• How to Govern AI Agents Effectively
    Sep 24 2026

    Camilo Artiga-Purcell is General Counsel at Kiteworks, where he leads the company's global legal operations across commercial contracts, data privacy and cybersecurity compliance, M&A, litigation, and regulatory strategy. He has advised on seven acquisitions and brings over a decade of experience litigating complex commercial disputes from inception through trial and appeal. A recognized voice on AI governance and data security risk, Camilo regularly publishes on the legal challenges organizations face as they adopt emerging technologies.

    In this episode…

    AI agents are becoming more common in everyday business operations, gathering data and carrying out tasks for organizations. Traditional governance policies typically place guardrails around the AI tools human employees can use, what data they can access, and how that information can be used for business purposes. Companies need to extend those same controls to AI agents as they deploy them to reduce risk and meet compliance requirements under a growing patchwork of AI regulations and existing US and global privacy laws. So, what does it take to govern AI agents effectively?

    Before allowing AI agents to access and use sensitive data, organizations need to establish governance policies that define what they can or cannot do with it. Companies can then use tools like software wrappers to implement these policies on the front end while generating an audit trail on the back end that logs the agent's identity, the prompt, where it went, and what it did. Those records can plug into e-discovery systems to show whether the agent operated in compliance and provide a clear path to reconstruct its activity if it goes rogue. Alongside these controls, companies should also put security measures in place when they adopt AI models, rather than after problems arise. Employees also need training on how to use AI responsibly, with ongoing education that evolves with the technology.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Camilo Artiga-Purcell, General Counsel at Kiteworks, about governing AI agents as their use expands across organizations. Camilo explains why governance policies need to be applied directly to AI agents, with evidence-quality audit trails that document their activity. He discusses the importance of proactively embedding security controls into AI tools, highlighting the risks surrounding certain AI models. Camilo also shares his insights into rising AI costs and how organizations can determine which models are appropriate for different teams, and he offers practical tips for verifying AI outputs and pressure testing the results.

    Mehr anzeigen Weniger anzeigen
    29 Min.
  • How to Solve AI's Data Problem
    Sep 10 2026

    Cillian Kieran is the Founder and CEO of Ethyca, where he leads its product vision, engineering strategy, and growth. A serial entrepreneur and privacy engineer with two decades of experience, he launched Ethyca in 2018 to bring privacy-by-design infrastructure to developers. Earlier, he built the digital consultancy CKSK to 100-plus employees across four countries, serving clients like PepsiCo, Heineken, and PlayStation. He pairs deep technical grounding with a track record of scaling data-intensive businesses.

    In this episode…

    As companies expand their use of AI, they need guardrails around how the technology is used by employees and how those systems use enterprise data. Because models are trained on data, bias can be introduced through this information, while systems also continue to use this data to perform different tasks. This creates risk, and managing it requires evaluating what data a model or tool can access, its intent when it uses that data, and the economic, ethical, and regulatory implications of that intended use. So, what controls do companies need to manage AI and company data safely?

    Because AI wants to satisfy a user's request, it will keep trying to access data unless clear boundaries define what it can use. Using AI responsibly requires managing the data behind it alongside the technology itself. To do this effectively, companies need to know what data they have collected, where it came from, whether they have sufficient consent, and what legal basis applies to its use. Once companies understand those elements, they can give AI access to the information it needs for a specific purpose while limiting what falls outside that use, allowing them to leverage the value of their data while minimizing risk. Governance also needs to move from written policies into controls that can be enforced on a system in real time. And while AI can streamline processes like privacy risk assessments by gathering information and comparing it against policies, past assessments, and relevant requirements, human privacy experts still need to review the output for accuracy and challenge AI when it's wrong.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Cillian Kieran, Founder and CEO of Ethyca, about the importance of unifying AI governance and data governance. Cillian explains how bringing these two areas together helps companies stay in control of their data while allowing the technology to support the business. He discusses why companies are turning to open-source models for greater sovereignty and cautions that bringing a model in-house can still introduce risks. Cillian also addresses the tension between AI's need for data and privacy's data minimization principles, and he stresses why professionals need to think critically, question AI outputs, and avoid relying on AI as a crutch.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • Maintaining Human Intelligence in an AI World
    Aug 27 2026

    Elise Houlik is the Chief Privacy Officer at Intuit, where she leads the company's global privacy and responsible data innovation and protection strategy, ensuring data is used to safely power innovation across Intuit's ecosystem of financial technology products. Her team is deeply engaged with the business on all matters related to product development, data innovation and governance, and information security.

    In this episode…

    Legal and privacy professionals are using AI more often to save time and accomplish more in their day-to-day work. While these tools offer clear advantages, they also generate convincing outputs that are incomplete, generic, or factually wrong. Using AI responsibly requires professionals to apply human judgment and review the output closely to ensure it is accurate and supported before relying on it. As AI becomes more embedded in legal and privacy work, critical thinking skills remain just as important as knowing how to use the technology.

