
On September 7, the open source community gathered in Shanghai for OSPOlogy + OSPO Summit China 2026, bringing together OSPO practitioners, enterprise open source leaders, and community experts to explore how open source program management is evolving in the age of AI.
Held during KubeCon + CloudNativeCon + OpenInfra Summit + PyTorch Conference China week, and alongside events including AGNTCon + MCPCon China, the summit provided an especially timely setting for these conversations.
Across the broader week, organizations were discussing and demonstrating how open AI infrastructure is being built across models, agents, protocols, developer tooling, cloud native infrastructure, and open source ecosystems.
For OSPOs, the question is increasingly not simply how organizations use AI, but how they can manage, integrate, and participate in the open ecosystems that are becoming part of their AI infrastructure. That shift was at the center of the conversations in Shanghai.

Community shared learnings
Across sessions and community discussions, several recurring themes emerged around AI governance, agentic infrastructure, trusted software supply chains, organizational transformation, and the strategic role of OSPOs in these areas. The following are some of the key takeaways from the event:
1. AI governance is becoming part of open source governance
One of the strongest themes across the event was the expanding scope of OSPO work. As organizations integrate AI into products, developer workflows, and internal infrastructure, governance questions increasingly span open source software,models, data, dependencies, licenses, provenance, and AI systems.
This creates an overlap with skills OSPOs have already developed: understanding external technology ecosystems, establishing contribution and consumption policies, managing software supply chain risks,connecting engineering with legal and compliance teams, and representing the organization in upstream communities.
Organizations are finding that many of the questions created by AI infrastructure already intersect with the OSPO. This makes open source expertise increasingly relevant to conversations about AI governance,technology strategy, risk, and organizational policy.
“The questions have expanded. Alongside establishing an OSPO, building trust in software supply chains, and contributing upstream, practitioners now need to understand what happens when AI participates in those workflows. The foundations of open source program management remain relevan, but the systems to which we apply them are changing”
2. Agentic AI is moving from experimentation into OSPO workflows
The discussion also moved beyond AI governance as policy and into practical implementation. For instance, Ant Group shared how its OSPO is integrating AI into day-to-day open source governance, including LLM-powered issue triage and assignment, pull request pre-reviews, AI-assisted code provenance and license compliance analysis, or community health insights.
Other discussions explored how AI agents can help OSPO teams deal with repetitive workflows and connect organizational knowledge with developer workflows.
This brings OSPOs into a new part of the conversation: not simply governing which open source components enter an organization, but helping determine how open technologies are used by systems that can increasingly take actions on behalf of developers and organizations.
3. The infrastructure around the model matters
A related discussion focused on the rapidly developing open infrastructure surrounding AI agents. Models are only one component of an agentic system: Agent harnesses,context, gateways, protocols, and data quality determine what an agent can actually do and under which conditions.
The session “Agent Harnesses, MCP and the Next Frontier for OSPOs” explored this emerging layer through projects and specifications including Goose, Model Context Protocol (MCP), AGENTS.md, and agentgateway.
This is also where the traditional ecosystem role of the OSPO becomes particularly relevant. If protocols and open projects become critical parts of enterprise AI infrastructure, organizations need to understand not only how to consume them, but how they are governed, where they are developed, and where upstream participation can influence their long-term direction.
4. Patent non-aggression is part of the open infrastructure story
The expansion of OSPO responsibilities into AI does not replace the foundations of open source governance. In many cases, it makes them more important.
Shane Coughlan’s session on OIN 2.0: The Patent Non-Aggression Community for Open Source in China and Beyond brought another layer of open source governance into the conversation: patents.

“For more than two decades, Open Invention Network (OIN) has developed a community around patent non-aggression for open source. In 2026, OIN introduced OIN 2.0 to expand this model as open source moves into new technologies and industries. OIN 2.0 expands that protection as the open source technology landscape continues to evolve.”
OSPOs can connect open source knowledge with IP functions, helping organizations understand how patent strategy intersects with their participation in open source ecosystems. Recent developments in China illustrate this connection. ByteDance joined the OIN 2.0 community in August 2026, extending its participation in the patent non-aggression ecosystem as open source becomes increasingly important to global-scale technology infrastructure.
5. Open standards and trusted software supply chains remain foundational
The same principle applies to software supply chains. As organizations introduce models, agents, frameworks, protocols, and new software dependencies into enterprise infrastructure, established open source governance mechanisms remain essential.
Open standards and specifications can give organizations common approaches to compliance, security, provenance, and trusted software supply chains rather than requiring every company to solve these problems independently. For OSPOs, understanding these initiatives is therefore not separate from AI strategy. It is part of understanding the increasingly complex open technology stack on which AI systems are being built.
6. OSPO transformation is also organizational transformation
Technology was only one side of the conversation. Bosch shared its experience building an OSPO within an established global organization, showing that organizations rarely start their open source programs from a blank slate: Existing processes, legal structures, engineering practices, business units, and organizational cultures all influence how an OSPO develops.
7. Open source, digital sovereignty, and AI sovereignty
Another important conversation in Shanghai concerned the changing geopolitical environment surrounding open technology. As organizations operate across different markets and regulatory regimes, questions about technology dependencies increasingly connect with discussions around digital and AI sovereignty.
The discussion started with the global model race and the focus on increasingly capable frontier models. Participants challenged that framing with a different question: Are organizations looking at the right part of the AI stack?
The model is one component. Performance, security, portability, and efficiency increasingly depend on the open technologies surrounding it, from PyTorch, Ray, and vLLM to Kubernetes and open protocols such as MCP.
In fact, this perspective was visible across the broader Shanghai week. PyTorch Conference China, KubeCon + CloudNativeCon, OpenInfra Summit, and AGNTCon + MCPCon brought together communities working across the AI stack, from infrastructure and orchestration to models and agents. For OSPOs, this expands the sovereignty question beyond “Which model do we use?” toward where organizations have choice across the AI stack, where dependencies and lock-in exist, and how open source and open standards can preserve that choice.
Conversations beyond the stage
The event brought together practitioners working on open source governance from different organizations, industries, and regions, creating space to compare how organizations are approaching many of the same challenges.
There is no single blueprint for an “AI-ready OSPO.” Sharing implementation patterns, experiments, failures, policies, and emerging practices helps the community identify which problems can be addressed collectively rather than independently inside every organization.
OSPOs are becoming a connective layer for open AI infrastructure
Perhaps the clearest takeaway from Shanghai was that the OSPO role is expanding alongside the infrastructure it helps organizations navigate.
The traditional OSPO remit around open source consumption, contribution, compliance, community participation, and strategy remains essentiat, but organizations are now building AI systems on top of a much broader collection of open technologies:models, datasets, agent frameworks, protocols, gateways, developer tools, specifications, standards, and cloud native infrastructure.
The opportunity for OSPOs is to provide the connective tissue between them: helping organizations understand their open dependencies, participate in the communities shaping critical infrastructure, translate governance requirements into engineering practices, and identify where open standards and upstream collaboration can solve problems collectively
Thank you to the people who made it possible
Thank you to ByteDance Open Source, our Diamond Sponsor, and vivo, our Supporter Sponsor, for supporting the gathering.
We are grateful to the program committee and organizing team, with special thanks to Ryan Tao, Zhiqiang Yu, Horace Li, Mary Wang and Ana Jiménez Santamaría, and to everyone who helped review proposals, shape the program, and bring the community together. Thank you also to all the speakers named above, the event staff, and every participant who contributed questions and experience.















