IAPP GPS 2026 reflections
A handful of takeaways from the IAPP conference plus lots of recommendations
Drafts. So many drafts. My virtual drawer1 is full of them. And this is why: An idea pops up in my head - often during running. Quickly, before the idea disappears, I start composing a post in my mind. It’s an exciting idea, it all sounds brilliant. As soon as I arrive home, I rush to the computer to jot it down. But what is this? Where do all these inconsistencies, fallacies and flawed examples come from? Minutes ago, this all sounded superb in my head!
It’s the following quote (included in my “About” page) come to life:
“Writing is nature’s way of letting you know how sloppy your thinking is.”
Dick Guindon
So, while I am working on kicking these unwieldy drafts into publishable shape, I am sharing a handful of take-aways from the IAPP Global Privacy Summit in DC.
IAPP GPS 2026 reflections
[While all of my Substack posts are my personal views, full disclosure that I am on the board of the IAPP.]
AI governance: While some privacy professionals are quite happily leaving AI governance to others, the trend for the profession (and the IAPP with it) seems to go the other way. Many privacy teams have taken on AI governance and even broader “digital responsibility” (see IAPP’s Organizational Digital Governance Report 2025). Not least because the status (and budgets) of privacy teams seem to be waning (a point Woodrow Hartzog called out in his keynote).
Prince Harry: The talk of the event was undeniably Harry, the ‘Prince of Privacy’2. Some loved his keynote (video, summary); others were less impressed. While I don’t agree with all of it (e.g., the idea of innovation as a ‘darling word’ that shields from regulation), I liked his keynote. He emphasised that we need (a) better alignment between business models and human interests and (b) more moral leadership. Who’s to argue with that?
Cookie consent banners conquering the US: The cookie consent banner is having its moment in the US. Not because it’s a brilliant European invention (it isn’t!) but as a reaction to a wave of litigation against website tracking. Plaintiffs rely on decades-old state wiretapping and privacy laws, among others, to challenge tracking practices (see this Morgan Lewis article for a good overview). This has in turn led companies to adopt EU-style cookie banners on US websites to obtain consent and reduce litigation risk.
Limited global AI regulation: While US states are busy drafting and adopting risk-specific AI laws3, there is still a surprising lack of international AI legislation. My 2026 prediction seems to hold up so far: Globally, countries generally don’t see the EU AI Act as a model to adopt.
Privacy and AI governance with AI: A hot topic during side events was privacy / AI governance teams building their own AI agents to assist with privacy impact assessments (PIAs) and AI impact assessments (AIIAs) as well as with other resource-intensive and repeatable processes. How will this impact the privacy and AI tool vendors? I suspect they (just as SaaS companies more generally) will point out the challenges in maintaining these tools once implemented. But for internal teams, it’s a good way to experiment with AI agents and build AI literacy.
Recommended posts on GPS
Isabelle Roccia’s review of the closing session: https://www.linkedin.com/posts/isabelleroccia_iappsummit26-trust-ai-ugcPost-7444796718107414528-fjxq
Joe Jones’ thoughts on Princy Harry’s keynote: https://www.linkedin.com/posts/joe-jones-b1793bb6_iappsummit26-ugcPost-7445346957801279488-eU7D
Natalie Moreno’s takeaways: https://www.linkedin.com/posts/dr-nathalie-moreno-882908_iappsummit26-privacy-digitaltrust-ugcPost-7445194983902494721-scuW
Barbara Cosgrove’s highlights: https://www.linkedin.com/posts/barbara-cosgrove_iapp2026-aigovernance-digitaltrust-ugcPost-7447332752737153024-ytZ2
Uplifting
Good news: The Artemis II mission has generally been a ray of sunshine during crazy times, and this Progress Network post highlights how much has changed for the better since the 60s/70s when we last circled the moon.
Sound bite: The CHVRCHES’ version of ‘Addicted to Love is fabulous:
Eye candy: Stunning Artemis II shot of the crescent Earth appearing over the moon’s horizon
My posts elsewhere
Best of recent posts on LinkedIn and Bluesky:
Hiring for blind loyalty (Bluesky)
On the second order effects of the recent social media decisions (Bluesky)
Oh so many metaphors (photo) (Bluesky)
Stairway to heaven (photo) (Bluesky)
Recommended
Reading: Pilots and the challenges for humans in the loop
Ashley Goodall uses the analogy of airplane accidents as a warning on the complexities of humans in the loop for AI: Supervising very complex systems and “staying ahead” of these systems is challenging, and we are not very good at it.
