Audience attending a panel discussion at TechCrunch Disrupt, with large screens displaying speakers and event branding.

TechCrunch Disrupt 2026 puts AI safety and security at the center of founder strategy

TechCrunch Disrupt 2026 spotlights AI safety with sessions on agents, enterprise deployment, robotics, and autonomous systems.

In short

TechCrunch Disrupt 2026 is putting five AI safety sessions on its agenda to help founders build products that enterprises and users will trust. The sessions cover enterprise deployment, agent security, cloud governance, physical AI, and robotics.

  • Five Disrupt 2026 sessions focus on AI safety, security, and trust.
  • The lineup spans enterprise AI, agentic systems, cloud security, autonomy, and robotics.
  • Speakers from Anthropic, Okta, AWS, NVIDIA, Shield AI, Waabi, and General Motors are featured.
  • The common theme is deployability: getting AI into production safely, not just building impressive demos.
  • TechCrunch is positioning trust as a core business issue for AI founders.

TechCrunch Disrupt 2026 is highlighting five AI safety sessions that focus on the hardest question facing founders today: can customers trust what they are building? The sessions, scheduled for October 13–15 at Moscone West in San Francisco, are designed to help companies move AI from impressive demos into secure, deployable products.

The programming matters because AI is no longer confined to chatbots and proofs of concept. Founders are now shipping agents, enterprise systems, robots, and autonomous tools that can access company data, make decisions, and interact with the physical world. That shift turns safety, governance, and security from afterthoughts into core product requirements.

At the center of the Disrupt agenda are two stages — the AI Stage and the Real World AI Stage — where speakers from Anthropic, Okta, AWS, NVIDIA, Shield AI, Waabi, General Motors, and other companies will examine how to build systems that enterprises and consumers will actually trust.

For startups working on agentic AI, enterprise deployment, robotics, and autonomy, the message is simple: the next competitive advantage may not be model size or feature velocity, but the ability to prove reliability.

Why TechCrunch is putting AI safety front and center

AI safety has moved from an abstract research concern to an operational necessity. As more companies deploy AI into internal workflows, cloud environments, and physical systems, they are confronting questions that traditional software stacks were never designed to answer.

Founders now have to think about what access an agent should receive, how to audit its actions, how to govern data flows, and how to determine when a system is safe enough to leave the lab. In robotics and autonomy, those questions become even more urgent because the consequences of failure can extend beyond digital damage into the real world.

TechCrunch’s Disrupt programming reflects that shift. Rather than treating safety as a niche topic, the event is framing it as a market issue: if buyers do not trust a product, they will not deploy it, no matter how advanced the underlying model may be.

What makes this year different?

This year’s sessions are aimed at the moment when AI products stop being pilots and start being infrastructure. That transition forces companies to confront security architecture, enterprise procurement, testing discipline, and regulatory exposure all at once.

For founders, the implication is significant. Winning attention is no longer enough. To win revenue, they need systems that can be integrated into serious environments without creating new operational or security risks.

What Anthropic sees when enterprises actually deploy Claude

Anthropic’s applied AI leader, Cat de Jong, will open one of the most practical discussions on the schedule: why some enterprise AI efforts produce measurable business value while others remain stuck in pilot mode for months or even years.

De Jong works directly with organizations that are trying to put Claude into business-critical workflows, giving her a front-row view of where adoption succeeds, where it fails, and what operational conditions separate the two outcomes.

Anthropic’s applied AI team is seeing the difference between experiments that stay in test environments and deployments that start delivering value in real operations.

The session is especially relevant for startup founders building enterprise-facing tools. It offers a look at the gap between a compelling demo and a production-ready product, including the hidden friction points that often slow adoption: integration complexity, internal governance, user trust, and unclear business ownership.

In practice, enterprise buyers are not asking only whether an AI system works. They are asking whether it is reliable, auditable, controllable, and worth the organizational effort required to put it into use.

Why do some enterprise AI pilots stall?

Some pilots stall because they solve a narrow problem without fitting into broader workflows. Others fail because the product cannot satisfy security, compliance, or governance requirements. In many cases, the obstacle is not model quality but the organization’s inability to safely operationalize the technology.

