Pseudonymize your documents, and include the values in your AI deliverablesPseudonymize your documents consistently, and restore (de-pseudonymize) the original values in your AI assistants' outputs

Marvin Systems CEO

The 2026 International Association of Privacy Professionals (IAPP) Global Summit, held in Washington, D.C., from March 30 to April 2, brought together more than 15,000 data protection and compliance professionals. The central message, echoed by all the regulators in attendance, was that compliance on paper is no longer enough.
While policies, notices, and internal frameworks remain essential, audits now focus on whether compliance programs actually work in practice.
A recurring theme: the inadequacy of compliance models relying on periodic assessments, spot checks, or written policies. Speakers emphasized that AI governance requires continuous monitoring, adaptive safeguards, and real-time oversight. Compliance is no longer a state that is achieved and then maintained, it is a living process that evolves with usage, technology, and risks.
Regulatory authorities have emphasized that their enforcement capabilities are rapidly expanding. Smaller countries are drawing on the resources of larger ones. Cross-border information sharing has become routine.
What this means in practice for companies operating across multiple jurisdictions: an investigation opened in one country can now trigger parallel investigations elsewhere, simultaneously amplifying legal, operational, and reputational risks.
One of the most prominent themes of the summit was the growing expectations placed on senior management and the board of directors.
In a recent action, the California Privacy Protection Agency required board-level oversight of privacy risk assessments, as well as the identification of the specific board members responsible. Regulators have been clear: their decision to name executives or board members in their complaints depends on the context, their knowledge of the facts, and their level of responsibility. But one thing is certain, senior executives can no longer claim immunity from scrutiny.
Privacy, cybersecurity, and AI governance are no longer technical matters to be delegated. They are business risks that require commitment at the highest level.
This is the most practical aspect for operational teams, and often the most underestimated.
Regulators have emphasized that transparency, data minimization, purpose limitation, and storage limitation now constitute the benchmark criteria for regulatory enforcement. These are no longer ethical aspirations. They are red lines that must not be crossed.
Companies must collect only the minimum amount of personal information strictly necessary and particular attention is now being paid to the risks of re-identification when data sets are combined across platforms.
This was undoubtedly the session that sparked the most debate. And for good reason.
An AI agent is not a chatbot. A chatbot answers your questions. An AI agent acts on your behalf: it browses the web, places orders, interacts with other systems, and accesses your accounts and personal data autonomously to achieve a goal. This semantic shift masks a significant legal shift.
The rise of these autonomous agents has rendered traditional consent models insufficient to protect consumers. The famous “I accept the terms and conditions” was designed for a world where the user takes action. It was not designed for a world where an automated system acts on their behalf, with access to everything.
Questions of liability remain without a clear legal answer: who is liable when an AI agent causes harm? The user who activated it? The company that developed it? The platform that hosts it? The summit raised the question. There is no answer yet. New approaches are still in the proposal stage. What is certain is that the current legal framework was simply not designed for this kind of world.
Given the increased risk of inspections, organizations would be wise to keep several practical points in mind.
Maintaining appropriate documentation is essential. The steps taken to implement a defensible compliance program, including evidence of board oversight, form the foundation for a prompt and credible response to requests from regulators. A delayed response can be interpreted as a sign of non-compliance, regardless of intent.
Early identification of regulatory concerns is equally important. Understanding the authorities’ objectives and anticipating sensitive areas before they are raised, since enforcement priorities may shift during an investigation, is crucial, and it is best not to be caught off guard.
Having a clear vision of internal and external communication is essential. Regulators are not always familiar with the operational nuances of compliance. It is up to the company to provide context, clearly and precisely, without assuming that the regulator already has the necessary information to understand the situation. External communication protocols, including those with the press, must be defined in advance.
Finally, it is clearly essential to take the multi-jurisdictional aspect into account. Practices in force in one jurisdiction can trigger investigations in another. Keeping documentation that explains any differences in practices between jurisdictions means addressing the issue before it is even raised.
For further information : https://www.alston.com/en/insights/publications/2026/04/takeaways-from-the-2026-iapp-global-summit
https://vucense.com/privacy-sovereignty/law-policy/iapp-global-summit-2026-key-takeaways/
https://natlawreview.com/article/key-takeaways-2026-iapp-global-privacy-summit