PrivSec AI: Privacy, Copyright, IP & Governance | 11 November 2026, ExCeL London
PrivSec AI Governance Wed 11 Nov 2026 · ExCeL London Book your place →

Day two of #RISK Expo Europe · ExCeL London

Privacy, copyright and AI governance. One room, one day.

Most conferences take one thread. PrivSec AI takes all three — data protection law, intellectual property risk and emerging AI regulation — and works through what they mean for the people who carry the accountability.

£199 per ticket until 30 September, then £299. Every booking is reviewed against the delegate criteria.

Keynote speakers

Plus five practitioner-led panels. See the agenda →

Counting down to ExCeL London Early rate £199 until 30 September · £299 after
Days
Hrs
Mins
Secs
11 Nov 2026 ExCeL, London
2 keynotes Holmes & Schrems
5 panels Practitioner-led
£199 Until 30 Sept, then £299

Why this year

2026 brought the most consequential wave of AI regulation in a decade.

Three separate fights are now landing on the same desks at the same time. Very few teams have a clear view of all three.

Thread 01 — Regulation

The UK's AI and ADM Code of Practice, and the Data (Use and Access) Act

New obligations are arriving in a country that still has no cross-sector AI statute, while EU enforcement moves in the opposite direction. Knowing which rules bind you, and when, is now a job in itself.

Thread 02 — Copyright & IP

Unresolved copyright battles over training data

Litigation over what went into the models has not settled, and the exposure runs downstream to the organisations deploying them. Procurement questions that were theoretical in 2024 are contractual in 2026.

Thread 03 — Identity

A fast-emerging legal fight over deepfakes and digital replicas

Personality rights, biometric scraping and synthetic likeness are converging into a live legal risk for brands, executives and employees alike, ahead of any settled framework.

Leave with a clear view of your compliance exposure across privacy, copyright and governance at once — plus a room full of peers under exactly the same pressure.

Book your place →

The agenda

Practitioner-led sessions. Not vendor pitches.

Direct, actionable guidance on where the law stands today and what is coming next. Filter by the part of the problem you own.

Keynote Lord Chris Holmes
Regulation With Teeth: Why the UK Needs Binding Rules on AI Transparency, Auditing and Data Rights

The UK remains one of the only major economies without cross-sector AI legislation, relying on a principles-based approach that places no binding obligation on regulators to act. Lord Chris Holmes sets out why he believes that gap needs closing, and what binding rules on transparency, independent auditing and data rights would look like under the AI Authority his Bill proposes to create.

Keynote Max Schrems
Hallucinations, Biometrics and the Digital Omnibus: The New Front Line of GDPR Enforcement

Max Schrems and noyb are currently pursuing GDPR complaints against ChatGPT over fabricated personal data and against Clearview AI over biometric scraping, the latter now escalating toward personal criminal liability for executives. Schrems examines what these cases reveal about AI's collision with data protection law, and why he believes the EU's proposed "simplification" of GDPR would strip away protection at the exact moment AI makes it more necessary.

Panel featuring Michael Charles Borrelli
Agentic AI and the Death of the Static Data Inventory: Governing Systems That Don't Sit Still

Traditional data protection assumes a fixed map of what personal data exists and where. Agentic AI breaks that assumption, moving data across tools and workflows with limited human oversight and creating "shadow agents" that governance teams don't know exist. This panel examines what the UK ICO's early guidance means for DPOs in practice, and how privacy teams are rebuilding data governance for systems that never stay still.

Panel Threat landscape
AI vs AI: Cyber Threats, Defences and the Governance Gap Between Them

The UK's National Cyber Security Centre expects AI to make cyber offence more effective within the next two years, and the same underlying tools are just as capable of powering next-generation defence. This panel examines what the AI-driven threat landscape looks like over the next three years, from automated exploit discovery to AI-generated social engineering, and why strong AI governance, not just stronger security tooling, is fast becoming the difference between organisations that keep pace and those left exposed.

Panel Model security
Securing the Model: Protecting Training Data, Outputs and Infrastructure From a New Attack Surface

AI systems introduce a security problem existing controls weren't built for: training data that can be poisoned, outputs that can leak information they were never meant to reveal, and models that can be manipulated through the inputs they're designed to accept. This panel examines what securing the model itself requires, distinct from securing the infrastructure around it.

