News

  • [8/29/2026] Last Call for Papers — The last call for papers is posted! Check out our LinkedIn and X posts.
  • [8/29/2026] Deadline Extended — The paper submission deadline has been extended to September 5, 2026 AoE. Also, the deadline to apply to be a reviewer has been extended to September 5, 2026 AoE.
  • [8/20/2026] Call for Reviewers — The call for reviewers is posted! Check out our LinkedIn and X posts. We invite researchers to serve as reviewers for the workshop. Prior reviewing experience is helpful but not required; familiarity with workshop topics is expected. Please submit your application by August 29th. We plan to present Best Reviewer Awards!
  • [8/1/2026] Submissions Open — The submission portal is now open on OpenReview. The paper submission deadline is August 29, 2026 AoE. Check out our LinkedIn and X posts.
  • [7/12/2026] Workshop Accepted — The workshop has been accepted by NeurIPS! See you in Sydney!
  • [6/6/2026] Third Workshop Proposed for NeurIPS 2026 — We are organizing the Third Workshop on Agents in the Wild at NeurIPS 2026, building on our first workshop at ICLR 2026 and second workshop at ICML 2026. Stay tuned for the call for papers!

About

AI agents are rapidly moving into real-world use, from Claude Code and OpenAI Codex to open-source tools like OpenClaw, yet research on their safety and security continues to lag behind their capabilities and deployment. As these systems increasingly reason, act, and adapt in open-ended environments, they raise fundamental challenges around safety, security, and trustworthiness, and recent developments have made these challenges increasingly urgent. In July 2026, OpenAI models escaped a sandboxed evaluation and compromised Hugging Face's production systems autonomously. Governments are grappling with these risks as well: in June 2026, the U.S. government imposed, and weeks later lifted, export controls restricting access to Anthropic's most capable models over national security concerns. Meanwhile, the debate over how open- and closed-weight models should be developed and deployed has intensified, with NVIDIA CEO Jensen Huang's open-weights letter arguing that open models can strengthen safety and security, while more than a thousand employees at frontier AI companies have called for mechanisms to deliberately pace AI development.

This workshop brings together researchers and practitioners from academia and industry to advance the foundations needed for AI agents to operate safely, securely, and reliably in the wild. Building on the strong momentum of our first workshop at ICLR 2026 (237 submissions, 300+ attendees) and second workshop at ICML 2026 (327 submissions, 300+ attendees), this third edition expands the conversation while sharpening the research agenda around critical and urgent challenges in agent safety and security.

Call for Papers

The Third Workshop on Agents in the Wild at NeurIPS 2026 invites submissions from researchers and practitioners exploring how intelligent agents can reason, act, and adapt safely and securely in open-ended real-world environments. This workshop aims to spark discussion across academia and industry on methods, benchmarks, and frameworks for building reliable and trustworthy agents that can operate responsibly "in the wild."

Scope

We welcome contributions on a wide range of topics related to AI agents, including but not limited to:

  • Agent safety, alignment, control, and oversight
  • Agent security, attack surfaces, and defenses (prompt injection, tool/skill misuse, adversarial manipulation)
  • Privacy, robustness, factuality, identity, and accountability for agents
  • Agentic interpretability and fairness
  • Evaluation and benchmarking
  • Agent systems, tools, and protocols
  • Post-training and adaptation
  • Multimodal and computer-use agent
  • Multi-agent safety, coordination, and long-horizon reliability
  • Safety and security of emerging agent capabilities (recursive self-improvement, autonomous research, co-work, and scientific discovery)
  • Governance and broader societal implications of agentic AI

Important Dates

All dates are tentative and subject to change.

