Day two of #RISK Expo Europe · ExCeL London
Most conferences take one thread. PrivSec AI takes all three — data protection law, intellectual property risk and emerging AI regulation — and works through what they mean for the people who carry the accountability.
£199 per ticket until 30 September, then £299. Every booking is reviewed against the delegate criteria.
Keynote speakers
Lord Chris Holmes
Member of the House of Lords
Regulation With Teeth: Why the UK Needs Binding Rules on AI Transparency, Auditing and Data Rights
Author of the Artificial Intelligence (Regulation) Bill, setting out what a UK AI Authority would bind regulators to do.
Max Schrems
Founder, noyb
Hallucinations, Biometrics and the Digital Omnibus: The New Front Line of GDPR Enforcement
The litigator behind Schrems I and II, now pursuing noyb complaints against OpenAI and Clearview AI.
Plus five practitioner-led panels. See the agenda →
Why this year
Three separate fights are now landing on the same desks at the same time. Very few teams have a clear view of all three.
Thread 01 — Regulation
New obligations are arriving in a country that still has no cross-sector AI statute, while EU enforcement moves in the opposite direction. Knowing which rules bind you, and when, is now a job in itself.
Thread 02 — Copyright & IP
Litigation over what went into the models has not settled, and the exposure runs downstream to the organisations deploying them. Procurement questions that were theoretical in 2024 are contractual in 2026.
Thread 03 — Identity
Personality rights, biometric scraping and synthetic likeness are converging into a live legal risk for brands, executives and employees alike, ahead of any settled framework.
Leave with a clear view of your compliance exposure across privacy, copyright and governance at once — plus a room full of peers under exactly the same pressure.
Book your place →The agenda
Direct, actionable guidance on where the law stands today and what is coming next. Filter by the part of the problem you own.
The UK remains one of the only major economies without cross-sector AI legislation, relying on a principles-based approach that places no binding obligation on regulators to act. Lord Chris Holmes sets out why he believes that gap needs closing, and what binding rules on transparency, independent auditing and data rights would look like under the AI Authority his Bill proposes to create.
Max Schrems and noyb are currently pursuing GDPR complaints against ChatGPT over fabricated personal data and against Clearview AI over biometric scraping, the latter now escalating toward personal criminal liability for executives. Schrems examines what these cases reveal about AI's collision with data protection law, and why he believes the EU's proposed "simplification" of GDPR would strip away protection at the exact moment AI makes it more necessary.
Traditional data protection assumes a fixed map of what personal data exists and where. Agentic AI breaks that assumption, moving data across tools and workflows with limited human oversight and creating "shadow agents" that governance teams don't know exist. This panel examines what the UK ICO's early guidance means for DPOs in practice, and how privacy teams are rebuilding data governance for systems that never stay still.
The UK's National Cyber Security Centre expects AI to make cyber offence more effective within the next two years, and the same underlying tools are just as capable of powering next-generation defence. This panel examines what the AI-driven threat landscape looks like over the next three years, from automated exploit discovery to AI-generated social engineering, and why strong AI governance, not just stronger security tooling, is fast becoming the difference between organisations that keep pace and those left exposed.
AI systems introduce a security problem existing controls weren't built for: training data that can be poisoned, outputs that can leak information they were never meant to reveal, and models that can be manipulated through the inputs they're designed to accept. This panel examines what securing the model itself requires, distinct from securing the infrastructure around it.
A growing share of AI vendors are not disclosing the AI sub-processors sitting behind their own products, and employees are adopting AI browser extensions, coding assistants and embedded SaaS features faster than procurement can review them. This panel examines what genuine third-party AI risk management looks like when the vendor relationship itself is only the first link in a much longer, largely invisible data-processing chain.
Security agencies including the NSA, CISA and the UK's NCSC have confirmed that adversaries are already archiving encrypted data today, betting on tomorrow's quantum computers to decrypt it. This panel examines what that means for personal and sensitive data with a long shelf life, and what privacy and security leaders need in their cryptographic migration plan before the harvesting window closes.
No sessions under that filter yet. Try another theme.
Further sessions, speakers and the full running order will be published here as the programme is confirmed. Registered delegates are notified first.
On stage, confirmed so far
Member of the House of Lords
Author of the Artificial Intelligence (Regulation) Bill, which proposes a UK AI Authority with binding duties on transparency, auditing and data rights.
Founder, noyb
The litigator behind Schrems I and II, now pursuing GDPR complaints against OpenAI over fabricated personal data and against Clearview AI over biometric scraping.
AI governance practitioner
Joining the panel on agentic AI, shadow agents and what the ICO's early guidance means for data protection teams in practice.
Who's in the room
Chief Privacy Officers, Data Protection Officers, Heads of Data Governance, General Counsel and in-house AI/IP leads, alongside Chief Risk Officers, GRC directors and compliance heads from financial services, retail, technology and the public sector — plus the legal, consultancy and technology providers who advise them.
Tickets are £199 until 30 September, and every booking is reviewed. Pick the line closest to your role and we'll tell you where you stand before you spend anything.
Previous attending organisations
For solution providers
Delegates come to benchmark vendors as well as regulation. Headline, gold and silver packages include speaking slots, hosted lunch and table-top presence — and guarantee your team access to the room. PrivSec AI concentrates the #RISK audience into the privacy, IP and AI governance buying group specifically.
Nick James
#RISK Director and Founder
Ask for the exhibitor brochure, current package availability and the speaking slots still open on the 11 November programme.
nick@grcworldforums.com →Wednesday 11 November 2026 · ExCeL London
£199 per ticket until 30 September, then £299. Booking takes two minutes, and we review every booking against the delegate criteria before confirming by email.
Book your place →