On Thursday, 9 April, the TDL webinar series continued with an esteemed panel of experts and practitioners discussing the privacy challenges known and emerging over the coming year.
Although significant progress was made to protect personal data and user privacy during the last decade, the advent of machine learning (ML)-based artificial intelligence (AI) as well as the expansion and diversification of the computing environment has led to new challenges. These include:
· ensuring accountability, protecting personal data from inclusion in training and increase and transparency in AI systems
· creating and deploying technologies to ensure continued protection without significant performance and functionality trade-offs
· identifying the challenges for enforcement of privacy regulations and compliance with them
· the expanding use of biometrics affect privacy
· protecting data and users from both AI-focused and general cybersecurity attacks that affect privacy
Summary
This webinar focused on privacy challenges in 2026, particularly in the context of AI and agentic AI systems. The panellists discussed how AI is accelerating data use and creating new privacy challenges, such as re-identification risks, code generation by AI systems and the psychological trust people place in AI agents. They explored how AI is transforming regulatory landscapes with rapid rule evolution and examined the role of privacy-enhancing technologies (PETs) in addressing these challenges. The panellists shared concerns about current privacy threats and optimism related to emerging solutions, particularly in real-time compliance technologies; and the potential for AI to help document organisational knowledge. They concluded that while significant challenges remain, progress is being made in developing technologies to support privacy in the AI era.
Background
The objective was to elicit the views of each participant as to which are, in their opinion, the most important privacy and data protection challenges in 2026. Firstly, it was important to establish the status quo, i.e., whether anything has already changed substantially in 2026, whether the regulatory fragmentation, AI and approaches to AI governance in particular have been influences and whether there are indicators that the long awaited shift from checklist-based compliance to true enforcement is taking place. The geographic mix on the panel was also an opportunity to assess the philosophical and technical differences between the US and EU in their approaches to privacy and data protection.
Given the changing landscape for data and privacy, we looked to assess the new or newly important privacy threats and mitigations; for example, it is to be expected that new PETs are being deployed in 2026. Looking at current trends, it is to be expected to already see AI-driven threats including AI profiling and, looking to the future, to the importance of the emerging threats from quantum computers. While acknowledging and understanding the threat is important, realising what the most important currently deployable mitigations for these threats are is even more crucial as is being cognizant of the challenges deploying these mitigations.
Despite the efforts of regulators, there is perceived (and actual) fragmentation in regulatory and economic developments for which remedies are required. The regulatory approaches first developed in the late 1980s and 1990s have served us well until today but, given the significant changes in the overall landscape, it’s questionable whether they are still applicable and changes are needed. The panacea of a unified regulatory framework may be feasible but remains elusive, particularly with extra territorial approaches expanding or contracting in the near future. From an economic perspective, there are undoubted challenges to ensuring privacy and protecting data in the world of AI; for example, controlling compliance costs especially for SMEs and detecting breaches faster and more effectively.
In short, to address these issues impacting the short term future of the current regulatory, technical and economic approaches may well require compliance to be automated, automation to reduce some costs, as well as the use of AI to help detect privacy and data breaches earlier.
The global market for PETs is predicted to increase nearly five-fold over the next three years, and critically vendors need to understand which technologies need to be prioritised in order to maximise the impact of this dramatic growth, alongside other non-technical approaches.
These and many other questions were discussed during the webinar, so not surprisingly the panellists were to be asked to assess whether they were overall optimistic about progress in this area, given all the challenges.
Speakers
The panel consisted of the following notable experts:
· Virginia Bartlett, Practice Leader, Digital Trust, Colossus Technologies Group, LLC
· Janne Uusiliehto, Global Leader in AI Governance, Privacy, and Security Engineering
· Konrad Vesey, Cybersecurity and Privacy Champion; Adjunct Faculty, University of Maryland, Baltimore County
The session was moderated by TDL Strategic Advisor, Claire Vishik
Privacy in the Digital Age
The meeting opened by reflecting on the evolution of privacy in the digital age, highlighting how traditional privacy approaches are less effective in the current AI-driven data landscape. It was noted that, while regulatory frameworks have evolved to include AI, questions remain about sufficiency and enforcement. The discussion was set to focus on the current state of privacy, challenges and opportunities, particularly in the United States, but also comparing US and European perspectives. Predictably, AI was the focus during much of the discussion since it has often been the root cause of the greatest challenges and opportunities in all aspects of privacy in recent years,
AI Data Governance Challenges
The conversation continued with observations on how AI is accelerating data governance challenges, with 140 AI-related laws enacted in the US in the last two-three years, creating pressure to implement solutions quickly while governance frameworks lag behind. It was emphasised that the main privacy issue with AI is ensuring proper permissioned use of data in models, rather than re-identification concerns. Optimism was expressed about the current state of privacy technology, noting that automated real-time compliance solutions are now available to address the rapid pace of AI implementation, though some technical challenges remain around machine un-learning and PKI systems. This discussion concluded with a question about the balance between privacy benefits and potential violations in agentic AI technologies.
Data Integrity and AI Challenges
The importance of maintaining data integrity and trust throughout the chain from user to system was mentioned, emphasising the need for authorised and traceable agents. It was noted that the rapid evolution of generative AI creates challenges for traditional software engineering practices and privacy, particularly with AI-generated code. An increased adoption of formal verification techniques and model-based systems engineering as potential solutions were proposed to address these challenges while also recognising the limitations of these approaches.
AI Privacy Challenges Discussion
Privacy challenges posed by AI and large language models (LLMs) then came up for discussion with several issues highlighted, including the re-identification of users based on rich online profiles, lack of transparency in agentic AI systems and psychological dependency leading to excessive trust in AI. The need for better tools to verify and analyse agentic AI systems and LLM-based applications, similar to traditional software development practices, was mentioned. The discussion touched on the potential for AI to process vast amounts of user data, making re-identification more feasible than in the past, and the unknown implications of users sharing sensitive information with AI systems they trust.
AI in Software Development Implications
The implications of AI in software development were raised, with an emphasis on the importance of high-quality inputs and detailed requirements to avoid surprises and misinterpretations. The need for context in requirements and the importance of cleaning datasets from bias and personal identifiable information to mitigate risks were highlighted. The topic of legacy code and regulatory compliance was brought up, with questions about the potential positive influence of AI in the regulatory space.
AI Privacy Governance Challenges
The rapid acceleration of AI use in privacy and data governance over the past six months was noted, highlighting, as examples, real-time code scanning and integration with DSARs (data subject access requests). Important questions were raised about whether AI instances should be considered personal data, observing how organisations are beginning to treat AI systems as employees for authentication purposes. While acknowledging progress in AI governance, it was believed that significant adjustments are still needed as society better understands AI’s impact on human identity and data privacy.
Privacy Technologies and AI Future
The panellists shared their optimistic perspectives on privacy-enhancing technologies and AI’s future impact. Optimism was expressed about the widespread adoption of privacy technologies, highlighting progress in making privacy controls more engineering-focused rather than legally dominated. The importance of viewing AI outputs as human-centric (where appropriate) rather than just data was emphasised, noting that solution providers in the governance space are developing AI-based tools to address privacy challenges. The discussion concluded with a consensus that, while AI presents complex challenges, new privacy technologies and cultural shifts toward human-centred perspectives offer promising pathways forward.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.