    Professionals get the most value from AI when they view it as a collaborator, rather than an authority. As privacy and legal teams use AI to kickstart analysis, pull facts together, and hunt for nuances across fragmented laws, they need to compare its answers against actual laws and reputable sources and challenge the tool when an output misses the mark instead of accepting it at face value. Being mindful about the personal information they put into public models is equally important. Professionals should also be comfortable using a variety of different tools and learning which ones fit different purposes. And as companies hire the next generation of tech-savvy professionals, they need to ensure they don't become overly reliant on AI and provide them with hands-on experience and exposure to real conversations that strengthen analytical skills.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Elise Houlik, Chief Privacy Officer at Intuit, about the importance of maintaining human intelligence in the age of AI. Elise shares how AI is changing the skills employers value in legal and privacy professionals and explains why human judgment, curiosity, and a willingness to challenge AI-generated answers are essential as these tools become a standard part of workflows. She highlights why junior professionals still need practical experience and peer-to-peer learning opportunities and shares her perspective on keeping human intelligence at the center of how professionals use AI. Elise also offers tips for building AI skills and experimenting with different tools.

    Mehr anzeigen Weniger anzeigen
    30 Min.
  • Navigating the New Era of Data Broker Laws
    Aug 13 2026

    For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005.

    In this episode…

    Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it?

    Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation.

    Mehr anzeigen Weniger anzeigen
    33 Min.
  • The People-First Approach to Building Effective Privacy Programs
    Jul 30 2026

    Chris Tarbell is a leading privacy, cyber, and data strategy executive. He currently serves as the Chief Privacy Officer for VERSANT Media LLC. Prior to his current role, Chris was an associate general counsel for Fanatics and the Walt Disney Company, where he advised global businesses on compliance with domestic and international privacy, data security, and related consumer protection laws. Most recently, Chris served as Senior Counsel at the leading law firm of Kelley Drye and Warren, where he also supported clients in numerous regulatory investigations related to marketing and advertising.

    In this episode…

    Building strong privacy programs relies on human connection and a deep understanding of organizational dynamics and business goals. To be successful, privacy professionals must participate in the business rather than just focusing on meeting legal requirements. This approach enables leaders to advocate for the tools, budget, headcount, and other resources to move the program forward. Because privacy impacts many business functions, it is very much a people business, requiring strong relationships, cross-functional collaboration, and the ability to build trust with stakeholders and internal teams. So, what steps can companies take to achieve this?

    Putting this into practice starts with assembling a people-first privacy team and hiring individuals with the soft skills to step into unfamiliar situations, assess what is needed, and work across departments to move the program forward. By bringing curiosity and enjoyment to privacy work, they create an environment where other departments are more willing to involve privacy early and often. This approach is especially important in the media industry, where privacy pros may need to work with news colleagues to balance the right to be forgotten with First Amendment considerations or partner with intellectual property teams to protect personal information during piracy investigations. And while collaboration is essential, teams must also determine what can realistically be achieved with the time and resources available without allowing perfection to stall progress.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Chris Tarbell, Chief Privacy Officer at VERSANT Media, about building effective privacy programs through relationships and collaboration. Chris explains how his experience as both in-house and outside counsel shaped his ability to understand business objectives, advocate for resources, and communicate the value of privacy. He shares insights on the cross-disciplinary nature of privacy work in the media industry, lessons from building a program during a major corporate spinoff, and the importance of creating a people-first privacy team capable of handling unfamiliar business challenges. Chris also explains why bringing some fun to privacy work can make a program more effective.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • AI Governance Built to Scale
    Jul 16 2026

    Andrew Burt is a lawyer, entrepreneur, and former national security official widely recognized as one of the world's leading experts in the intersection of law and artificial intelligence.

    Over the last decade, he has built companies, law firms, and software systems that have revolutionized how AI is managed for legal risks, and his work has impacted hundreds of millions of people around the world.

    As a pioneer in the field of legal engineering, he founded and led the world's first legal engineering team focused on automating data governance in 2016. In 2019, he co-founded and later sold the first-ever law firm run by lawyers and data scientists solely focused on artificial intelligence.

    He is co-founder and CEO of Luminos.AI, the first AI governance company focused on legal risk, where he currently serves as CEO.

    In this episode…

    Companies are adopting AI faster than they can set guardrails around it. Privacy and legal teams can review an AI model or approve a vendor contract, but AI governance doesn't stop there. Risk varies by use case, including whether the system is internal or customer-facing and the level of human oversight involved. As organizations connect new AI tools, chatbots, and agents to more business processes and systems, AI governance has to move from policy to a scalable structure.

