WORKSHOP | CO-LOCATED WITH SOSP 2026

Agentic OS

The 2nd Workshop on Operating Systems Design for AI Agents

September 29, 2026
Congress Hotel Prague, Czechia

Overview

AI agents are rapidly evolving from experimental prototypes to always-on services that autonomously plan, invoke external tools, collaborate, and continuously interact with their environment. This shift challenges traditional operating system abstractions—processes, threads, files, sockets, and resource controllers—which were never designed for dynamic, semantically rich, adaptive agent workloads. To support AI agents at scale, operating systems themselves must become agentic, adapting their abstractions and resource management policies to the semantic behaviors of agents.

The second AgenticOS workshop, co-located with SOSP 2026, seeks original position papers and experience reports that explore OS-level mechanisms for AI-agent workloads. Our goal is to define the primitives, isolation models, scheduling techniques, and observability mechanisms necessary to build operating systems explicitly tailored to agent-based systems.

Workshop Schedule

September 29, 2026 — Afternoon session (local time)

Opening 1:30pm – 1:35pm
Workshop Opening Remarks + Best Paper Awards
Keynote 1:35pm – 2:20pm
Laurent Bindschaedler (Max Planck Institute for Software Systems)
Title: TBD
Isolation and Risks 2:20pm – 3:05pm
Isolation in the Age of Agents
Anjali, Michael Swift (University of Wisconsin–Madison)
Agent libOS: A Runtime Substrate for Capability-Controlled Self-Evolving LLM Agents
Yingqi Zhang (Tsinghua University)
An AgentOS Needs a Formal Representation of Agents
Qin Liu, Boyuan Shao, Xinhao Wang, Yuyang Qiu, Fengshan Zhao (State Key Laboratory of Novel Software Technology, Nanjing University)
Coffee Break 3:05pm – 3:30pm
Profiling 3:30pm – 4:00pm
Preserving GPU Profiling Accuracy under Concurrent GPU-Coding Agent Workloads
Yingyi Hao, Xingda Wei, Rong Chen, Haibo Chen (Shanghai Jiao Tong University)
AgentProf: Semantic Profiling for AI Agents
Yusheng Zheng (UC Santa Cruz), Chaokun Chang, Tianyuan Wu (HKUST), Wenan Mao, Shuyi Cheng, Tao Ma (Alibaba Group), Andi Quinn (UC Santa Cruz), Wei Wang (HKUST)
Scheduling and Budget 4:00pm – 4:30pm
Patient Bytes: A Reliability-Budgeted Scheduler for Agentic LLM Workflows
Hannah B. Pasandi, Negar Arabzadeh, Melissa Pan (UC Berkeley), Tianyin Xu (UC Berkeley & UIUC), Sina Darabi (Università della Svizzera italiana), Mohammad Hosseini (Shahid Beheshti University), Hamed Haddadi (Imperial College London & Brave Software)
The Irreversibility Budget: Fleet-Level Risk Accounting and Admission Control for Agent Operating Systems
Bardia Mohammadi, Laurent Bindschaedler (Max Planck Institute for Software Systems)
OS Structure 4:30pm – 5:00pm
TypeGo: An OS Runtime for Embodied Agents
Guojun Chen, Alex Schott, Lin Zhong (Yale University)
When Agent Context Goes Stale: Incoherence in Volatile Agent Context
Yingying Liu, Junzhou Fang, Chenxiong Qian (The University of Hong Kong)
Lightning Talks 5:00pm – 5:30pm
Formal Methods as the Harness for AIOS
Mingyu Li, Zhanbo Wang, Yiping Weng (Institute of Software, Chinese Academy of Sciences)
LLM Agent Capabilities Should Follow Task Intent and Context Source
Yusheng Zheng (UC Santa Cruz), Wenhui Zhang (Roblox), Yu Mao (Bytedance)
Securing Agentic AI with OS-Level Intent-Driven Capabilities
Miguel Lourenço (INESC-ID, Instituto Superior Técnico, University of Lisbon), Matthias Neugschwandtner (Oracle Labs), Nuno Santos, Rodrigo Bruno (INESC-ID, Instituto Superior Técnico, University of Lisbon)
Agate: Capability Microkernels as a Natural Substrate for AI Agents
Zhao Wei (Huawei 2012 Laboratories)
Externalization Barriers: An OS Abstraction for Untrusted Agent Exploration
Jinhao Hu, Bardia Mohammadi (Max Planck Institute for Software Systems), Ashvin Goel (University of Toronto), Laurent Bindschaedler (Max Planck Institute for Software Systems)
The Abstractions Are Slipping: Four OS Mismatches in the Agent Era
Zheng Liu, Qin Long, Jinli Zhang, Yong Yang, Tao Ma (Alibaba Cloud Computing)

Topics of Interest

Topics of interest include (but are not limited to):

  • New OS abstractions for agent execution (process/container/multikernel enhancements)
  • Dynamic sandboxing and lightweight runtimes for securely executing agent-generated code and tasks
  • Semantics-aware resource management and scheduling for dynamic, multi-agent workloads
  • Long-lived state abstractions for managing agent context, prompts, and episodic memory
  • Observability, provenance, and debugging for agent executions
  • Compiler–OS co-design for adaptive and agent-aware JIT execution strategies
  • GPU and accelerator virtualization for large-scale deployment of agent workloads
  • Security and isolation mechanisms for agent-invoked tools, code, and data flows
  • Agents managing systems: kernel tuning, anomaly detection, resource orchestration, failure recovery, and dynamic policy updates
  • Inter-agent communication patterns and primitives
  • Reliability and fault tolerance of agents

Submission Guidelines

We solicit two types of submissions:

Track 1

Vision Papers

1–2 pages (excluding references).

Suitable for early-stage ideas, position statements, ongoing projects, demos, and insights from production systems. We strongly welcome contributions from industry practitioners and the open source community to share real-world experiences and challenges.

Track 2

Research Papers

Up to 6 pages (excluding references).

Suitable for more complete concepts, research results and experience reports.

All submissions must follow the ACM double-column conference format. The review process is double-blind, with each submission receiving at least two reviews. Submit your paper via HotCRP.

Frequently Asked Questions

Can I submit work that is already on arXiv?

Yes. Posting on arXiv or other preprint servers does not disqualify a submission.

Can I submit work-in-progress or concurrent submissions?

Yes. We welcome early-stage ideas and ongoing work. Submissions under review at other venues are acceptable.

Will this affect future publication at other venues?

No. This workshop has no formal proceedings. Accepted papers will only appear on the workshop website, which does not preclude future publication at conferences or journals.