What to Watch at ALL IN 2026: The Enterprise AI Questions Montréal Will Be Asking

Abstract enterprise AI conference illustration showing four connected themes and a runtime governance checkpoint

AI is moving from demonstration to operation. At ALL IN 2026, the important question is not whether models are becoming more capable. It is whether enterprises, public institutions, and infrastructure providers can deploy that capability with enough control to make it reliable, accountable, and economically useful.

The program makes that question concrete through four talks: “The New AI Infrastructure Race: Energy, Data Centres, and Sovereignty,” “Build vs. Buy,” “The AI Cyber Battleground: Defense, Offence and Resilience,” and “Building Responsible, Sovereign, and Sustainable AI.” Together, they map the decisions that determine whether enterprise AI remains a promising pilot or becomes controlled production infrastructure.

On September 16–17, more than 7,500 participants from 40+ countries and 260+ speakers are expected at the Palais des congrès de Montréal. The event spans AI and society, applied AI and enterprise transformation, frontier AI, data and infrastructure, and physical AI and robotics, with Germany as Country of Honour. This preview uses four specific program elements to examine the governance questions enterprise leaders should carry into the event.

The four talks to watch

Exact talk title What the talk addresses Enterprise governance question
“The New AI Infrastructure Race: Energy, Data Centres, and Sovereignty” Sovereign compute, data autonomy, resilient data centres, energy supply, and supply-chain security Can your organization control the infrastructure and dependencies that its AI workflows rely on?
“Build vs. Buy” Proprietary models, commercial solutions, open source, cost, governance, data control, and technological sovereignty How does your sourcing decision change your data, provider, and runtime-control boundaries?
“The AI Cyber Battleground: Defense, Offence and Resilience” Evolving cyber threats, deepfakes, digital identity, defense, offence, and organizational resilience Can you govern what an AI agent is allowed to access and execute when attacks move at machine speed?
“Building Responsible, Sovereign, and Sustainable AI” Independent evaluation, local adaptation, strategic compute, energy efficiency, and decision-making autonomy Does trusted infrastructure also provide trusted authorization for every agent action?

“The New AI Infrastructure Race” makes sovereignty operational

The Forum session “The New AI Infrastructure Race: Energy, Data Centres, and Sovereignty” is the clearest place to examine sovereign AI as an operating requirement rather than a branding exercise. The published description connects computing capacity, energy supply, data-centre resilience, digital sovereignty, data autonomy, and supply-chain security. Its panel brings together perspectives from Hypertec Group, TELUS, Nokia Bell Labs, and NVIDIA, with Murad Hemmadi of The Logic as moderator.

The title captures the change in enterprise AI strategy. Organizations are no longer evaluating only which model performs best on a benchmark. They are evaluating where compute resides, who operates the infrastructure, which energy and hardware dependencies sit beneath the workload, and whether the supply chain remains resilient when conditions change. If an enterprise depends on capacity, networks, components, or providers it cannot influence, its AI strategy contains a control gap.

Sovereign AI means controlling more than data residency. It includes the models, compute, deployment paths, operational decisions, and trusted relationships that determine whether an organization can continue to use AI under its own policies. Canada’s opportunity is therefore tied to infrastructure, energy, research, talent, and the ability to keep strategically important workloads within trusted operating boundaries.

The enterprise question is direct: where can your AI context travel, which infrastructure can process it, and who controls the decision when an agent turns that context into an action?

That final question matters because sovereign infrastructure and sovereign authorization are different controls. A Canadian-hosted model can still overreach. A trusted data centre can still expose excessive authority to an agent. Keeping data and compute in a trusted jurisdiction does not determine whether an agent may modify a record, approve a transaction, or call a privileged tool.

Infrastructure location answers where the system runs. Runtime authorization answers what the system may do. Enterprises need both.

“Build vs. Buy” is a governance decision

The Agora session “Build vs. Buy” examines one of the decisions that shapes every enterprise AI program: whether to use proprietary models, commercial solutions, open-source components, or a combination of approaches. The published context includes perspectives from BDC, Sun Life, the Vector Institute, and AMD, moderated by Yvonne Lau of the Financial Post.

This is not only a procurement discussion. It is a discussion about dependency, data control, evaluation, cost, flexibility, and technological sovereignty. A proprietary model may reduce implementation work while increasing provider dependency. A commercial platform may accelerate deployment while limiting visibility into data paths, updates, and subprocessors. An open-source stack may increase flexibility while shifting more responsibility for evaluation, security, maintenance, and operational control to the enterprise.

