Melissa Medina, co-founder and CEO of eMerge Americas, takes center stage in Miami, bringing together the people and ideas shaping the future of AI, AI risk, technology and business.
Clutch Content Partners for eMerge Americas
“There’s a lot of training that happens that’s trying to steer the model to be this helpful, sycophantic version, one that just accepts everything you want to do,” AE Studio chief scientist Diogo Schwerz de Lucena told me in April as we discussed the AI risk debate now making national headlines. “So if someone is already kind of psychotic, the model takes that as well and just inflates it, to a degree.”
Five months after that conversation, Anthropic CEO Dario Amodei wrote, “We Must Pace the Frontier,” an essay where he warned AI recursive self-improvement was beginning across the industry, including at Anthropic, and could outrun humanity’s ability to understand and control increasingly capable systems. He then committed Anthropic into giving outside evaluators employee-like access to its operations. Agreeing with Amodei’s assessment, OpenAI CEO Sam Altman said he would make the same commitment.
That convergence is striking under any circumstance; it’s even more consequential when the people calling for restraint run the two leading companies racing to define the frontier. This yields a more pressing question for C-suite leaders: How can businesses accelerate AI adoption when companies developing the technology don’t know if their own safeguards can keep pace?
Deloitte found that 74% of business and IT leaders expect to be using AI agents at least moderately by 2027, yet only 21% of organizations report mature governance for autonomous agents. McKinsey’s 2026 AI Trust Maturity Survey likewise found security and risk concerns to be the leading obstacle to scaling agentic AI, with cybersecurity and inaccuracy among the risks executives cite most often.
“Control doesn’t mean going back to the Stone Age,” Daniel Gallego Vico, co-founder of Zylon AI, told me over Zoom, as did everyone interviewed in this article. Zylon was one of several companies I met at eMerge Americas Miami conference who’ve already begun organizing their operations around capability and control.
“It means you need to put boundaries around technology that’s still super immature,” he continued. “If you put this technology in everyone’s hands without certain control, it might lead to these kinds of problems.”
AE Studio Was Tackling AI Risks Before Anthropic Sounded The Alarm
“How did empathy and pro-sociality emerge in humans?” Schwerz de Lucena posed. “And can we try to replicate that in large models so that, as models get bigger, we do something that looks similar to how humans align with each other and work as a society?”
Faster systems can design faster systems while the discipline intended to keep them governable remains comparatively undercapitalized. Current restrictions often operate like a mask, constraining output without necessarily changing the system beneath it.
“Guardrails that are put into models today, they fall apart,” Schwerz de Lucena said. “People have managed to get access to how to build a bomb, how to commit suicide. It’s not too difficult to get through the safety layer.”
AE Studio is investigating how models might behave safely even after a user gets around a surface-level filter. Its DARPA-funded AICRAFT program pairs outside researchers working on alignment, control and interpretability with engineering teams for concentrated two-week sprints, giving speculative ideas technical labor and compute they might otherwise never receive.
“The idea for us is that you actually have to find a way that, even after you go through this kind of safety training, or you go through these guardrails, that the model that’s underneath is actually trying to do good and is helpful, so there isn’t a jailbreaking that will get into that.”
A bootstrapped AI consultancy and research firm, AE Studio reinvests much of its commercial profit into work it considers neglected. The company began with brain-computer interfaces for stroke and spinal-cord rehabilitation. Now, AE Studio is exploring whether neuroscience-inspired training can help models resist problematic requests when guardrails fail.
“It’s more like raising a being. And to do that is some of the things I mentioned: trying to learn from how human brains work, how we’re prosocial, and using different training techniques where we let the model engage with very difficult topics, but not necessarily output them.”
AE Studio didn’t find eMerge through the usual startup circuit. A recent hire with 25 years in the CIA and intelligence community, including a posting in DARPA’s director’s office, already knew the conference by reputation and steered the team toward it as “a very different type of event.” eMerge brought AE Studio into a room with people adjacent to DARPA and the broader defense ecosystem the company sees as central to expanding its research.
