World Congress 2026 Europe Jul 9, 2026 Session details

The Private AI Platform: Why Agentic Apps Need a Private Application Platform

Oren Penso

Soft prompt boundaries won't stop an autonomous agent from exploiting enterprise resources. Discover why securely scaling agentic apps demands a private platform built on zero-trust runtime containment.

Pause
Mute Enter Fullscreen
#1 about 1 min

Defining an AI agent as an application setup

Treating an AI agent as a standard software application requires connecting a large language model to serve as its reasoning engine.

#2 about 2 min

Equipping AI agents with memory and context

Connecting long-term and short-term memory through databases or retrieval-augmented generation reduces token costs and improves contextual relevance.

#3 about 2 min

Securing data privacy and defining agent identity

Establishing a clear system prompt shapes the agent's behavior to produce deterministic responses without exposing private information during inference.

#4 about 1 min

Managing soft boundaries to prevent unintended behavior

Instructions provided via files serve as soft boundaries that agents can breach, necessitating strict environment guardrails to avoid catastrophic operations.

#5 about 2 min

Providing agents with network actions and connections

Granting execution capabilities via shell commands or the model context protocol requires strict oversight because unconstrained automation will actively reach out to external endpoints.

#6 about 2 min

Deploying agents inside isolated runtime environments

Running agentic workloads in stripped-down micro virtual machines or custom containers restricts excessive hardware capabilities and shared kernel permissions.

#7 about 2 min

Harnessing super applications on private on-premises clouds

Maintaining internal orchestration layers enables enterprise customers to govern multi-agent task fleets while avoiding expensive public hardware conflicts.

#8 about 2 min

Mitigating agent risks with zero trust networking

Adopting runtime containment and strict network isolation ensures an AI workload starts with zero access and earns permissions dynamically.

#9 about 1 min

Managing agent identity and centralized middleware auditing

Centralizing identity checks and infrastructure access through a single AI middleware helps enforce just-in-time constraints and comprehensive deployment auditing.

#10 about 2 min

Configuring a baseline isolated agent on Tanzu platform

Initializing an open-source PyDantic framework in a local home lab demonstrates an application sandbox devoid of external network capabilities.

#11 about 2 min

Building secure baseline containers using cloud native buildpacks

Pushing a single markdown specification file directly to cloud native buildpacks automatically compiles a secure baseline container image.

#12 about 3 min

Attaching offline open-source language models to agents

Binding a local generative intelligence model as the reasoning engine provisions brainpower to the local runtime without transmitting sensitive requests publicly.

#13 about 3 min

Introducing tools via model context protocol servers

Deploying a model context protocol server grants the isolated application strict, conditional access to web searches and execution commands.

#14 about 4 min

Giving external data access through internal memory APIs

Interfacing the conversational endpoint with a Postgres database and retrieval-augmented generation routines dynamically expands recall capability while confining internal queries.

#15 about 3 min

Enforcing data scrubbing policies with open-source Presidio

Rerouting generation completions via Presidio actively scrubs identifiable user details from textual logs to enforce internal compliance standards automatically.

#16 about 2 min

Delegating queries to specialized sub-agents and peers

Linking the primary chat interface to nested platform nodes enables delegated command chains for robust administrative cloud tasks.

Matching moments

3:45 min

Fusing developer experience and platform engineering for agentic SDLC

Julia Kordick Julia Kordick · World Congress 2026 Europe

2:52 min

Designing agentic AI solutions for the enterprise

Damir Dobric · Coffee With Developers

1:44 min

Introduction to the Model Context Protocol security agenda

Jose Manuel Ortega Jose Manuel Ortega · Europe 2026 Virtual

2:28 min

Mitigating excessive agency through scoped tool access

Deepu Deepu · World Congress 2025

1:55 min

Current state of security in AI applications

Deepu Deepu · World Congress 2025

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 7

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

Yoav Gal, Dor Cohen

Yoav Gal
Dor Cohen
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 3

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Šelajev

AI and Developer relations at Docker

Oleg Šelajev
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Mainstage

I Don't Trust AI Agents (And Neither Should You): Building Production-Ready Architectures

Darko Mesaros

Distinguished Developer Advocate at AWS

Darko Mesaros
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Outdoor Stage

MicroAgents: The Microservices of the Agentic Era

Ashish Shubham

Runs the show bussiness at ThoughtSpot

Ashish Shubham