    One of the biggest challenges companies face is making governance work at the same speed as AI adoption. Andrew Burt knows this well as a co-author of the NIST AI Risk Management Framework, where he helped shape how companies identify, document, and manage AI risk. Turning frameworks into action is where organizations often get stuck. Implementing AI guardrails requires involvement from legal, privacy, security, compliance, engineering, and other business teams. Yet when too many people share responsibility without a lead decision-maker, it can create what Andrew calls "governance debt." Effective governance starts with accountable leadership and a working connection between the teams writing the rules and the teams building the AI systems. This means moving beyond policy-heavy approaches so governance can scale with the business and the technology.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Andrew Burt, Co-founder and CEO of Luminos.AI, about the challenges of scaling AI governance. Andrew explains why traditional governance models struggle to keep up with how quickly AI systems are built and deployed. He breaks down the differences between managing risk at the model level and at the use-case level, including why the same AI tool can carry different risks depending on its use. Andrew also shares his prediction for the future of AI regulation in the United States and offers practical steps companies can take to strengthen AI governance.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • Lessons Learned From a Decade of FTC Privacy Enforcement
    Jul 2 2026

    Aaron Alva is a Harvard Berkman Klein Center fellow and the Founder of Alva Strategy Center, advising organizations and enforcers on privacy, security, and AI governance. Previously, Aaron was a lead tech advisor at the FTC, where he was instrumental in driving the agency's approach to privacy and security enforcement.

    In this episode…

    Privacy risks often hide in how companies collect, use, and share personal information. Smart TVs, health-related websites, and location data have all drawn regulatory scrutiny when data is used in ways consumers did not reasonably expect. A decade of FTC privacy enforcement shows companies what regulators consider unfair or deceptive. So, what can companies learn from these cases to strengthen their privacy practices?

    Reducing privacy risk starts when companies understand the data they collect, where it goes, why it's being used, and whether that use is necessary in the first place. Companies should pay close attention to handling sensitive data with care, including health information, location data, children's and teens' data, and driver behavior data. Embedding stronger privacy practices often comes down to establishing clear purpose limitations, thoughtful data minimization measures, limited retention, and privacy-enhancing defaults. It also requires a regular and thorough review of AdTech tools, like pixels and tags. Getting these practices right can help companies reduce regulatory risk. Yet when companies fall short, the FTC and state privacy regulators can impose remedies that reach beyond fines, requiring companies to delete data, stop certain data uses, change platform default settings, or build a stronger privacy program.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Aaron Alva, Founder of Alva Strategy Center, about what companies can learn from a decade of FTC privacy enforcement. Aaron explains the role technologists play in helping enforcement agencies work through technically complex privacy issues during investigations. He delves into lessons from major enforcement actions involving smart TVs and social media platforms and shares insights on the FTC's privacy remedies. Aaron also explains how companies can strengthen their privacy practices by setting clear limits on data use, treating sensitive data with care, and aligning privacy controls with consumer expectations.

    Mehr anzeigen Weniger anzeigen
    36 Min.
  • How to Build and Implement AI Systems That Businesses Can Trust
    Jun 18 2026

    Myles McNamara is Tarkenton's lead technical architect and full-stack developer, specializing in building secure, scalable software solutions. He oversees infrastructure, code, and system design, serving as the team's in-house expert. Previously, he worked with Fortune 500 government contractors and ran his own software and hosting companies.

    In this episode…

    Integrating responsible AI tools and systems into business operations depends less on the model itself and more on the privacy and security controls a company embeds around it. "We need AI" is often where the conversation starts, but turning that need into a safe and controlled environment requires a clear understanding of where data lives, who can access it, and what the AI system is allowed to do. Those considerations shape whether AI can support the business without creating unnecessary risks. How can organizations design and implement AI in a way that is secure and grounded in real business needs?

    Before companies implement a new AI system, they need to set guardrails around how it will operate in practice. Governance needs to be built into the system from the beginning, not left in a policy or bolted on later. Establishing clear data boundaries, access controls, and system-level permissions defines what the AI tool can access and which actions it can perform. Logging and audit trails give companies visibility into how the system is functioning, so if something goes wrong, they can understand what happened and why. AI will continue to evolve, and companies also need to ensure that their privacy and security controls keep pace through regular monitoring and continued improvements.

    In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Myles McNamara, Principal Software Engineer at Tarkenton, about designing and implementing AI tools and systems responsibly. Myles shares what it takes to build AI agents and systems in a secure, controlled way, including how companies should think about whether AI is needed and how much autonomy it should have. He emphasizes the importance of integrating governance into system design and offers advice for safeguarding data. Myles also shares how engineering teams can balance business expectations with privacy and security concerns and discusses why AI governance might get overlooked in practice.

    Mehr anzeigen Weniger anzeigen
    27 Min.