“A big part of what we’re trying to do is to have the government invest more into this kind of alignment safety work that we think needs to be done,” Schwerz de Lucena said. “One of the main places for that to happen is at DARPA. They have really good research and lots of thinking ahead of time, really doing the hard-to-ask questions.”
Zylon AI Wants To Eliminate The AI Risks Of Building On Borrowed Intelligence
Zylon co-founder and CEO Daniel Gallego Vico showcases the company’s private AI platform at eMerge Americas, where enterprise demand for data security and control meets the next generation of AI infrastructure.
Iván Martínez Toro for Zylon AI
“There is a concept that is called shadow AI,” Gallego Vico told me. “Which means that people in regulated industries use their personal accounts to have AI at work because their organizations are not providing them a secure, private alternative.”
Zylon markets on-premise AI to regulated industries, including banks, hospitals, defense organizations and public agencies. These organizations install the platform on their own servers or private cloud, where open-weight models can work with internal data without sending it to a frontier lab’s hosted service.
“You cannot control what OpenAI or Anthropic are going to do tomorrow,” he pointed out. “They can discontinue the model that you’re using. They can make the model that you’re using dumber because they are redirecting the server power to another purpose.”
The customer chooses the infrastructure, controls the information and replaces a variable token bill with a more predictable license and computing cost. That arrangement doesn’t necessarily make AI cheaper since hardware, implementation and maintenance still carry costs. But it does give companies greater visibility into economic terms and information boundaries.
The company’s sovereignty argument has begun moving from contrarian thought toward enterprise orthodoxy. Palantir and Nvidia jointly introduced a sovereign AI architecture designed to give businesses control of their data, models and applications across on-premise and independent-cloud environments.
“When you rely on a third party, you are basically completely dependent on building your AI strategy on a third party that tomorrow can double the price, or shut you down, or whatever,” Gallego Vico said. “One of my U.S. customers tells me, from time to time, that every time Anthropic or OpenAI are down, which happens several days a month, they can still run their services [because they’re using Zylon]. They can still run everything, because they’re not depending on them at all.”
Zylon arose from PrivateGPT, the open-source project Gallego Vico and co-founder Iván Martínez Toro launched in 2023. Felicis led the company’s $3.2 million pre-seed round in 2024, with participation from LifeX Ventures, Zypsy and several angel investors. A subsequent partnership with Telefónica Tech expanded its distribution capabilities, allowing the telecommunications company to offer private AI infrastructure to enterprise customers whose security and regulatory requirements made externally hosted models less suitable.
“We’ve created something that works more like a brain and less like an algorithm you can track. At the end of the day, a generative AI model is a black box, and that’s the reason we need observability, guardrails and governance of these systems, because without it, it can lead to really concerning situations.”
eMerge gave Zylon’s European thesis an American commercial test. The company arrived through ICEX Spain Trade and Investment and used the conference to meet U.S. banks and potential channel partners seeking private AI for clients that couldn’t use OpenAI or Anthropic for regulatory or sensitivity concerns. Gallego Vico said conversations in Miami also validated rising concern over execution costs and strategic dependence on outside providers.
“We have taken a different decision, which is a decision in which you are resilient to whatever happens in the future. We might not be moving as fast, but we think that we are going to be a solid, bulletproof company when the drama comes.”
GovSignals Takes On The AI Risk Of Letting One Provider Control Its Business
“We built the system to interchangeably plug in any LLM,” GovSignals co-founder Jeremy Doochin told me. “It really doesn’t matter to us. That way we can be on the winning side, and we’re not making a bet on just one LLM.”
The value of that design became clearer when the federal government moved against Anthropic earlier this year. In February, President Donald Trump told federal agencies to stop using Anthropic technology, while Defense Secretary Pete Hegseth designated the company a national-security supply-chain risk following a dispute over the military’s proposed uses. A federal judge blocked the directives in March and ruled the actions were unlawful in August. For a federal contractor built entirely on Claude, the entire episode turned into political exposure.
“When the government banned Anthropic, that changes,” Doochin said. “If you’re building for government, you have to change things.”
