:30",
  "end": "14:50",
  "track": [
   "Emerging Agentic Architecture"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "AI as a New Architectural Domain in an API and Event-Driven Platform",
  "speakers": [
   {
    "name": "Axel Vuylsteke",
    "title": "Enterprise Integration Architect",
    "company": "The Value Hub"
   }
  ],
  "facets": [
   "discoverability",
   "operational_transparency",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [
   "mcp_server"
  ],
  "why": "An intelligence domain that knows which consumers a schema change breaks and which integrations to retire.",
  "abstract": "Organizations have spent years building API-first and event-driven architectures, yet understanding and operating modern integration landscapes still depends heavily on tribal knowledge. Critical information is scattered across API specifications, event streams, monitoring tools, documentation, business domains and operational dashboards. This talk introduces the concept of an Intelligence Domain: a new architectural layer within the integration platform that continuously consumes APIs, events, metadata, telemetry, and business context to create a cognitive view of the ecosystem. Rather than adding a chatbot on top of existing tools, this domain becomes a first-class platform capability that understands how systems, events, consumers, and partners are connected. Combining event-driven architecture, knowledge graphs, semantic search, and AI agents through standards such as MCP (Model Context Protocol), the platform can answer questions like: Which consumers are affected by this schema change?, Why are partners missing updates?, or Which integrations should be modernized or retired? Attendees will learn how integration platforms can evolve beyond exposing capabilities to becoming intelligent systems that understand, operate, and optimize the APIs and events they manage. The next evolution of integration is not just API-first or event-driven—it is AI-native.",
  "url": "https://nordicapis.com/sessions/ai-as-a-new-architectural-domain-in-an-api-and-event-driven-platform/"
 },
 {
  "id": 57,
  "day": "2026-10-14",
  "type": "Lightning",
  "start": "13:50",
  "end": "14:05",
  "track": [
   "Demos & Lightning Talks: Day 2"
  ],
  "room": [
   "C10"
  ],
  "title": "Securing AI Agents: A Practical Guide to Building an Agentic Platform",
  "speakers": [
   {
    "name": "Isabelle Mauny",
    "title": "Field CTO",
    "company": "WSO2"
   }
  ],
  "facets": [
   "agent_readiness",
   "accountability",
   "operational_transparency"
  ],
  "agent_readiness_dimensions": [
   "agent_identity_declared",
   "mcp_server"
  ],
  "why": "The attack surface growing from an LLM integration to an autonomous agent: identity, auditable chains, the MCP supply chain.",
  "abstract": "Every enterprise is deploying AI agents, but security thinking hasn’t kept pace. Most teams bolt on guardrails after deployment — or treat the LLM itself as a trusted component. This session traces a single application as it evolves from a basic LLM integration into a fully autonomous agent, exposing how the attack surface expands at each stage: LLMs are nondeterministic execution engines — yet we grant them tool access, data access, and decision-making authority. Third-party integrations and the Model Context Protocol create a supply chain attack surface that most teams aren’t vetting. Agents operate across trust boundaries with no standardized identity, no auditable execution chain, and no rogue-detection mechanism. At each stage, we ask: What can go wrong? Who is accountable? How do we prove it? You’ll leave with a practical security architecture you can apply to your own agentic deployments.",
  "url": "https://nordicapis.com/sessions/securing-ai-agents-a-practical-guide-to-building-an-agentic-platform/"
 },
 {
  "id": 58,
  "day": "2026-10-14",
  "type": "Lightning",
  "start": "14:05",
  "end": "14:20",
  "track": [
   "Demos & Lightning Talks: Day 2"
  ],
  "room": [
   "C10"
  ],
  "title": "Blind Spots to Blocked Threats: Akamai API Security Live in 10 Minutes",
  "speakers": [
   {
    "name": "Martijn Doedens",
    "title": "Principal Enterprise Security Architect",
    "company": "Akamai Technologies"
   }
  ],
  "facets": [
   "operational_transparency",
   "discoverability"
  ],
  "agent_readiness_dimensions": [],
  "why": "Vendor demo: finding shadow APIs and blocking attacks in real time.",
  "abstract": "APIs are the engine of modern applications, but they are also the primary vector for sophisticated cyberattacks. In this fast-paced live demo, watch how Akamai API Security uncovers hidden shadow APIs, monitors traffic for malicious behavioral patterns, and automatically neutralizes threats in real time. See firsthand how to turn your biggest API security blind spots into robust defense checkpoints without slowing down developer velocity.",
  "url": "https://nordicapis.com/sessions/blind-spots-to-blocked-threats-akamai-api-security-live-in-10-minutes/"
 },
 {
  "id": 59,
  "day": "2026-10-14",
  "type": "Lightning",
  "start": "14:20",
  "end": "14:35",
  "track": [
   "Demos & Lightning Talks: Day 2"
  ],
  "room": [
   "C10"
  ],