Panel Third-party risk
Shadow AI and the Extended Vendor Chain: Auditing Third-Party AI Tools and Sub-Processors

A growing share of AI vendors are not disclosing the AI sub-processors sitting behind their own products, and employees are adopting AI browser extensions, coding assistants and embedded SaaS features faster than procurement can review them. This panel examines what genuine third-party AI risk management looks like when the vendor relationship itself is only the first link in a much longer, largely invisible data-processing chain.

Panel Cryptographic migration
Harvest Now, Decrypt Later: Preparing Today's Data for Tomorrow's Quantum Threat

Security agencies including the NSA, CISA and the UK's NCSC have confirmed that adversaries are already archiving encrypted data today, betting on tomorrow's quantum computers to decrypt it. This panel examines what that means for personal and sensitive data with a long shelf life, and what privacy and security leaders need in their cryptographic migration plan before the harvesting window closes.

Further sessions, speakers and the full running order will be published here as the programme is confirmed. Registered delegates are notified first.

On stage, confirmed so far

Lord Chris Holmes

Lord Chris Holmes

Member of the House of Lords

Author of the Artificial Intelligence (Regulation) Bill, which proposes a UK AI Authority with binding duties on transparency, auditing and data rights.

Max Schrems

Max Schrems

Founder, noyb

The litigator behind Schrems I and II, now pursuing GDPR complaints against OpenAI over fabricated personal data and against Clearview AI over biometric scraping.

Michael Charles Borrelli

AI governance practitioner

Joining the panel on agentic AI, shadow agents and what the ICO's early guidance means for data protection teams in practice.

Who's in the room

Built for the people personally accountable for getting AI governance right.

Chief Privacy Officers, Data Protection Officers, Heads of Data Governance, General Counsel and in-house AI/IP leads, alongside Chief Risk Officers, GRC directors and compliance heads from financial services, retail, technology and the public sector — plus the legal, consultancy and technology providers who advise them.

  • Chief Privacy Officer
  • Data Protection Officer
  • Chief AI Officer
  • General Counsel
  • Head of Data Governance
  • CISO
  • Privacy Counsel
  • GRC Director
  • Head of AI
  • AI Ethics Officer
  • Head of Security Risk
  • Chief Risk Officer

Is this room for you?

Tickets are £199 until 30 September, and every booking is reviewed. Pick the line closest to your role and we'll tell you where you stand before you spend anything.

Previous attending organisations

Peers from the organisations facing the same questions.

  • PepsiCo
  • American Express
  • Meta
  • HSBC
  • Wells Fargo
  • Salesforce
  • Amazon
  • Mastercard
  • Bloomberg
  • EY
  • Google
  • Apple
  • Visa
  • Verizon
  • Disney
  • 3M
  • IBM
  • BNY Mellon
  • JPMorgan Chase
  • Citi
  • Dell Technologies
  • GE HealthCare
  • S&P
  • Pfizer
  • Bank of America
  • KPMG
  • Intel
  • PwC
  • PayPal
  • Boeing

For solution providers

Sponsor, speak or exhibit

Delegates come to benchmark vendors as well as regulation. Headline, gold and silver packages include speaking slots, hosted lunch and table-top presence — and guarantee your team access to the room. PrivSec AI concentrates the #RISK audience into the privacy, IP and AI governance buying group specifically.

Nick James

#RISK Director and Founder

Ask for the exhibitor brochure, current package availability and the speaking slots still open on the 11 November programme.

nick@grcworldforums.com →

Wednesday 11 November 2026 · ExCeL London

A year's worth of regulatory intelligence in a single day.

£199 per ticket until 30 September, then £299. Booking takes two minutes, and we review every booking against the delegate criteria before confirming by email.

Book your place →
PrivSec AI Governance is presented by #RISK Expo Europe, 10–11 November 2026, ExCeL London. Part of GRC World Forums · Powered by Emerald. #RISK Expo Europe info@grcworldforums.com

GRCWF Ticket Tailor Headers

#RISK Expo Europe, 10-11 November 2026, Excel London - Europe’s leading Risk, GRC, Security & RegTech Expo.