That is why production deployment has become such a useful benchmark. A system that works in a demo can still fail in the messy reality of departments, permissions, and legacy software.

The agent security problem nobody is talking about

AI agents introduce a different kind of risk because they do not merely generate outputs — they can take actions. That means they may need access to files, systems, customer records, APIs, or internal tools, and every permission creates a possible attack surface.

Okta President of Products and Technology Ric Smith and NanoCo co-founder and CEO Gavriel Cohen will address the infrastructure side of that challenge in a session focused on agent security. Their discussion is expected to examine where application-level permissions fall short and why agentic systems may require a deeper architectural rethink.

As AI agents become more capable, the security model has to move from “who can see this” to “what can this system do, and how do we control it.”

The concern is not theoretical. A poorly constrained agent can amplify ordinary mistakes into serious security incidents. It may follow a malicious prompt, misuse credentials, or take actions outside its intended scope. In other words, autonomy introduces both efficiency and exposure.

That is why the security conversation is changing. Founders can no longer treat access control as a minor implementation detail. In agentic AI, permissions are part of the product architecture itself.

How should founders think about agent access?

Founders should begin by mapping the exact tasks an agent needs to perform and then limiting access to the smallest possible set of systems and actions. The goal is to reduce blast radius, improve monitoring, and make every action traceable.

That approach may seem restrictive, but it is often the difference between a useful tool and a dangerous one. In agent design, restraint is frequently what makes deployment possible.

Securing the AI enterprise got more complicated

The enterprise cloud environment is becoming more difficult to secure because AI products do not behave like conventional business software. They can be probabilistic, dynamic, and difficult to predict in edge cases, which means standard IT assumptions do not always hold.

In the session titled “Securing the AI Enterprise: Why the Cloud Just Got a Lot More Complicated,” AWS Vice President of Security Services Rudy Mitra, Luta Security CEO Katie Moussouris, and cybersecurity veteran Wendy Nather are set to discuss the security, governance, and observability layers enterprises now expect around AI.

For buyers, the requirements are broad: they want to know how data is handled, how model behavior is monitored, how access is controlled, and how risk is tracked across the full deployment stack. For founders, that means the product conversation now includes controls and evidence, not just functionality.

The security burden is especially high when AI systems are used in critical workflows. Enterprises are increasingly asking who can change the model, what logs exist, how decisions are reviewed, and whether the system can be rolled back if something goes wrong.

What enterprises expect before they deploy AI

  • Clear governance over data, prompts, and outputs
  • Robust observability and audit logs
  • Permission controls and role-based access
  • Testing procedures for failure modes and abuse cases
  • Deployment policies that fit existing compliance frameworks

Those expectations do not necessarily stop adoption, but they raise the bar. Startups that understand that reality are more likely to shorten sales cycles and convert pilots into paid deployments.

Building AI systems when failure is not an option

Some AI products can recover from mistakes with a retry or a manual correction. Systems used in vehicles, aircraft, industrial environments, or defense applications cannot assume that luxury.

That is the premise behind the Real World AI Stage session featuring Shield AI Chief Technology Officer Nathan Michael, General Motors Director of Robotics Strategy Mikell Taylor, and Waabi founder and CEO Raquel Urtasun. Their discussion is expected to focus on how companies determine whether an autonomous system is ready for deployment when the cost of failure is physical.

This part of the program is likely to be especially relevant to founders in robotics, autonomy, industrial AI, and mission-critical systems. The core challenge is not whether the software looks intelligent, but whether it can be trusted to operate safely under uncertainty.

In physical AI, safety is not just a feature; it is a condition for operation.

The conversation will also touch on testing, validation, safety culture, and regulatory pressure. These are increasingly central to product development in sectors where a bad decision can damage property, endanger people, or undermine public confidence in the technology.

Why does physical AI demand a different standard?

Because the consequences are immediate and tangible. A software glitch in a digital product can often be patched. An error in a vehicle, robot, or autonomous platform can be far more serious and far harder to contain.

That raises the importance of simulation, real-world testing, layered safeguards, and conservative deployment strategies. In this category, reliability is not a competitive feature; it is the entry ticket.