  "title": "The Autonomous Enterprise: Where Agents Execute on Your Lead",
  "speakers": [
   {
    "name": "Stefan Asanin",
    "title": "Senior Pre‑Sales Consultant",
    "company": "Axway"
   }
  ],
  "facets": [
   "agent_readiness",
   "developer_ergonomics"
  ],
  "agent_readiness_dimensions": [],
  "why": "Vendor demo: APIs as an integration backbone agents execute on. Thin API-surface signal.",
  "abstract": "In this demo, we’ll show how to turn APIs into a live integration backbone by connecting them to real systems and activating flows in a modern integration platform. From there, we extend the platform to expose capabilities and automate real business actions, creating a flexible foundation that can adapt as needs change. Finally, we explore how this foundation can support more advanced, intelligent execution of workflows end-to-end. Join us for a practical glimpse into how APIs, integrations, and AI come together to move from automation to true autonomy.",
  "url": "https://nordicapis.com/sessions/the-autonomous-enterprise-where-agents-execute-on-your-lead/"
 },
 {
  "id": 60,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "13:50",
  "end": "14:10",
  "track": [
   "AI & Platform Engineering"
  ],
  "room": [
   "C8"
  ],
  "title": "What ‘Agentic-Ready’ Actually Requires: A Platform Engineer’s Guide to AI-Native Observability",
  "speakers": [
   {
    "name": "Andi Mann",
    "title": "Chief Product and Technology Officer",
    "company": "Apica"
   }
  ],
  "facets": [
   "operational_transparency",
   "agent_readiness",
   "contract_quality"
  ],
  "agent_readiness_dimensions": [],
  "why": "What agentic-ready observability requires: latency, schema consistency, open data contracts agents can act on.",
  "abstract": "Every observability vendor claims their platform is ready for agentic AI. Almost none of them tell you what ‘agentic-ready’ actually requires from your infrastructure. In this practitioner-focused session, Andi Mann moves past the marketing and into the stack. Agentic AI systems have strict requirements that most current observability architectures fail to meet: sub-second pipeline latency, schema consistency across heterogeneous sources, intelligent routing that filters signal from noise before ingestion, and open data contracts that let agents act without vendor intermediaries. Drawing on Apica’s work building agentic-ready telemetry infrastructure for enterprise customers, Andi walks through a concrete five-part agentic-readiness framework that platform engineers and architects can apply to their own environments. Attendees will leave with a practical checklist, a clear vocabulary for evaluating vendor claims, and an honest assessment of how far most stacks are from being truly ready for autonomous AI operations.",
  "url": "https://nordicapis.com/sessions/what-agentic-ready-actually-requires-a-platform-engineers-guide-to-ai-native-observability/"
 },
 {
  "id": 61,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "14:10",
  "end": "14:30",
  "track": [
   "AI & Platform Engineering"
  ],
  "room": [
   "C8"
  ],
  "title": "Taking the “P” out of APIs: Dependability in the Age of Machine-Speed Execution",
  "speakers": [
   {
    "name": "Mayur Upadhyaya",
    "title": "CEO",
    "company": "APIContext"
   }
  ],
  "facets": [
   "operational_transparency",
   "agent_readiness"
  ],
  "agent_readiness_dimensions": [],
  "why": "5,600 monitored endpoints: a third degrade silently while the status page stays green. The rubric credits a status page's presence, not its honesty.",
  "abstract": "For the first time in internet history, machines and automated bots generate more web traffic than humans, fundamentally changing how digital services are consumed and operated. AI agent activity against APIs surged 300% in 2025 alone, and by 2028 Gartner projects that 80% of organizations will rely on AI agents as their primary API consumers. We are operating a machine internet on human-era assumptions, and the consequences are already visible in the data. Across 12 months of synthetic monitoring covering approximately 5,600 endpoints, the numbers tell a striking story. The vast majority of services maintain strong availability figures on paper, yet nearly a third exhibit silent degradation signals that never register as failures on a status page. Hard failure rates have stayed flat while tail-heavy degradation events rose 74% in a single year. The headline outages attract attention, but the more consequential signal is the slow drift beneath them. This drift is far more dangerous when machines are the consumers. Attendees will leave with a clearer framework for why availability and dependability are no longer the same thing, and what resilience strategy looks like in a machine-speed world.",
  "url": "https://nordicapis.com/sessions/taking-the-p-out-of-apis-dependability-in-the-age-of-machine-speed-execution/"
 },
 {
  "id": 62,
  "day": "2026-10-14",
  "type": "Talk",
  "start": "14:30",
  "end": "14:50",
  "track": [
   "AI & Platform Engineering"
  ],
  "room": [
   "C8"
  ],
  "title": "AI-Augmented Platform Engineering",
  "speakers": [
   {
    "name": "Alexander Troppmann",
