Camilo Artiga-Purcell is General Counsel at Kiteworks, where he leads the company's global legal operations across commercial contracts, data privacy and cybersecurity compliance, M&A, litigation, and regulatory strategy. He has advised on seven acquisitions and brings over a decade of experience litigating complex commercial disputes from inception through trial and appeal. A recognized voice on AI governance and data security risk, Camilo regularly publishes on the legal challenges organizations face as they adopt emerging technologies. In this episode… AI agents are becoming more common in everyday business operations, gathering data and carrying out tasks for organizations. Traditional governance policies typically place guardrails around the AI tools human employees can use, what data they can access, and how that information can be used for business purposes. Companies need to extend those same controls to AI agents as they deploy them to reduce risk and meet compliance requirements under a growing patchwork of AI regulations and existing US and global privacy laws. So, what does it take to govern AI agents effectively? Before allowing AI agents to access and use sensitive data, organizations need to establish governance policies that define what they can or cannot do with it. Companies can then use tools like software wrappers to implement these policies on the front end while generating an audit trail on the back end that logs the agent's identity, the prompt, where it went, and what it did. Those records can plug into e-discovery systems to show whether the agent operated in compliance and provide a clear path to reconstruct its activity if it goes rogue. Alongside these controls, companies should also put security measures in place when they adopt AI models, rather than after problems arise. Employees also need training on how to use AI responsibly, with ongoing education that evolves with the technology. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Camilo Artiga-Purcell, General Counsel at Kiteworks, about governing AI agents as their use expands across organizations. Camilo explains why governance policies need to be applied directly to AI agents, with evidence-quality audit trails that document their activity. He discusses the importance of proactively embedding security controls into AI tools, highlighting the risks surrounding certain AI models. Camilo also shares his insights into rising AI costs and how organizations can determine which models are appropriate for different teams, and he offers practical tips for verifying AI outputs and pressure testing the results.
Cillian Kieran is the Founder and CEO of Ethyca, where he leads its product vision, engineering strategy, and growth. A serial entrepreneur and privacy engineer with two decades of experience, he launched Ethyca in 2018 to bring privacy-by-design infrastructure to developers. Earlier, he built the digital consultancy CKSK to 100-plus employees across four countries, serving clients like PepsiCo, Heineken, and PlayStation. He pairs deep technical grounding with a track record of scaling data-intensive businesses. In this episode… As companies expand their use of AI, they need guardrails around how the technology is used by employees and how those systems use enterprise data. Because models are trained on data, bias can be introduced through this information, while systems also continue to use this data to perform different tasks. This creates risk, and managing it requires evaluating what data a model or tool can access, its intent when it uses that data, and the economic, ethical, and regulatory implications of that intended use. So, what controls do companies need to manage AI and company data safely? Because AI wants to satisfy a user's request, it will keep trying to access data unless clear boundaries define what it can use. Using AI responsibly requires managing the data behind it alongside the technology itself. To do this effectively, companies need to know what data they have collected, where it came from, whether they have sufficient consent, and what legal basis applies to its use. Once companies understand those elements, they can give AI access to the information it needs for a specific purpose while limiting what falls outside that use, allowing them to leverage the value of their data while minimizing risk. Governance also needs to move from written policies into controls that can be enforced on a system in real time. And while AI can streamline processes like privacy risk assessments by gathering information and comparing it against policies, past assessments, and relevant requirements, human privacy experts still need to review the output for accuracy and challenge AI when it's wrong. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Cillian Kieran, Founder and CEO of Ethyca, about the importance of unifying AI governance and data governance. Cillian explains how bringing these two areas together helps companies stay in control of their data while allowing the technology to support the business. He discusses why companies are turning to open-source models for greater sovereignty and cautions that bringing a model in-house can still introduce risks. Cillian also addresses the tension between AI's need for data and privacy's data minimization principles, and he stresses why professionals need to think critically, question AI outputs, and avoid relying on AI as a crutch.
