Three Conferences, Too Many Thoughts
Themes and resources from three privacy and AI governance conferences plus the usual recommendations
Can you tell? - I am not doing terribly well with my commitment to write shorter and more frequent posts. While I am hectically scrambling for excuses, please remember that this Substack is called *Incrementally* Better. Yes, the “incrementally” also applies to me. But I have some excuses for not finding the time to write my Substack posts as you can gather from the main bit below.
What I Learned from a Month of Privacy Conferences
It is possibly a bit crazy to attend three privacy conferences in a single month: The IAPP AIGG Dublin, the FPF DC Privacy Forum and Annual Advisory Board Meeting and IAPP Navigate1. It’s certainly a first for me. I would normally attend that many conferences in half a year at most. But this year, the stars aligned2.
Each conference was great on its own terms. And together, they have given me an excellent sense of the latest regulatory developments (including the latest thinking of legislators and regulators), how privacy and AI governance teams handle those developments and - last but not least - how privacy and AI governance teams are leveraging AI themselves to make their programmes more efficient and effective.
As with my post on the IAPP GPS, I am sharing some nuggets with you, my dedicated – small, but mighty - readership. It’s hitting your inboxes in my favourite form of prose: A bulleted list.
Key themes
AI twins: During my favourite session at Navigate, Suraj Srinivasan explored the rise of ‘AI twins’ (LLM versions of employees to help with succession, capacity … and I guess attending all the meetings on your behalf?), and the resulting challenges such as consent, IP ownership, accountability for errors and workplace surveillance (for a picture of the key slide see my Navigate Bluesky thread).
HR AI risk: Multiple sessions highlighted the issues related to the use of AI in HR as an emerging and significant enterprise risk (particularly on the question of how to ensure human oversight for AI in recruitment as the number of applications per open position has skyrocketed).
AI sovereignty: Countries across the globe - including traditional US allies - are developing industrial policies to reduce their dependency on US and Chinese companies (hello, geopolitics) by diversifying the ‘AI stack’ layers3 - not least the EU with its Tech Sovereignty Package (more thoughts on that - ahem - ambitious package soon).
US chatbot regulation: The US has not regulated AI, right? Not quite. It’s correct on the federal level4, but US states (e.g., Colorado AI Act, California SB 243) have started regulating various AI risks with increasing focus on AI companions / chatbot risks. Love the US state privacy laws patchwork? Good news for you: We’ll have the same for AI in the absence of federal legislation.5
Oversight of AI agents: The human oversight principle is a core principle of many influential AI governance frameworks and laws (e.g., Asilomar principles, OECD AI principles, EU AI Act). But implementing this principle for AI agents that can operate independently for long periods with increasing accuracy and intelligence (and no end in sight regarding enhanced capabilities) is a challenge. Ongoing human review and approval is simply not a scalable approach with agents performing hundreds or thousands of actions in short time frames. The approach will likely have to shift from “humans in the loop” to “humans on the loop” where humans monitor performance and retain the ability to intervene (rather than being involved in every decision). From “helicopter parenting” to “laissez-faire parenting”?6 Various sessions pointed out that the EU AI Act does not easily accommodate this in practice and pointed to the Singapore Model AI Governance Framework for Agentic AI as a helpful framework (see also resources section below).
Using AI for privacy / AI governance: Leading privacy and AI teams have started using AI (agents) for increasingly sophisticated tasks. A few companies demonstrated their (mightily impressive) AI agents during the FPF Annual Advisory Board Meeting. The use cases included automating DPIAs/AIIAs, personal assistants that summarise regulatory developments and keep track of your decisions and agents reviewing user interface choices.
Not enough talked about (yet)
An interesting exercise after a conference is to reflect on the topics that *should* have been widely discussed but weren’t (enough). Here’s my subjective selection:
EU AI Act high-risk compliance in practice: What does EU AI Act high-risk compliance look like in detail? How are companies setting up quality management systems, risk management systems, conformity assessments, etc. on the ground? How resource-intensive are these processes and what are the roles of compliance, privacy / AI governance teams and product / IT teams? Lots of open questions, not many answers during the conference sessions. Not entirely surprising, though, given that many of the detailed CEN / CENELEC standards that are intended to provide detailed guidance are still being worked on.
AI governance as a protocol issue: Existing laws (e.g., EU AI Act, Colorado AI Act) define compliance and requirements mainly on the AI system-level. But with agentic AI, it’s not only a question of managing the risks of AI systems, but also managing the risks resulting from the interactions with other AI agents, end users and other tools. Protocols defining how these AI agents interact with one another (A2A), with end users, payment services and tools are therefore critical … but not talked about enough. We need to build privacy, security and AI governance into these protocols. For instance, under most current MCP7 implementations, agents use the same IDs / credentials as their users, which is not sustainable.8
New approaches for AI regulation: We are still at the early stages of AI regulation with no clear global baseline and a tension between regulation and innovation. I am pretty convinced that the EU AI Act approach is not effective and flexible enough. “Radical optionality” by the Institute for Law & AI is an interesting proposal that I like. But it is mainly focused on frontier AI. I need to think and write more about this, but to achieve effective, technology-neutral and flexible regulation that covers AI risks across the full spectrum9, we probably need to go further and opt for “radical modularity”, i.e. building regulation modularly. For instance, a foundational module could define the (technology-neutral and high-level) desired outcomes, principles, concepts / definitions and regulatory approach with additional modules managing specific AI risks (e.g. frontier AI risks, companion/chatbot risks, automated decision-making). More to come!10
Helpful resources shared during the conferences
Singapore Model AI Governance Framework for Agentic AI (advertised by many sessions as the best framework to handle agentic AI)
CDT’s AI governance lab which aims to help develop the necessary ecosystem (e.g. evaluation, agent protocols)
CNAS’ Sovereign AI index
Uplifting content
Depressed by the state of the world and the flood of negative news? Here’s content to brighten your day.
