Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The Linux Foundation’s March 26, 2026 announcement released the schedule for Open Source Summit + Embedded Linux Conference North America (OSS + ELC NA), held May 18–20 in Minneapolis. Its program connected AI infrastructure with software-supply-chain security, embedded and edge systems, and the practical work of sustaining open-source projects. The conference has since concluded; its official archive points to recordings and presentations where available.
What the announcement covered
The announcement was a schedule release for a broad Linux Foundation conference—not the launch of one AI product, a new technical standard, or an independent assessment of the state of the industry. Open Source Summit was co-located with the Embedded Linux Conference, bringing software infrastructure and open-source community topics together with embedded, real-time, and safety-focused engineering.
The Linux Foundation framed the program around the “next era” of AI infrastructure, security, and open ecosystems. That phrase is event positioning. The schedule supports a more measured takeaway: teams increasingly have to consider AI alongside the platforms, security practices, physical devices, and governance that make software usable in production.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The announcement was published March 26, 2026, and carried a March 19 dateline. The main event ran May 18–20 in Minneapolis, Minnesota. It is now in the past, so registration and early-bird details in the original announcement are historical, not current offers. See the schedule announcement and the archived schedule for the event record. Session times and rooms were subject to change.
#1 Best Overall
AI infrastructure meant more than GPUs
AI appeared in the program as an operational and infrastructure challenge, not just a model or application topic. The schedule touched a stack that can include inference and model serving, containers, orchestration, data and context systems, platform engineering, software delivery, observability, identity, and the interfaces agents use to reach tools.
One highlighted IBM Research session, “KV-Cache Centric Inference: Building an Open Source LLM Serving Platform Around State,” focused on the serving layer. KV-cache behavior and state management matter because an inference platform must manage more than model weights: it must also handle request state, latency, memory use, and the practical demands of serving workloads. The session title shows the problem under discussion; it does not, by itself, establish a performance result or prove that a particular architecture is best.
Other listed sessions explored MCP servers and context graphs, while the archived schedule included a keynote on “Where AI Meets the Physical World: The Robot MCP Ecosystem as an Open Bridge Between AI and Robotics.” These topics point to a broader question: how should AI applications obtain context and interact with external tools or devices? Connecting an agent to a tool is not a security control in itself. Teams still need to decide which identity an agent uses, what it may access, how actions are authorized, and how activity is logged and reviewed.
Free tools Windows power users keep installed
One-click scans. No signup required.
For platform and AI teams, the useful takeaway is to evaluate the complete path to production. Can the serving layer meet latency and cost needs? Can deployment and updates fit existing delivery controls? Are agent actions governed by explicit permissions? What happens when a model, context source, tool, or underlying dependency changes?
Rank #2
Security: from producing SBOMs to using them
The security thread went beyond vulnerability lists. A software bill of materials (SBOM) can describe components in a software artifact, but generating one does not automatically tell an organization which systems contain an affected component, whether it is reachable, who must fix it, or whether a release should be stopped. An inventory becomes more useful when connected to ownership, prioritization, remediation, release decisions, and incident response.
The announcement highlighted “Securing the AI Supply Chain: Critical Infrastructure for Model Integrity and Trust,” a scheduled session with representatives from OpenSSF, Microsoft, OpenAI, and Intel. The roster indicates the range of organizations represented; it is not evidence that participants shared one position or reached a particular conclusion. For AI systems, the supply-chain question can extend from conventional software dependencies to model and data integrity, provenance, and the tooling used to assemble or operate a system.
The wider Cloud & Orchestration security topics included cloud infrastructure security, policy agents, confidential computing, and identity, authentication, and authorization. These are complementary controls, not interchangeable labels: identity establishes who or what is acting; authorization limits permitted actions; policy expresses rules; and confidential-computing approaches address protection of data while it is being processed in supported environments. Their value depends on implementation and operational practice, not simply on their appearance in a program.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteFor a security or compliance team, the practical questions are whether software and model provenance can be traced, whether inventories are maintained, whether findings reach the right owners, and whether agent and build systems operate under defined identities and policies. SBOMs are one input to that work, not a substitute for it.
Embedded Linux, edge, robotics, and safety
The Embedded Linux Conference and related tracks kept the program grounded in software that runs close to hardware. The announcement pointed to industrial automation, automotive platforms, IoT, and edge computing. The archived track list also included Zephyr, PX4 Dev Summit, and Safety-critical Software, covering real-time embedded development, autonomous flight, and safety-oriented engineering.
A featured Nordic Semiconductor session, “From Physics to eBPF: Quantifying Flash Wear in Embedded Systems,” illustrates the kind of systems concern that can be easy to miss in a cloud-centric view: storage has physical limits, and observability can help teams understand wear and lifecycle behavior. The session’s inclusion does not establish a particular finding, but it shows that the agenda addressed reliability at the device level as well as at the platform level.