    "title": "Lead Cloud-native Architect for Platform Integration",
    "company": "ZEISS Group"
   }
  ],
  "facets": [
   "developer_ergonomics",
   "contract_governance"
  ],
  "agent_readiness_dimensions": [],
  "why": "AI inside an API platform team's own workflow. Internal.",
  "abstract": "In this session, an experienced platform engineering team shares how it is using AI to make everyday work faster, more effective and more scalable across API management and the wider platform landscape. Through practical examples, the talk explores how AI can accelerate repetitive engineering tasks, improve developer workflows, strengthen automation, and help teams build and evolve platforms more efficiently. This is a practitioner’s view of where AI is already making a meaningful difference – with lessons and ideas that other platform teams can apply to their own work.",
  "url": "https://nordicapis.com/sessions/ai-augmented-platform-engineering/"
 },
 {
  "id": 63,
  "day": "2026-10-14",
  "type": "Keynote",
  "start": "15:20",
  "end": "15:45",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "TBD: Gravitee Keynote",
  "speakers": [],
  "facets": [],
  "agent_readiness_dimensions": [],
  "why": "Title not yet announced.",
  "abstract": "",
  "url": ""
 },
 {
  "id": 64,
  "day": "2026-10-14",
  "type": "Keynote",
  "start": "15:45",
  "end": "16:10",
  "track": [
   "Keynotes"
  ],
  "room": [
   "Bankettsalen"
  ],
  "title": "The Agent Hype is at Odds with Your API Foundation",
  "speakers": [
   {
    "name": "Kin Lane",
    "title": "API Evangelist",
    "company": "API Evangelist LLC"
   }
  ],
  "facets": [
   "agent_readiness",
   "contract_governance",
   "contract_quality",
   "operational_transparency",
   "access_clarity",
   "discoverability",
   "developer_ergonomics"
  ],
  "agent_readiness_dimensions": [
   "idempotency",
   "error_semantics",
   "auth_clarity",
   "consent_identity",
   "rate_limit_signal",
   "mcp_server",
   "agent_skills"
  ],
  "why": "My talk: the Kin Score facets as the foundation, Agent Readiness as the layer, and what the scored catalog says about the announcements.",
  "abstract": "As the API Evangelist I score roughly 25,000 providers on two independent instruments. My “”Kin Score”” is a 0–100 composite of governance fundamentals — contracts, documentation, security, support, operations, and a conditional regulatory layer that applies only to banking, health, payments, insurance, securities and government. Agent Readiness is a separate 0–100 rating across twelve dimensions, measuring whether an autonomous consumer can drive an API safely without a human filling in the gaps. The two are computed independently and never blended, which makes the relationship between them such an industry finding when it comes to cutting through the AI hype. The finding is that readiness is a layer, and a layer does not rise above its foundation. The dimensions that separate the agent-native band from everyone else — idempotency, error semantics an agent can branch on, auth and consent clarity, rate-limit signalling — are not AI features. They are governance disciplines that were always supposed to be there, now load-bearing in a way they never were when a human developer was around to work around them. An agent does not consume an endpoint; it tries to complete a capability, and it fails at whichever contract in that chain is ungoverned. Enterprises and startups are racing to deploy MCP servers and publish Agent Skills to meet this moment, but without a proper API foundation that is well designed and governed, we are just assembling a house of cards. With the Kin Score I intend to cut through the hype and show were the press releases and mandates are not aligned with the foundation in which enterprises have built their businesses over the last 25 years. It can be tough to make sense of which companies have a handle on this moment from the stories we are all being bombarded with, and as a storyteller, it is important to me that we are able to tell. This session walks the rubric facet by facet, shows what each one becomes once an agent is the consumer, and reads the scored catalog for what actually moves readiness — including the negative finding that shipping an MCP server on top of an ungoverned API does not move the number, and in a governed portfolio makes things worse by handing agents a confident interface to an unreliable contract. Governance is shifting from an offensive strategy to a defensive one, and the foundation underneath your platform is what determines how much of the agentic era you can absorb. The governance facets that become load-bearing the moment an agent is the consumer instead of a developer, and why readiness is bounded by the least-governed contract in a capability path. Why agent readiness scored separately from governance is the only way to prove the dependency between them — and what the scored catalog says about how far most portfolios actually are. How to map capabilities to contracts to scores and get a defensible readiness number for your own estate, instead of a press release.",
  "url": "https://nordicapis.com/sessions/the-agent-hype-is-at-odds-with-your-api-foundation/"
 }
]