As companies move AI agents from experimental copilots into systems that can access enterprise data and perform real-world tasks, the industry’s biggest challenges are shifting from model capability to infrastructure, security and control. AGNTCon + MCPCon Japan 2026, scheduled for September 10–11 in Tokyo, will bring developers and enterprise engineering teams together to examine how agentic AI can be built, evaluated and governed at production scale.
The next phase of enterprise AI may depend less on how intelligent an individual model becomes and more on whether organizations can safely connect multiple AI agents to the systems they already operate.
That is the central issue behind AGNTCon + MCPCon Japan 2026, an event organized by the Agentic AI Foundation (AAIF) and taking place September 10–11 at Belle Salle Shibuya Garden in Tokyo.
The conference is expected to bring together developers, infrastructure engineers and enterprise technology leaders from across Asia-Pacific, with more than 40 sessions covering agent orchestration, interoperability, evaluation, security and multi-agent systems.
The timing reflects a broader shift in enterprise AI.
Companies are increasingly experimenting with AI agents that can retrieve information, invoke tools, make decisions and execute multi-step workflows. But giving an AI system access to internal databases, software applications or operational systems introduces a different class of engineering problems.
Who is allowed to authorize an agent? What happens when two agents interact? How can an organization reconstruct an agent’s actions after an incident? And how can teams determine whether an autonomous system is actually reliable enough for production?
These questions feature prominently in the Japan conference program.
Trust becomes an infrastructure problem
One of the featured sessions examines trust boundaries for agent-to-agent systems, drawing on a technical proof of concept from SoftBank Corp.
That topic reflects a key challenge in multi-agent architectures. Traditional software generally has explicit permissions and predictable execution paths. Autonomous agents can dynamically select tools, delegate tasks and interact with other agents, making authorization and accountability more complicated.
Enterprise teams therefore need controls around identity, permissions, approval gates, logging and auditability.
The problem becomes even more important when agents interact with sensitive corporate systems.
The conference’s program includes sessions on reliable agent systems, multi-agent and distributed systems, agentic engineering, interoperability, protocols and standards. Speakers include representatives from Adobe, Anthropic, Google, IBM, JPMorgan Chase, Microsoft, Red Hat, Uber and Walmart Global Tech, alongside Japanese technology organizations including Hitachi, SoftBank and NTT.
MCP moves toward enterprise infrastructure
A major part of the event will focus on the Model Context Protocol (MCP), an open protocol designed to standardize how AI applications connect to external tools and data sources.
MCP has become an important part of the emerging agent ecosystem because it addresses a practical integration problem: developers increasingly need AI systems to interact with services beyond the model itself.
Instead of building bespoke connectors for every AI application and every tool, standardized protocols can potentially make those connections easier to develop and maintain.
That does not eliminate the security problem, however. It makes questions around authentication, authorization, transport and lifecycle management more important.
The MCPCon track will therefore cover areas including identity and authorization, transport mechanisms, task lifecycle specifications and operating MCP infrastructure at scale. David Soria Parra, an Anthropic member of technical staff and MCP co-creator, is also scheduled to deliver a keynote.
For enterprise architects, this is arguably more consequential than another discussion about which foundation model performs best on a benchmark.
If agents become a standard software layer, the protocols connecting them to enterprise systems could become part of the industry’s underlying infrastructure.
Testing autonomous systems is different
Another focus is agent evaluation.
Conventional software testing assumes relatively deterministic behavior. AI agents introduce probabilistic outputs, changing prompts, dynamic tool selection and potentially unpredictable chains of actions.
That means organizations need to evaluate more than whether an application returns the correct answer.
They may need to test whether an agent selects the right tool, respects authorization policies, handles unexpected inputs, recovers from failure and avoids introducing regressions when its underlying model or prompt changes.
A featured session from PagerDuty will examine an open-source evaluation pipeline for AI agents, highlighting the growing effort to make agent behavior more measurable and repeatable.
This is an important development for enterprise adoption. Without reliable evaluation infrastructure, deploying autonomous systems at scale can become a governance problem as much as a technical one.
The open-source agent stack is still taking shape
The event also highlights a less obvious challenge: there is no single standardized “agent stack” yet.
Companies are combining foundation models, orchestration frameworks, vector databases, identity systems, observability platforms, tool protocols and custom application logic.
Hitachi speakers will discuss lessons from integrating open-source components and what remains missing from the open agentic stack.
That fragmentation creates both opportunity and risk.
Open technologies can prevent organizations from becoming dependent on a single vendor, while also giving developers greater control over infrastructure. But assembling a production-grade agent platform from numerous components can create operational complexity.
The companies building today’s AI infrastructure — from Microsoft and Google to Anthropic, IBM and Red Hat — are therefore competing not only on models, but increasingly on the surrounding software ecosystem.
What enterprises should take away
For enterprise technology teams, the important message from AGNTCon + MCPCon Japan is that agentic AI is becoming an infrastructure discipline.
Organizations moving beyond pilots will need to consider identity, observability, evaluation, security and interoperability alongside model selection.
Certification is also becoming part of that ecosystem. Attendees at the event will have access to discounted pathways for the Model Context Protocol Associate (MCPA) Certification, designed to validate knowledge of MCP standards, tooling and ecosystem practices.
The larger direction is clear.
AI agents are moving from isolated interfaces toward software systems that can act on behalf of organizations. As that happens, protocols such as MCP, evaluation frameworks and governance mechanisms may become as important to enterprise AI deployment as the underlying models.
Tokyo’s AGNTCon + MCPCon program offers a snapshot of that transition — from demonstrating what agents can do to figuring out how companies can safely let them do it.
Market Landscape
The agentic AI market is evolving from model-centric experimentation toward a broader software and infrastructure stack.
Key layers include:
- Foundation models: Google Gemini, Anthropic Claude, OpenAI models and other LLMs.
- Agent frameworks: Tools for orchestration, planning, tool use and multi-agent coordination.
- MCP and interoperability: Standardized mechanisms for connecting agents with external tools and data.
- Identity and security: Authentication, authorization, sandboxing and policy enforcement.
- Observability: Monitoring agent actions, tool calls, costs and failures.
- Evaluation: Testing agent reasoning, routing, tool selection and reliability.
- Enterprise governance: Audit trails, human approval and regulatory controls.
The competitive opportunity is increasingly shifting toward the infrastructure surrounding AI agents. For enterprises, interoperability may ultimately matter as much as raw model performance because organizations rarely operate their entire technology stack through a single vendor.
Top Insights
- AGNTCon + MCPCon Japan will examine enterprise AI agent security, interoperability and evaluation as autonomous systems move into production workflows.
- MCPCon focuses on Model Context Protocol infrastructure, authorization and task lifecycles, reflecting MCP’s growing role in connecting AI agents with enterprise tools.
- SoftBank, Hitachi and other Japanese technology leaders will share practical lessons on multi-agent trust boundaries and open-source agent infrastructure.
- Agent evaluation is becoming a core enterprise requirement as teams test tool selection, routing behavior, regressions and autonomous decision-making before deployment.
- The event highlights a broader shift from AI model competition toward standardized protocols, security layers and infrastructure for production-grade agentic systems.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