No sourcing decision answers the runtime authorization question by itself. Whether an agent uses a hosted model, a locally deployed model, or an open-source orchestration stack, it can still reach enterprise tools and systems of record. The organization must still define which operations the agent may perform, which data it may use, and which actions require a named approver.

The distinction is categorical: model choice determines dependencies; policy determines authority. A build-versus-buy decision should therefore include a control review that asks what the chosen architecture can reach, how context moves through it, and where an independent enforcement point will evaluate actions before execution.

“The AI Cyber Battleground” moves from detection to resilience

The Agora session “The AI Cyber Battleground: Defense, Offence and Resilience” addresses evolving cyber threats, deepfakes, digital identity, and organizational resilience. The published panel includes Jean Le Bouthillier of Qohash, Wendy J. Wagner of Gowling WLG, and Ralf Wintergerst of Giesecke+Devrient and Bitkom, moderated by Justin Ling.

The session is especially relevant to enterprise AI governance because cyber risk is no longer limited to whether a model produces unsafe text. AI systems can influence identity, accelerate deception, retrieve sensitive information, and trigger changes across business systems. As agents act with greater speed and autonomy, resilience depends on whether an organization can contain the action, preserve control, and reconstruct the decision.

A firewall can control a network path. Identity and Access Management can authenticate a principal. An API gateway can manage a connection. None of these controls, alone, determines whether an AI agent should approve a payment, alter a customer record, access a regulated dataset, or invoke a privileged tool in the current workflow.

That decision requires action-level context. The system must identify the user who initiated the task, the agent performing it, the tool and operation requested, the data involved, the applicable policy, and the consequences of allowing the action. It must then return a clear result before execution: ALLOW, BLOCK, or ESCALATE.

Detection after an action is useful for investigation. It is not a substitute for prevention. A resilient enterprise does not only identify abnormal behavior; it can stop an unauthorized action before it reaches the system of record.

“Building Responsible, Sovereign, and Sustainable AI” connects local capability to control

The AI Sessions program element “Building Responsible, Sovereign, and Sustainable AI” brings the Université Laval and Institute for Intelligence and Data perspective into the event. The published discussion focuses on independent evaluation, local language and sector adaptation, strategic computing capacity, energy efficiency, and decision-making autonomy for Québec and Canada.

That framing makes sovereign AI practical. A sovereign system is not simply one that excludes outside technology. It is one that gives institutions meaningful control over how technology is evaluated, adapted, deployed, and used. Local language requirements, sector-specific workloads, public-sector needs, privacy obligations, and energy constraints all determine whether a system can operate responsibly in its intended environment.

The enterprise governance question is what happens after the model and infrastructure decisions are made. An agent may use a locally evaluated model and operate on trusted compute while still accessing too much data or invoking an unauthorized tool. Sovereign infrastructure is not sovereign authorization. The organization still needs policies that govern where context may travel, why it may be used, and what action the agent may take.

A practical control model separates three boundaries:

  • Trusted path: where enterprise context may travel.
  • Purpose boundary: why that context may be used.
  • Action boundary: what operation the agent may perform.

LangGuard’s perspective is that these boundaries must be enforced at runtime. SCOPE-MCP maps the complete agent action surface, including connected tools, exposed operations, and reachable systems of record. Arbiter evaluates consequential actions before execution, allowing safe operations automatically while blocking or escalating actions that exceed scope, violate policy, or cross a segregation-of-duties boundary.

What enterprise leaders should carry into Montréal

These four talks create a practical agenda for enterprise AI leaders:

  1. Map the dependency surface. Identify the models, providers, compute, data paths, tools, and systems of record inside each workflow.
  2. Separate infrastructure sovereignty from action authority. Know where AI runs, then define exactly what each agent may access and execute.
  3. Evaluate sourcing decisions as control decisions. Build, buy, and open-source choices change dependency and visibility, but none removes the need for runtime authorization.
  4. Move cybersecurity controls closer to the action. Monitor threats, but also hold, block, or escalate high-risk tool calls before execution.
  5. Preserve evidence. Record the user, agent, operation, policy, decision, timestamp, and approver so the action can be replayed and explained.

The production question is not only whether an agent works. It is whether the organization can prove that the agent worked within authorized bounds, using trusted infrastructure, under a policy that existed before the action occurred.

ALL IN 2026 will bring these questions together across infrastructure, sourcing, cyber resilience, and responsible sovereign AI. The common thread is control: who decides, what the system may do, where context moves, and whether the organization can prove what happened.

The LangGuard team will be available to meet at ALL IN in Montréal on September 16–17. If you are attending and working through the move from AI pilots to controlled production, connect with the team at the event to discuss your agent action surface, sovereign AI requirements, runtime policies, approvals, and audit evidence.