P

Zoe Hillenmeyer

Chief Operating Officer at Reco

Overview

Zoe Hillenmeyer serves as Chief Operating Officer at Reco [1]. Hillenmeyer maintains a presence on X (formerly Twitter) at the handle @ZoeLive [2].

Career history

  1. Chief Operating OfficerApr 2026 to PresentReco
  2. Chief Marketing OfficerMar 2025 to PresentProtect AI
  3. Head of Tech AlliancesMar 2024 to Mar 2025Protect AI
  4. Chief Commercial Officer (CCO)Jan 2022 to Jun 2023Peak
  5. Head of AI Business Development and Specialst SalesFeb 2020 to Jan 2022Amazon Web Services (AWS)
  6. Head Of Business Development - Industrial & Applied AIMar 2018 to Feb 2020Amazon Web Services (AWS)
  7. Chief Product AdvisorFeb 2018 to Sep 2018Cognitive Application Studios
  8. Global Offering Management - Transformation & StrategyFeb 2017 to Nov 2017IBM

Education

  1. WUMBA, Management & ConsultingWashington University in St. Louis

Insights & ideas

The through-line

Everything Zoe Hillenmeyer says circles back to a single conviction: security has to move with AI adoption rather than behind it. She frames it as the reason the company exists, arguing that "there should be no enterprise adoption of AI without the security of AI and it's why we built the company" [1]. The corollary is a stubborn insistence on where the risk actually sits today, which is usually not where the conversation is. She describes a market fixated on the newest model class while the bulk of production workloads, and therefore the bulk of exposure, sits somewhere far less glamorous [1].

The second thread is timing. Hillenmeyer thinks in terms of the gap between a technology becoming real and a technology becoming an enterprise workload, and she treats getting ahead of that gap as both a product strategy and a credibility claim, pointing out that the company was founded in 2022, "before chat GPT was live" [1].

On no AI without secure AI

Her position is that AI security is not a feature bolted onto AI adoption but a precondition for it. She wants the security function present at the moment models are chosen and built, not after deployment, and she is blunt that this has not been the norm: "security hasn't been invited to the table historically on a lot of this ML and AI innovation. We want security at the table" [1]. The evidence she offers for the gap is telling in its own right, that when working with customers, "we know more about their ML than the security team might" [1]. The practical version of the argument is confidence at the point of building: a developer bringing a third-party or open source model into their environment should already know it has been scanned and "will not introduce any kind of nefarious code" into the enterprise [1].

On the lag between hype and production

Hillenmeyer treats the distance between a trend's peak attention and its commercial reality as predictable rather than surprising. Her framing is that "the commercial impact and relevance" and "the viability of those trends into true technology that's adopted at commercial scale" always lags the hype [1]. Applied to the current cycle, generative AI drew the noise a year or two ago and those workloads "are just now going to production," while agentic is the hypiest thing now [1]. She does not dismiss it, and is careful to say the technology "is a real thing" with real science underneath, but her prediction is that agentic will not become "true commercial complex enterprise workloads until the end of this year and into next year" [1]. The implication for a security vendor is that you build for the trend before the workloads arrive, and you keep building for the workloads that arrived years ago.

On the iceberg of predictive ML

This is her sharpest and most contrarian point. While the industry talks about agentic and generative systems, she says, "the majority of production for major enterprises today is actually on predictive ML," the kind of thing put into production roughly between 2015 and 2020 [1]. Internally she calls it the iceberg: generative and agentic represent "absolutely meaningful changes in the threat environment," but "there's still about 80 90% of production ML is running on more traditional predictive ML" [1]. That analysis is what justifies heavy investment in model scanning, so that those older workloads have their code scanned on an ongoing basis rather than being quietly left out of the AI security conversation [1].

On securing AI across the deployment cycle

Hillenmeyer describes the problem as a lifecycle rather than a single control point, with a product for wherever a customer sits in that cycle [1]. At the front is Guardian, a model scanner built to detect things like architectural backdoors and similar threats before a model enters an enterprise environment [1]. In the middle is recon, which addresses the pre-production question of what UAT and pen testing look like for a generative application. Her argument for why that phase needs its own tooling is that these applications behave nothing like conventional software: the models "are stochastic by nature. They change. They're dynamic. The way that you interact with them will change the way that they interact back with you" [1]. Her conclusion is that before pushing any generative application to production, "you need to effectively red team it and do some pen testing against it" [1].

The third layer is runtime security for applications already in production, which she describes as being for today's and tomorrow's AI [1]. The threat model there is an application used as an entry point: "if you have a bad actor on the other end of an app, they can use that as a front door to your infrastructure and to your data," which is why monitoring has to be continuous and has to stop suspicious behaviour before it reaches additional data in the environment [1]. She positions Layer explicitly at the difficult end of the market, built for the largest scale and the most complex environments, and pitched at customers with a "messy, wonky, weird architecture" or scale "beyond the scope of what most of these kind of more scrappy AI firewalls that are out there can handle" [1].

On threat research as the real moat

Where competitors are also scanning, Hillenmeyer argues the differentiator is coverage and speed of detection. Because of the Hugging Face partnership, the company scans the entire hub, which she says means detecting problem models "much sooner than any other competitor," including competitors who scan but do not match the same latency in surfacing threats [1]. Alongside that sits the world's largest AI and ML dedicated bug bounty program, which she frames as a way to "scale our eyes and ears to the ground" and surface model file vulnerabilities and other signals through a community of expert ethical hackers [1]. Taken together, she claims a position in threat research leadership that no one else is near [1]. The wider platform story is enterprise readiness and scale, supported by partnerships including AWS, Azure, Hugging Face, data bricks and elastic [1].

On the scarcity of genuine AI experience

Hillenmeyer treats deep tenure as the thing that makes the market read possible, and she notes how rare it is: long-term AI veterans are "a hard thing to find in the industry" [1]. She describes more than a decade working in AI herself, and a leadership team where the members who have not spent ten years in AI have spent ten years in cyber security, forming what she calls "a band of thought leaders" whose job is to identify the emerging threat vector introduced by AI technologies and then solve for it [1].

Takeaways

  • Her founding premise is that there should be no enterprise adoption of AI without the security of AI [1].
  • The security team is often the last to know: she says her company frequently knows more about a customer's ML than that customer's security team does, because security was never invited to the table on AI innovation [1].
  • Attention and production are out of sync. Generative workloads are only now reaching production, and she predicts agentic will not become complex enterprise workloads until the end of this year and into next year [1].
  • The iceberg argument: roughly 80 to 90 percent of production ML still runs on traditional predictive ML from the 2015 to 2020 era, which is why ongoing model scanning matters as much as securing the newest systems [1].
  • Generative applications need red teaming and pen testing before production because the models are stochastic and dynamic, and how you interact with them changes how they respond [1].
  • A production generative application is a potential front door to infrastructure and data for a bad actor, so runtime monitoring has to be continuous [1].
  • Coverage plus community is the research edge: scanning the entire Hugging Face hub gives earlier detection than competitors, and the largest AI and ML dedicated bug bounty program extends the vulnerability signal [1].

Media & appearances

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.