Session
Description:
As AI systems evolve from chatbots into agents capable of planning, calling tools and executing workflows, public institutions face a new governance challenge. Open-source AI agents may strengthen transparency, local adaptation, digital sovereignty and public-sector capacity building, but they also raise urgent questions around cybersecurity, accountability, procurement, liability and human oversight. This workshop examines how open-source agentic AI should be governed when deployed in public- interest contexts. It will begin with a concise state-of-the-art briefing explaining the current open- source agentic AI stack, including open models, agent frameworks, tool integration, permission layers, runtime environments, evaluation methods and monitoring. The briefing will highlight why agents differ from conventional AI applications: they do not only generate outputs, but can interact with systems and produce real-world consequences. The main part of the session will be interactive. Participants from government, academia, technical communities, civil society and industry will map key risks, including prompt injection, excessive agency, insecure tool access, data leakage, weak auditability and unclear responsibility for agent actions. The discussion will then move from risk identification to governance design: what should regulation require, what should public procurement demand, what should be treated as public digital infrastructure, and what can remain market-led or community-led? The session will explore whether an Open Agentic AI Commons could support responsible public- sector adoption through shared evaluation tools, procurement templates, reference architectures, security practices, training resources, and deployment playbooks. The goal is not to promote open- source AI uncritically, but to examine how openness, security, accountability, and public capacity can be aligned.
As AI systems evolve from chatbots into agents capable of planning, calling tools and executing workflows, public institutions face a new governance challenge. Open-source AI agents may strengthen transparency, local adaptation, digital sovereignty and public-sector capacity building, but they also raise urgent questions around cybersecurity, accountability, procurement, liability and human oversight. This workshop examines how open-source agentic AI should be governed when deployed in public- interest contexts. It will begin with a concise state-of-the-art briefing explaining the current open- source agentic AI stack, including open models, agent frameworks, tool integration, permission layers, runtime environments, evaluation methods and monitoring. The briefing will highlight why agents differ from conventional AI applications: they do not only generate outputs, but can interact with systems and produce real-world consequences. The main part of the session will be interactive. Participants from government, academia, technical communities, civil society and industry will map key risks, including prompt injection, excessive agency, insecure tool access, data leakage, weak auditability and unclear responsibility for agent actions. The discussion will then move from risk identification to governance design: what should regulation require, what should public procurement demand, what should be treated as public digital infrastructure, and what can remain market-led or community-led? The session will explore whether an Open Agentic AI Commons could support responsible public- sector adoption through shared evaluation tools, procurement templates, reference architectures, security practices, training resources, and deployment playbooks. The goal is not to promote open- source AI uncritically, but to examine how openness, security, accountability, and public capacity can be aligned.
Policy Question(s)
A. Which parts of the open-source agentic AI stack should be considered public digital infrastructure, and which should remain market-led or community-led?
B. How can regulation and public procurement foster open-source AI agents while ensuring cybersecurity, accountability, human oversight, fundamental rights and long-term maintainability?
C. What shared resources should be included in an Open Agentic AI Commons to help public institutions deploy AI agents responsibly across different regional and institutional contexts?
Expected Outcomes
Participants will leave with a clearer understanding of how agentic AI differs from conventional AI systems, why open-source agents create both public-interest opportunities and security risks, and what practical governance mechanisms are needed before such systems are deployed in public institutions.
Participants will also identify candidate components for an Open Agentic AI Commons, such as evaluation tools, red-teaming practices, prompt-injection test cases, reference architectures, procurement templates, public-sector deployment playbooks and training materials.
The workshop will produce a co-developed draft checklist for responsible public-sector use of open-source AI agents, synthesising inputs from participants during the session. The checklist will reflect shared perspectives on procurement criteria, governance requirements, security safeguards,
auditability principles, human oversight, liability considerations and capacity-building needs, and will serve as a preliminary, non-binding output to inform further community and policy development.
Format
Roundtable
Duration (minutes): 90
Format description: The session is designed as an interactive governance workshop rather than a conventional panel. A roundtable layout supports direct exchange between policymakers, technologists, public-sector practitioners, civil society, academia and industry. The topic requires both technical orientation and structured policy discussion: participants first need a shared understanding of open-source agentic AI before debating governance, procurement and security requirements. The 90-minute duration allows the session to move through four stages: a concise state-of-the-art briefing, short stakeholder responses, interactive risk mapping, and collaborative development of a public-sector deployment checklist. A shorter format would leave insufficient time for meaningful audience participation and would risk becoming a one-way presentation. The roundtable format also supports hybrid participation, as online participants can contribute through live polling, shared documents and moderated interventions alongside onsite attendees.
Duration (minutes): 90
Format description: The session is designed as an interactive governance workshop rather than a conventional panel. A roundtable layout supports direct exchange between policymakers, technologists, public-sector practitioners, civil society, academia and industry. The topic requires both technical orientation and structured policy discussion: participants first need a shared understanding of open-source agentic AI before debating governance, procurement and security requirements. The 90-minute duration allows the session to move through four stages: a concise state-of-the-art briefing, short stakeholder responses, interactive risk mapping, and collaborative development of a public-sector deployment checklist. A shorter format would leave insufficient time for meaningful audience participation and would risk becoming a one-way presentation. The roundtable format also supports hybrid participation, as online participants can contribute through live polling, shared documents and moderated interventions alongside onsite attendees.
Hybrid Format: The session will be designed for equal participation from onsite and online attendees. After a short state-of-the-art briefing, the moderator will use live polling to identify the audience’s main concerns about open-source AI agents, including security, procurement, accountability and public infrastructure. Onsite and online participants will contribute to the same interactive exercises through a shared polling tool and collaborative document.
The moderator will alternate between onsite and online questions throughout the session, rather than leaving online input until the end. A designated online facilitator will monitor the chat, collect questions, surface remote interventions and ensure online participants can contribute to the risk- mapping and checklist-building exercises.
The session will use tools such as Slido, Mentimeter or an equivalent polling platform, plus a shared document or digital whiteboard to co-develop the draft public-sector checklist for responsible deployment of open-source AI agents.
Organizer 1: Hailan Wang, TUM
Organizer 2: Till Zacher, TUM
Organizer 3: Nico Caballero, SPARK Foundation
Organizer 4: Ricardo Aveiro, Internet Society Paraguay
Organizer 2: Till Zacher, TUM
Organizer 3: Nico Caballero, SPARK Foundation
Organizer 4: Ricardo Aveiro, Internet Society Paraguay
Speaker 1: Hailan Wang, Civil Society, Asia-Pacific Group
Speaker 2: Nico Caballero, Technical Community, Latin American and Caribbean Group (GRULAC)
Speaker 3: Ricardo Aveiro, Civil Society, Latin American and Caribbean Group (GRULAC)
Speaker 2: Nico Caballero, Technical Community, Latin American and Caribbean Group (GRULAC)
Speaker 3: Ricardo Aveiro, Civil Society, Latin American and Caribbean Group (GRULAC)
Moderator
Nico Caballero, Technical Community, Latin American and Caribbean Group (GRULAC)
Online Moderator
Till Zacher, Civil Society, Western European and Others Group (WEOG)
Rapporteur
Ricardo Aveiro, Civil Society, Latin American and Caribbean Group (GRULAC)
What will participants gain from attending this session?