This matters as AI systems reach cameras, robots, vehicles, and industrial equipment. Physical deployments bring constraints that differ from hosted services: hardware availability, resource limits, update windows, real-time behavior, safety requirements, and long product lifecycles. A development board or open-source component is not automatically suitable for a production or safety-critical deployment; teams must assess support, security updates, qualification needs, and supply continuity for their own use case.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Open-source sustainability is technical and organizational
The program treated sustainability as more than whether source code is available. Project health depends on maintenance, governance, contributor capacity, funding and support, and the ability to respond to security issues. Organizations adopting open source have a related but distinct challenge: setting policies, tracking obligations, contributing responsibly, and giving internal teams a clear route to engage with projects.
Rank #4
The highlighted GitHub session “Scaling Your OSPO with Agents and Automation: Lessons from GitHub’s Open Source Program” connected automation and AI to open-source program office (OSPO) work. Automation may help with repeatable processes, but it does not settle questions of accountability, review, or community norms. AI-generated contributions still need human ownership and appropriate review; adopting a tool does not resolve project governance.
It helps to separate three meanings of sustainability:
- Project sustainability: maintenance, governance, contributor health, and long-term support.
- Organizational adoption: OSPO functions, policy, compliance, and responsible contribution practices.
- Technical sustainability: security updates, reproducible workflows, and lifecycle planning.
A project can be open yet poorly maintained, and an organization can use open-source software without having a mature process for managing it. Those distinctions are useful when evaluating production readiness and long-term risk.
Choose tracks by the problem you need to solve
The official archive listed tracks spanning infrastructure, development, embedded systems, and project management. This guide maps them to common reader needs; it is not a claim that every session in a track covered every listed topic.
Best Value
| Reader need | Relevant track |
|---|---|
| AI applications, data, agents, and open AI systems | Open AI & Data |
| Cloud platforms, orchestration, and operations | Cloud & Orchestration |
| CI/CD, platform engineering, and delivery workflows | cdCon |
| Software trust, security, and compliance | Digital Trust |
| Linux kernel and core Linux development | Linux |
| Deployment artifacts, packages, and containers | Packages, Images, & Containers |
| Embedded products and edge systems | Embedded Linux |
| Drones and autonomous flight systems | PX4 Dev Summit |
| Safety-regulated engineering | Safety-critical Software |
| Real-time embedded development | Zephyr |
| Organizational adoption and open-source program management | OSS Enabling & Management |
| Introductory open-source education | Open Source 101 |
The track name “Open AI & Data” refers to the program area; it should not be confused with OpenAI, the company.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Co-located events extended the program
Related programming added options for more specialized audiences. The announcement highlighted Linux Security Summit, Observability Summit, and OpenSSF Community Day North America. Archived materials also listed an LF AI & Data Mini Summit and RISC-V Insights. The dates were not all the same: the main OSS + ELC event ran May 18–20; Linux Security Summit ran May 21–22; OpenSSF Community Day North America and RISC-V Insights were listed for May 21. Consult the archived co-located events page for the historical details.
The announcement also named organizations including AWS, Cloudflare, Google, IBM, Intel, LG, Microsoft, Netflix, Nordic Semiconductor, OpenAI, and Sony. That indicates representation among speakers or sessions, not endorsement of the conference agenda or agreement among those organizations.
Recommended Free Tools
Who would have found the program useful?
- AI infrastructure engineers looking beyond model selection to serving, state, deployment, context, and tool access.
- Security teams trying to connect SBOMs and provenance to inventory, remediation, identity, and policy.
- Platform and cloud engineers working on orchestration, containers, CI/CD, and operational workflows.
- Embedded, robotics, and edge developers balancing real-time behavior, hardware lifecycle, reliability, and security.
- OSPO leaders and engineering managers responsible for governance, contributor practices, and long-term project health.
- Newcomers seeking an entry point through Open Source 101 or broader community exposure.
It would have been a poorer fit for someone seeking a consumer-AI product launch, a single-vendor comparison, independently measured performance benchmarks, or only an introductory programming course. The schedule describes sessions and intended subject matter; it does not validate tools or prove production outcomes.
What the archive can—and cannot—tell you
The event archive is the best starting point for post-event materials. The Linux Foundation says recordings are available through its YouTube channel and speaker-provided presentations can be reviewed through the schedule, but availability varies by session. Check the event archive and session directory rather than assuming every talk has a recording or slide deck.
The schedule announcement does not report attendance, adoption metrics, security findings, project releases, governance changes, or audience response. Nor does a session title demonstrate that a technology was tested in production. Use the materials to understand the questions and approaches discussed, then evaluate any implementation against your own requirements for security, reliability, licensing, support, and lifecycle.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