Reading: Will AI help us to be less politically divisive?
John Burn-Murdoch writes in the FT (£) about large language models elevating expert consensus and moderating views, in sharp contrast to social platforms.
If all goes well, future AI personal assistants could be feeding the “better angels” in us and nudging us towards good behaviour. Big “if”, of course.
https://www.ft.com/content/3880176e-d3ac-4311-9052-fdfeaed56a0e?shareType=nongift
Reading: Omnibus predictions - or how to build your own AI forecast machine
Intriguing post by Privacat on how she used Claude to vibe-code a full research & forecasting pipeline that resulted in the prediction that the AI Act will be reformed this year. The post also provides a great overview of the state of play of the Digital Omnibus packages.
Watching: Can AI be conscious?
Fascinating presentation of Anil Seth’s case against AI becoming conscious. He rejects “computational functionalism” (the idea that consciousness arises out of information processing and computation alone and doesn’t necessarily need a biological brain) and advocates for biological naturalism (that consciousness requires the messy chemical processes of the animal / human brain).
Reading: An LLM too dangerous to release
Great Simon Willison article on Anthropic’s Project Glasswing. Sure, there is always the question whether this is done to create hype, but it seems that Claude Mythos Preview is indeed so capable at finding and exploiting security vulnerabilities that it warranted restricting access to a limited number of companies. Seems like a paradigm shift.
https://simonwillison.net/2026/Apr/7/project-glasswing/
Reading/listening: AI destroying institutions?
Great episode of the Scaling Law podcast discussing Woodrow Hartzog’s paper ‘How AI destroys institutions’. I love it when podcasts robustly challenge guests and their ideas (but of course by ‘disagreeing agreeably’ like here).
Podcast episode:
Paper: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5870623
Reading: How to fix privacy gaps in consumer AI
Great summary by Theodore Christakis of his study and recommendations on how to deal with the privacy (and other) risks of powerful chatbots. It’s important that we start mapping these risks and potential safeguards.
I agree with a lot of the assessment but maybe not with all the recommendations. For instance, I don’t think more transparency and notices are helpful in a time when we are drowning in information (but still have transparency available on demand).
https://iapp.org/news/a/new-study-maps-the-privacy-gap-in-consumer-ai-and-proposes-a-fix
Reading / listening: Should you use AI for writing?
I highly recommend this clear-eyed and pragmatic piece by Andrés Guadamuz (TechnoLlama) about using AI for writing in academia and more broadly. I particularly like the acknowledgment of the incentive structure and of the fact that for many people AI is a gift because they struggle with writing.
https://www.technollama.co.uk/why-are-people-adopting-ai-to-write
On the same topic, a recent Hardfork episode included an interesting section on using AI for writing from a journalistic perspective. Not least on the idea that GPT-2 was a better writer due to less stringent post-training, but also on using AI differently depending on the writing stages: ideation, structure, writing, editing etc.
Listening: Automated AI surveillance and a “political assassination”
This is an interesting Ezra Klein Show episode about the legal battle between the Pentagon and Anthropic. It also covers the dangers of automating state surveillance, the tension between private AI companies’ alignment decisions and state sovereignty and the supply chain risk assignment as a ‘political assassination’.
Reading: UK unemployment system is not ready for AI job displacement
Great but sobering FT article (£) by Sarah O’Connor on how the UK’s unemployment system is not ready for a potential AI job disruption.
https://www.ft.com/content/771a7577-0002-4300-9226-eaafa45339e4?shareType=nongift
Listening: AGI timeline
This unusually short (only 25 mins) 80,000 Hours podcast episode explains the shift of AGI timelines in 2025 due to the cost of inference and the fact that the reasoning approach hasn’t generalised as well as predicted.
https://80000hours.org/podcast/episodes/agi-timelines-in-2025/
Google Docs.
No, nobody calls him that. Well, except for me here.
Yes, it can be advantageous to use a sectoral/risk-focused approach to regulation rather than trying to draft all-encompassing omnibus laws like the EU AI Act.




