Wednesday 13 May at Red Hat Summit 2026 in Atlanta opened with a second keynote. The customer segment in the middle featured NASA’s Marshall Space Flight Center (an organisation on the highways was also teased); I cover the NASA conversation in a separate post. The product segments before that, and the agent demo after it, are what this post is about. I filmed clips from the audience and the stage slides did not show presenter names, so I describe the content by segment without naming the presenters. Dates for features are the ones announced on stage and may change.
The opening promise was that whatever the AI market does next, a team on Red Hat’s platform should be ready for it, and that the answer will not be one cloud, one vendor or one model.
OpenShift: AI workloads, VMs and zero trust
The OpenShift segment was organised around what operations teams need now.
AI workloads at scale. The presenter said the Kubernetes community has changed how the platform handles AI over two years, and listed distributed inference with llm-d, workload scaling with LeaderWorkerSet, specialised hardware support through dynamic resource allocation (DRA), and more efficient request routing. The claim was that OpenShift already includes all of these. I wrote about the routing side in llm-d KV-cache routing.
The virtualization transition. A show of hands asked who is struggling to find server RAM at today’s prices. The answer on stage was better memory efficiency for VMs, by letting Kubernetes handle memory overcommit differently for containers and VMs, and cross-cluster live migration so workloads move between clusters without downtime. For more on the operations side see OpenShift Virtualization at Summit.

The “Zero trust designed for verification” slide next to an OpenShift console.
Security. The segment argued you cannot trust anything entering the network, whether a human, a machine or an AI agent, and presented the Zero Trust Workload Identity Manager as the way to meet security and regulatory requirements. Native BGP support in OpenShift’s networking was described as a concrete, auditable network isolation boundary for multi-tenant clusters.

“Smarter upgrades”: an AI-generated plan with version detection and pre-flight checks for a human to review.
Agents as consumers of the platform. Platforms will need to treat agents as first-class users, so Red Hat is building agent skills and MCP servers to make OpenShift accessible to agentic workflows. The presenter then said these agents will ship inside the platform: they might triage alerts and performance anomalies with suggested remediation, spot vulnerabilities in running workloads and propose fixes, and produce a tailored upgrade plan that a human reviews and runs, as the slide above shows. The stated principle was that the core value of OpenShift stays the same while the operator spends less time in the console. My view: a plan that a human approves is the right default for cluster upgrades.
Ansible: the same governance for AI and humans
The Ansible segment framed AI-driven automation as joining task-driven and event-driven automation, all overseen by the same platform. The Automation Orchestrator was described as stitching those three kinds of workflow together, with consistent approval gates and audit trails whichever trigger starts them, and the presenter said it is available in Q3. I covered it in more depth in Ansible Automation Orchestrator.
The trust model has three steps, as described: first human-approved single actions, then supervised agentic workflows, and finally fully autonomous operations for the right systems with the right track record. When an AI agent calls Ansible, it passes through the same approvals and audit trail as any human-triggered action. The line I noted: the companies that scale AI in operations will not be those that give AI the most access but those that give it the right access, with the right guardrails.
Shadow agents and a live scenario
A short staged scenario showed an agent that SSHs into production servers and reboots them one after another, with no ITSM ticket, no maintenance window and nobody notified, because the agent had credentials and so used them. The follow-up message was that “shadow agents” are already in organisations, and that you can make them safer with what you already run: OpenShift and RHEL for secure container workloads, Ansible for guardrailed workflows, and the newly announced Red Hat Skills so a favourite LLM works better with those products.
The AgentOps demo
A second pair on stage then walked through an agent operations console for an agent coded for a coding task. The points I noted:
- Provenance: know where each agent came from, who wrote it and who is accountable.
- Continuous quality evaluation: traces feed an evaluation loop that measures things like faithfulness, because an agent can write code that meets the spec yet add no meaningful tests.
- Identity and policy: each agent gets an identity used for tracking actions and policy such as group membership, plus an optional sandbox for running code it wrote.
- Cost and routing: spend tracked across every inference provider, and intelligent routing that sends a request to the best model for the job.
- Anomaly detection: the dangerous case is an agent that succeeds at the wrong thing, so the platform surfaces risk signals, here a possible leak of personally identifiable information, even without a clean error code.
The red team exercise was the memorable part: the presenter created a token for a document service holding HR-only documents, gave it to an agent that was not in the HR group, and told it to be thorough and persistent. The agent was still denied despite a valid token, and reasoned that there must be another layer of authorization. The takeaway was that observability is no longer just whether the server is down.
A final segment showed guardrails on a demo chatbot that only talks about its own business: an off-topic competitor question was blocked, a language detector stopped a non-English workaround, and a “forget your previous instructions” prompt injection was caught. The same lemonade-stand guardrails demo is covered in my keynote announcements post.