She Said Privacy/He Said Security Titelbild

She Said Privacy/He Said Security

She Said Privacy/He Said Security

Von: Jodi and Justin Daniels
Jetzt kostenlos hören, ohne Abo

This is the She Said Privacy / He Said Security podcast with Jodi and Justin Daniels. Like any good marriage, Jodi and Justin will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century. Management & Leadership Ökonomie
  • AI Governance Built to Scale
    Jul 16 2026

    Andrew Burt is a lawyer, entrepreneur, and former national security official widely recognized as one of the world's leading experts in the intersection of law and artificial intelligence.

    Over the last decade, he has built companies, law firms, and software systems that have revolutionized how AI is managed for legal risks, and his work has impacted hundreds of millions of people around the world.

    As a pioneer in the field of legal engineering, he founded and led the world's first legal engineering team focused on automating data governance in 2016. In 2019, he co-founded and later sold the first-ever law firm run by lawyers and data scientists solely focused on artificial intelligence.

    He is co-founder and CEO of Luminos.AI, the first AI governance company focused on legal risk, where he currently serves as CEO.

    In this episode…

    Companies are adopting AI faster than they can set guardrails around it. Privacy and legal teams can review an AI model or approve a vendor contract, but AI governance doesn't stop there. Risk varies by use case, including whether the system is internal or customer-facing and the level of human oversight involved. As organizations connect new AI tools, chatbots, and agents to more business processes and systems, AI governance has to move from policy to a scalable structure.

    One of the biggest challenges companies face is making governance work at the same speed as AI adoption. Andrew Burt knows this well as a co-author of the NIST AI Risk Management Framework, where he helped shape how companies identify, document, and manage AI risk. Turning frameworks into action is where organizations often get stuck. Implementing AI guardrails requires involvement from legal, privacy, security, compliance, engineering, and other business teams. Yet when too many people share responsibility without a lead decision-maker, it can create what Andrew calls "governance debt." Effective governance starts with accountable leadership and a working connection between the teams writing the rules and the teams building the AI systems. This means moving beyond policy-heavy approaches so governance can scale with the business and the technology.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Andrew Burt, Co-founder and CEO of Luminos.AI, about the challenges of scaling AI governance. Andrew explains why traditional governance models struggle to keep up with how quickly AI systems are built and deployed. He breaks down the differences between managing risk at the model level and at the use-case level, including why the same AI tool can carry different risks depending on its use. Andrew also shares his prediction for the future of AI regulation in the United States and offers practical steps companies can take to strengthen AI governance.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • Lessons Learned From a Decade of FTC Privacy Enforcement
    Jul 2 2026

    Aaron Alva is a Harvard Berkman Klein Center fellow and the Founder of Alva Strategy Center, advising organizations and enforcers on privacy, security, and AI governance. Previously, Aaron was a lead tech advisor at the FTC, where he was instrumental in driving the agency's approach to privacy and security enforcement.

    In this episode…

    Privacy risks often hide in how companies collect, use, and share personal information. Smart TVs, health-related websites, and location data have all drawn regulatory scrutiny when data is used in ways consumers did not reasonably expect. A decade of FTC privacy enforcement shows companies what regulators consider unfair or deceptive. So, what can companies learn from these cases to strengthen their privacy practices?

    Reducing privacy risk starts when companies understand the data they collect, where it goes, why it's being used, and whether that use is necessary in the first place. Companies should pay close attention to handling sensitive data with care, including health information, location data, children's and teens' data, and driver behavior data. Embedding stronger privacy practices often comes down to establishing clear purpose limitations, thoughtful data minimization measures, limited retention, and privacy-enhancing defaults. It also requires a regular and thorough review of AdTech tools, like pixels and tags. Getting these practices right can help companies reduce regulatory risk. Yet when companies fall short, the FTC and state privacy regulators can impose remedies that reach beyond fines, requiring companies to delete data, stop certain data uses, change platform default settings, or build a stronger privacy program.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Aaron Alva, Founder of Alva Strategy Center, about what companies can learn from a decade of FTC privacy enforcement. Aaron explains the role technologists play in helping enforcement agencies work through technically complex privacy issues during investigations. He delves into lessons from major enforcement actions involving smart TVs and social media platforms and shares insights on the FTC's privacy remedies. Aaron also explains how companies can strengthen their privacy practices by setting clear limits on data use, treating sensitive data with care, and aligning privacy controls with consumer expectations.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • How to Build and Implement AI Systems That Businesses Can Trust
    Jun 18 2026

    Myles McNamara is Tarkenton's lead technical architect and full-stack developer, specializing in building secure, scalable software solutions. He oversees infrastructure, code, and system design, serving as the team's in-house expert. Previously, he worked with Fortune 500 government contractors and ran his own software and hosting companies.

    In this episode…

    Integrating responsible AI tools and systems into business operations depends less on the model itself and more on the privacy and security controls a company embeds around it. "We need AI" is often where the conversation starts, but turning that need into a safe and controlled environment requires a clear understanding of where data lives, who can access it, and what the AI system is allowed to do. Those considerations shape whether AI can support the business without creating unnecessary risks. How can organizations design and implement AI in a way that is secure and grounded in real business needs?

    Before companies implement a new AI system, they need to set guardrails around how it will operate in practice. Governance needs to be built into the system from the beginning, not left in a policy or bolted on later. Establishing clear data boundaries, access controls, and system-level permissions defines what the AI tool can access and which actions it can perform. Logging and audit trails give companies visibility into how the system is functioning, so if something goes wrong, they can understand what happened and why. AI will continue to evolve, and companies also need to ensure that their privacy and security controls keep pace through regular monitoring and continued improvements.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Myles McNamara, Principal Software Engineer at Tarkenton, about designing and implementing AI tools and systems responsibly. Myles shares what it takes to build AI agents and systems in a secure, controlled way, including how companies should think about whether AI is needed and how much autonomy it should have. He emphasizes the importance of integrating governance into system design and offers advice for safeguarding data. Myles also shares how engineering teams can balance business expectations with privacy and security concerns and discusses why AI governance might get overlooked in practice.

    Mehr anzeigen Weniger anzeigen
    27 Min.
adbl_web_anon_alc_button_suppression_t1
Noch keine Rezensionen vorhanden