I've worked for companies who hired and then had to fire hackers for publishing vulnerabilities in their own and in customer products. Security is fundamentally a technology governance function, and AI ethics piece is also a technology governance function, where both hackers and AI ethics researchers are in-effect activists to create awareness for change, but aren't typically who you would put in the actual governance role.
An AI ethics conference has analogies to Defcon or Blackhat, in that shunning vendors because the attendees perceived that some prominent hackers were treated unfairly may have some precedents. Microsoft's relationship with Defcon in the 90's vs. post 2000 is an example of how this both happened and changed.
Extending that analogy, the disconnect in the relationship between researchers and vendors was a symptom of what a disadvantage the vendors were at to the asymmetric risk that activists/hackers posed because the media story of the conflict between giant corporations being vulnerable to scrappy hackers writes itself. In terms of how to handle it, google can probably use precedents from MSFT vs. defcon, and AI ethics researchers can look at how hackers both succeeded and failed to change security and tech governance.