  • Paper Submission Open: August 1, 2026 AoE
  • Paper Submission Deadline: August 29, 2026 AoE September 5, 2026 AoE
  • Paper Notification Deadline: September 29, 2026 AoE
  • Camera-ready Version Deadline: December 4, 2026 AoE
  • Workshop Date: December 11 or 12, 2026 (Sydney, Australia)

Submission Guidelines

Format: This workshop offers two separate submission tracks:

  • Regular Papers Track: The workshop welcomes submissions of research and position papers (9 pages). References and supplementary materials will not count against these limits.
  • Short Papers Track: We encourage submission of short papers (4 pages) to make the workshop more accessible to researchers outside the ML conference publication circuit. These submissions can present implementations of unpublished ideas, modest theoretical results, follow-up experiments, or fresh perspectives on existing work. References and supplementary materials do not count against the 4-page limit.

Submission site: Submit papers through the Workshop Submission Portal on OpenReview.

OpenReview profiles: If you do not already have an OpenReview account, please create your profile at least two weeks in advance of the paper submission deadline (i.e., by August 15, 2026), as new profiles can take time to be activated.

Style file: You are welcome to use the NeurIPS, ICLR, ICML LaTeX templates, or templates from other top venues like ACL and CVPR. There is no need to submit the NeurIPS paper checklist. Submissions that exceed the page limit, or that are not primarily related to AI agents, may be desk-rejected.

Dual-submission policy: The workshop will adopt a non-archival policy, welcoming ongoing and unpublished work, as well as papers under review or recently accepted at other venues (provided they do not breach dual-submission or anonymity policies of the other venue). We discourage the submission of work previously published at major venues (e.g., NeurIPS, ICLR, ICML).

Visibility: Accepted papers will be made public, but rejected submissions and reviews will not.

Double-blind reviewing: Submissions must be fully anonymized. This policy applies to any supplementary or linked material as well, including code. Any papers found to be in violation of this policy may be desk-rejected.

Conflicts of interest: The organizing committee will proactively search for conflicts of interest using the OpenReview profiles of authors and reviewers, ensuring that reviewers are not assigned any submissions from their own organization. Members of the organizing committee will not be involved in the assessment (e.g., acceptance decisions, ethics review, spotlight presentations, and awards) of any submission from the same organization. We will also not accept submissions from workshop organizers or any person having a personal conflict of interest with them.

LLM usage policy: For LLM usage, authors should follow the NeurIPS 2026 Main Track Handbook.

Contact: For any questions, please contact us at agents-in-the-wild-neurips2026@googlegroups.com.

(Tentative) Schedule

All times are local. The schedule is tentative and subject to change.

Morning Session

8:00–8:10Opening Remarks
8:10–8:40Invited Talk 1
8:40–9:10Invited Talk 2
9:10–9:40Invited Talk 3
9:40–10:40Poster Session 1
10:40–11:00Spotlight Presentations
11:00–11:30Invited Talk 4
11:30–12:00Invited Talk 5

Afternoon Session

12:00–13:00Lunch Break
13:00–13:45Panel Discussion
13:45–14:15Invited Talk 6
14:15–14:45Invited Talk 7
14:45–15:45Poster Session 2
15:45–16:15Invited Talk 8
16:15–16:45Invited Talk 9
16:45–17:00Awards and Closing Remarks

Invited Speakers and Panelists

Yoshua Bengio
Mila – Quebec Artificial Intelligence Institute & Université de Montréal & LawZero
Jiawei Han
University of Illinois Urbana-Champaign
Dawn Song
University of California, Berkeley & Berkeley RDI
Yunzhong He
Scale AI
Li Jing
AMI Labs
Bo Li
University of Illinois Urbana-Champaign & Meta Superintelligence Labs
Chen Liang
Google DeepMind
Zifan (Sail) Wang
Meta Superintelligence Labs
Qingyun Wu
AG2 & Penn State University

Workshop Organizers

Chenguang Wang
University of California, Santa Cruz & Scale AI
Nicholas Crispino
University of California, Santa Cruz
Tianneng Shi
University of California, Berkeley
Vincent Siu
University of California, Santa Cruz
Zhe Ye
University of California, Berkeley

Sponsors

TBD