Uplifting: Heart-warming story about a baby found in a NYC subway station: https://www.theguardian.com/lifeandstyle/2026/may/22/experience-found-baby-subway-now-26-year-old-son
Sound bite: Duckwrth and CLAY ‘Beg’:
Eye candy: ‘Morning in the forest’ by Kilian Schönberger:
My posts elsewhere
Best of recent posts on LinkedIn and Bluesky:
Red-/blue-teaming laws with AI to find loopholes (Bluesky)
Thread on the EU tech sovereignty package / CADA (Bluesky)
Thoughts on the impact of the SCOTUS ‘Slaughter’ decision on the EU-U.S. DPF (Bluesky / LinkedIn)
IAPP Navigate thread (Bluesky)
How AI helps me at work (Bluesky)
Claude for Legal creates need for SOPs and playbooks (Bluesky / LinkedIn)
Thread on the coming AI backlash (Bluesky)
Recommended
Reading: What plane crash reports can teach us
Fascinating Ashley Goodall post on a plane crash report... but really on the importance of treating human behaviour not as an explanation for a problem, but as a clue to its deeper causes.
Reading: The importance of the “AI loop”
Excellent Stuart Winter-Tear (‘Unhyped AI’) post on Microsoft’s pitch to be the foundation for the AI loop and how having the right “AI loop” is becoming more important than having the latest frontier AI model.
Reading: Study on lack of protection for chatbot data
Important study by Theodore Christakis on how the lack of an AI privilege leaves potentially sensitive data shared with chatbots unprotected.
https://ai-regulation.com/you-trust-your-chatbot-with-everything-should-you-part-2/
Listening: Sentience in plants and AI consciousness
A fascinating episode of Chris Hayes’ the AI Endgame podcast miniseries. This episode features Michael Pollen on sentience in plants, the brain as a hallucinating prediction-machine and on AI consciousness.
… even though on AI consciousness I am more on David Chalmers side:
Reading: Andor and authoritarianism
Great David Solove post on what one of the greatest TV shows can teach us about authoritarianism.
Listening: The economic impact of AI (and our lack of a plan)
Interesting if sobering London Futurists episode with Adrian Brown from the Windfall Trust on the economic impact of AI (job displacement, wealth concentration etc.). The key message is that politicians are not focused enough on this critical topic.
P.S. The Windfall Trust policy atlas is a great resource on policy solutions (and more broadly regarding AI risks): https://windfalltrust.org/policy-atlas.
Usual reminder that the IAPP does not put the conference presentations behind the paywall. Go to the event agenda and you’ll find them all there ready for your reading pleasure.
If you are interested in the detailed explanation why I decided to cram three conferences in one month: For AIGG, I was asked to be a speaker on a panel (thank you, Isabelle Roccia!). The FPF DC Privacy Forum and Annual Advisory Board Meeting is a staple that I try to attend every year. And as an IAPP board member I am lucky to get to go to IAPP Navigate for free. Get your tiny violins out, but as amazing as it is, it’s also pretty tough if you have to manage your usual workload, try to be an attentive husband and dad when you are at home and - particularly - when you stupidly schedule a wider family get-together in Paris between two of the conferences. Yes, I only have myself to blame. P.S. If you have read this footnote, you now also understand that the struggle for shorter and more frequent posts is real … too many thoughts trying to squeeze through the exit.
The AI stack layers from a sovereignty perspective: Energy layer, silicon layer (chips and hardware), data centre layer, model layer.
I am not counting the frontier AI-related Executive Order with the voluntary review scheme as regulation.
Using the US risk-based / sectoral approach to regulation may turn out to be the more effective and flexible approach than the EU ‘omnibus’ approach which tries to squeeze - with rather mixed success - everything into the EU AI Act.
Yes, I know that AI oversight and overseeing employees is not the same as parenting and that this risk anthropomorphising AI … but I am pretty sure that most of my readers will understand that this is included for comedic / hyperbolic effect. Just imagine the 😜 emoji at the end of the sentence if you are struggling.
MCP stands for Model Context Protocol, the key protocol to connect LLMs with other tools.
For some interesting suggestions on more secure AI agents, see Google’s paper. Also interesting is Estonia’s approach to issue state-recognised digital identities to AI agents. Finally, on the US side, NIST has published a draft concept paper “Accelerating the Adoption of Software and AI Agent Identity and Authorization”.
I would like to point, as usual, to the excellent MIT Domain Taxonomy of AI risks.
More on this in one of my upcoming posts, currently in early draft stage.