Elise Houlik is the Chief Privacy Officer at Intuit, where she leads the company's global privacy and responsible data innovation and protection strategy, ensuring data is used to safely power innovation across Intuit's ecosystem of financial technology products. Her team is deeply engaged with the business on all matters related to product development, data innovation and governance, and information security. In this episode… Legal and privacy professionals are using AI more often to save time and accomplish more in their day-to-day work. While these tools offer clear advantages, they also generate convincing outputs that are incomplete, generic, or factually wrong. Using AI responsibly requires professionals to apply human judgment and review the output closely to ensure it is accurate and supported before relying on it. As AI becomes more embedded in legal and privacy work, critical thinking skills remain just as important as knowing how to use the technology. Professionals get the most value from AI when they view it as a collaborator, rather than an authority. As privacy and legal teams use AI to kickstart analysis, pull facts together, and hunt for nuances across fragmented laws, they need to compare its answers against actual laws and reputable sources and challenge the tool when an output misses the mark instead of accepting it at face value. Being mindful about the personal information they put into public models is equally important. Professionals should also be comfortable using a variety of different tools and learning which ones fit different purposes. And as companies hire the next generation of tech-savvy professionals, they need to ensure they don't become overly reliant on AI and provide them with hands-on experience and exposure to real conversations that strengthen analytical skills. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Elise Houlik, Chief Privacy Officer at Intuit, about the importance of maintaining human intelligence in the age of AI. Elise shares how AI is changing the skills employers value in legal and privacy professionals and explains why human judgment, curiosity, and a willingness to challenge AI-generated answers are essential as these tools become a standard part of workflows. She highlights why junior professionals still need practical experience and peer-to-peer learning opportunities and shares her perspective on keeping human intelligence at the center of how professionals use AI. Elise also offers tips for building AI skills and experimenting with different tools.
For 30 years, Ben Isaacson has been a leading privacy professional and trusted counsel. During the "Internet 1.0" era, he was instrumental in launching the first self-regulatory guidelines for email marketing, addressable TV, and mobile marketing. Ben was one of the first privacy professionals to get certified as a CIPP/US with the IAPP in 2005. In this episode… Data broker laws are pulling a once-hidden industry into the light. For years, consumers generally had no idea which companies were compiling and selling their personal information, what those companies were doing with it, or how to opt out. States are responding with data broker laws that require brokers to register and disclose information about their businesses and data-selling practices. Seven states now have these laws on the books, with some providing consumers with a centralized mechanism to request deletion of their data or to opt out of its sale. So, how can companies that purchase or license data from brokers manage the downstream risks that come with using it? Companies buying or licensing data from data brokers need to know where that data comes from, how it's used, and what their third-party contracts permit. Legal and privacy teams should work with marketing and sales to identify which adtech vendors they buy or license data from and scrutinize their licensing relationships. They also need to map how purchased data flows through the business and ensure their privacy notices disclose its use. California's Delete Act makes this downstream visibility especially important because it requires data brokers to apply deletion requests before that data is used. Companies also need to consider whether their activities qualify them as data brokers, particularly because New Jersey's data broker law extends registration requirements to data collectors, potentially affecting businesses that fall outside the traditional data broker definition. Companies should seek a legal opinion to determine where they stand based on the nature of their business and its commercial terms. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Ben Isaacson, Principal at In-House Privacy, about the rise of data broker laws and what they mean for companies that buy, license, or sell personal information. Ben discusses the evolution of these laws and how data broker definitions and legal requirements vary across states. He highlights what companies can do to mitigate risk when using data purchased from brokers and provides tips on how companies can determine whether they are considered data brokers under these laws. Ben also shares his perspective on how California's Delete Act could influence future state and federal regulation.
Chris Tarbell is a leading privacy, cyber, and data strategy executive. He currently serves as the Chief Privacy Officer for VERSANT Media LLC. Prior to his current role, Chris was an associate general counsel for Fanatics and the Walt Disney Company, where he advised global businesses on compliance with domestic and international privacy, data security, and related consumer protection laws. Most recently, Chris served as Senior Counsel at the leading law firm of Kelley Drye and Warren, where he also supported clients in numerous regulatory investigations related to marketing and advertising. In this episode… Building strong privacy programs relies on human connection and a deep understanding of organizational dynamics and business goals. To be successful, privacy professionals must participate in the business rather than just focusing on meeting legal requirements. This approach enables leaders to advocate for the tools, budget, headcount, and other resources to move the program forward. Because privacy impacts many business functions, it is very much a people business, requiring strong relationships, cross-functional collaboration, and the ability to build trust with stakeholders and internal teams. So, what steps can companies take to achieve this? Putting this into practice starts with assembling a people-first privacy team and hiring individuals with the soft skills to step into unfamiliar situations, assess what is needed, and work across departments to move the program forward. By bringing curiosity and enjoyment to privacy work, they create an environment where other departments are more willing to involve privacy early and often. This approach is especially important in the media industry, where privacy pros may need to work with news colleagues to balance the right to be forgotten with First Amendment considerations or partner with intellectual property teams to protect personal information during piracy investigations. And while collaboration is essential, teams must also determine what can realistically be achieved with the time and resources available without allowing perfection to stall progress. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Chris Tarbell, Chief Privacy Officer at VERSANT Media, about building effective privacy programs through relationships and collaboration. Chris explains how his experience as both in-house and outside counsel shaped his ability to understand business objectives, advocate for resources, and communicate the value of privacy. He shares insights on the cross-disciplinary nature of privacy work in the media industry, lessons from building a program during a major corporate spinoff, and the importance of creating a people-first privacy team capable of handling unfamiliar business challenges. Chris also explains why bringing some fun to privacy work can make a program more effective.