AI Risk Summit Returns August 11–12 at Half Moon Bay for Its Third Year

CISOs, policymakers, and AI researchers converge on the Ritz-Carlton for two days of hard conversation about what enterprise AI risk actually looks like in practice.

ThreatVectr Newsdesk· 2 min read
AI Risk Summit Returns August 11–12 at Half Moon Bay for Its Third Year
Share

The fog rolls in off the Pacific most mornings at Half Moon Bay. It is a strange place for an industry reckoning, but perhaps the right one — quiet enough to think, far enough from San Francisco to feel like a deliberate choice. On August 11 and 12, 2025, the Ritz-Carlton there will host the third annual AI Risk Summit, a conference that has built a reputation less on keynote theatre and more on the kinds of closed-room debates security leaders rarely have in public.

The summit draws a specific crowd. Not general technologists. CISOs, enterprise risk officers, AI researchers, developers with production deployments, and policymakers who are actively writing the rules that will govern all of it (or trying to). The mix matters. It means a conversation about model supply-chain integrity can share a hallway with one about federal AI liability frameworks, and the people who need to hear both are already in the building.

This is the event's third iteration, which gives it something a first-year conference cannot buy: continuity. Attendees who showed up in year one have watched the threat surface shift under their feet. Generative AI went from proof-of-concept curiosity to enterprise dependency in roughly the time it took most security teams to draft a usage policy. The gap between deployment velocity and risk understanding is the real subject of the summit, even when it isn't the stated one.

The agenda, as of this writing, has not been fully published. But the format has historically favored working sessions over panels, and the speaker roster tends to include practitioners who have actually had to make a call under pressure — the CISO who had to decide whether to pull a model from production after an adversarial prompt incident, the red-teamer who found the jailbreak before an attacker did. So the conversations tend to stay grounded. Someone in the room was looking at a real screen when the problem happened.

And that grounding is precisely what makes the AI security conversation hard to replicate in a webinar. Risk without context is just vocabulary. The summit's value proposition, after three years, seems to be that it forces context back into the room.

Registration details have not been publicly announced beyond the dates and venue. The event typically draws a few hundred attendees — small enough that a conversation started at breakfast can continue at dinner without losing the thread.

The question no summit can fully answer, of course, is whether the conversations that happen in a cliffside hotel in August will have moved anything by September.

© 2026 Threat Vectr