This reply came a bit late, but TPM 1.2 is the only TPM version that works with AEM. Modern machines with TPM 2.0 aren’t compatible. One solution is to get a desktop motherboard with AEM support and then go buy a TPM 1.2 module.
It seems the Qubes team is working with OSResearch on a successor to AEM called SafeBoot that would obviate the need for TPM 1.2. More in this thread: Verified boot on Qubes -- a lofty dream? - #19 by fiftyfourthparallel