Robots are waiting for their ChatGPT moment

Robotics remains one of the most promising but least mature areas of AI commercialization. Unlike large language models, robots do not benefit from decades of abundant internet-scale training data. That scarcity has slowed progress and made scale harder to achieve.

NVIDIA Inception Global Head of Physical AI Les Karpas will tackle that challenge in a session focused on what is standing in the way of robotics’ next leap forward. His discussion is expected to center on data pipelines, simulation environments, and foundation models that could help robots learn more efficiently and operate more reliably.

For physical AI founders, the key question is how to create systems that can be trained, tested, and deployed in the real world without the vast data advantages that propelled modern language models.

Robotics is also where trust becomes highly visible. Customers and operators need confidence that machines will behave consistently around people, equipment, and unpredictable environments. That is why the path to a robotics breakout depends on more than better algorithms.

What is standing in the way of better robots?

Three obstacles appear repeatedly: not enough high-quality data, difficulty simulating real-world conditions accurately, and the challenge of transferring results from simulation to deployment. Each of those problems affects reliability.

Until those gaps narrow, many robotics systems will remain impressive prototypes rather than broadly deployed products.

At a glance: the five safety sessions

The sessions span enterprise AI, agents, cybersecurity, autonomy, and robotics. Together, they sketch a broader thesis about where the market is heading.

Session Stage Speakers Core theme
What Anthropic Sees When Enterprises Actually Deploy Claude AI Stage Cat de Jong Why enterprise AI moves from pilot to production
The Agent Security Problem Nobody Is Talking About AI Stage Ric Smith, Gavriel Cohen Infrastructure-level security for autonomous agents
Securing the AI Enterprise: Why the Cloud Just Got a Lot More Complicated AI Stage Rudy Mitra, Katie Moussouris, Wendy Nather Governance, observability, and enterprise security
Building AI Systems When Failure Is Not an Option Real World AI Stage Nathan Michael, Mikell Taylor, Raquel Urtasun Safety and validation for autonomous physical systems
Robots Are Waiting for Their ChatGPT Moment. Here Is What Is Standing in the Way Real World AI Stage Les Karpas Data, simulation, and the future of robotics

What founders should take away from Disrupt 2026

The common thread across all five sessions is not just safety in the abstract, but deployability. In each case, the speaker lineup is grappling with a different form of trust: enterprise trust, security trust, operational trust, and physical trust.

That matters because the AI market has matured. Investors and customers alike are increasingly asking not whether a product can be built, but whether it can be responsibly sold, integrated, and scaled.

For founders, the lesson is straightforward. The next wave of AI winners may be those that can prove they understand the constraints of production, not just the possibilities of research. The companies that get that right will be better positioned to move from early enthusiasm to durable business value.

TechCrunch Disrupt 2026 is expected to draw more than 10,000 founders, investors, operators, and tech leaders, along with more than 250 speakers and more than 300 exhibiting startups. The event will also include breakout sessions, roundtables, and networking meetings across six industry stages.

The event schedule is designed for people building in one of the most demanding periods in the history of the AI market. Models are becoming more capable, but the standards for trust are rising just as quickly. That tension is what makes these sessions more than conference programming; they are a snapshot of the new realities shaping AI commercialization.

In the end, the hardest problem may not be making AI smarter. It may be making it dependable enough for people to use without hesitation.

Frequently asked questions

What is TechCrunch Disrupt 2026 highlighting for AI founders?

TechCrunch Disrupt 2026 is highlighting five AI safety sessions that focus on the real-world challenges of deploying AI products. The agenda centers on enterprise trust, agent security, cloud governance, robotics, and physical-world autonomy.

Why is AI safety such a big topic at Disrupt 2026?

AI safety is a big topic because founders are moving beyond demos and into production systems that can access data, take actions, and operate in the physical world. That raises the stakes for security, reliability, and customer trust.

Which companies and speakers are involved in the sessions?

The sessions include speakers from Anthropic, Okta, AWS, Luta Security, NVIDIA, Shield AI, General Motors, Waabi, and other organizations. They bring perspectives from enterprise software, cybersecurity, autonomy, and robotics.

What is the main lesson for AI startups from these sessions?

The main lesson is that building a capable model is no longer enough. AI startups also need strong security, governance, testing, and deployment practices if they want customers to trust the product in production.

Share this 🚀