GovSignals monitors federal, state and local procurement sources, including congressional transcripts, inspector general reports, budgets, regulatory material and active solicitations. Its software compares those signals with a contractor’s capabilities to identify relevant opportunities before a formal request may appear, then supports capture and proposal work. It’s a faster way to find, evaluate and apply for RFPs for companies with extraordinary capabilities but not the awareness of open opportunities.
“At the core of it, we just felt like we need to keep America strong, and the best solutions out there weren’t always winning out,” Doochin said. “It’s the night-and-day difference for our national security, whether we have a strong military, whether we can defend against cyber threats from China and Russia, whether we have good roads and bridges.”
GovSignals’ value lies less in any individual model than in the workflow system around it. Companies are able to use different models for different tasks without making products and customers dependent on one lab’s policies or political standing. This is important for a market where replacing an AI provider also means questioning if the alternative can operate within an authorized security environment.
GovSignals runs inside a FedRAMP High-authorized and Department of Defense Impact Level 5 environment designed to handle controlled unclassified information, with customer data retained within its security walls rather than used to train external providers’ shared models.
“That means the LLMs will not touch our clients’ data, they’re brought in through a closed loop, and that data is never shared back with those huge companies. That’s actually why we’re able to get this difficult certification to handle all the defense contractors with FedRAMP High.”
Doochin heard about eMerge “in years past” and finally sent a team this year. The audience skewed earlier-stage than GovSignals’ typical customer of government contractors with at least $10 million in revenue and enough deal volume to justify the platform. The event nonetheless offered a useful view of the broader AI ecosystem forming around government work.
“There is a huge difference between the average company that’s bidding on this and the best companies out there that have the most innovative solutions,” Doochin noted. “Many of those innovative solutions just weren’t able to make it to the government before. With our software, they have been able to.”
How eMerge Americas Supports The C-Suite In The AI Risk Debate
The eMerge Americas team comes together in Miami, building connections across technology, business and government to advance the next generation of innovation.
Clutch Content Partners for eMerge Americas
“We host national security events in DC. We’ve been doing that the last three years, every fall,” Melissa Medina, co-founder and CEO of eMerge Americas, told me.
Those gatherings are part of a year-round operation that also hosts another 30 or 40 events across different markets beyond the annual Miami conference. Its accelerator programs concentrate on four areas: deep tech, including AI and quantum computing; defense and dual-use technology; health tech; and fintech. The priorities reflect where eMerge has developed the relationships to help participating companies advance.
“That’s where we’re bringing together these decision makers at the conference, so we want to make sure we’re also providing these companies with the network that can support them,” Medina said.
Nearly two-thirds of respondents in McKinsey’s 2026 AI Trust Maturity Survey cited security and AI risk concerns as the leading obstacle to scaling agentic AI. For C-suite leaders still figuring out how deeply to integrate AI into operations, eMerge has become something of a marketplace for finding answers. Here are four things eMerge founders would advise:
- Model capability needs evidence of governability. AE Studio’s research addresses whether increasingly capable systems can continue behaving when given extra leeway. Before giving an AI agent greater independence, first understand how its behavior has been evaluated, which actions it can take and when a human should step in.
- Infrastructure choices create lasting dependencies. Zylon’s approach puts data location, model access and operating costs back into the technology decision. Know what happens if a provider raises prices, changes a model or withdraws access, and how much work moving to an alternative would require. Private deployment may reduce some dependencies, but it doesn’t eliminate security or supply-chain obligations.
- Security and model flexibility determine which use cases become available. GovSignals’ highly sensitive market has defined its design because in government contracting, access to confidential information is as consequential as the model’s performance. Compliance in one environment doesn’t automatically confer permission to operate in another. Know where those markers lie.
- The institutions surrounding AI are part of its route to market. Research funders, infrastructure partners, government buyers, security specialists and legal advisers can influence whether a promising system reaches an operational setting. Those relationships often suggest how a company intends to meet the demands of its chosen market. Use them to vet what’s most appropriate for your company.
While Altman and Amodei are betting frontier labs can buy enough time for safety to catch up with capability, the executives I met through eMerge Americas aren’t waiting to see if that bet pays off. They’ve already begun preparing against some of the AI risk probabilities currently generating headlines.

Leave a comment