IAPP Canada Symposium 2026: Privacy | AI governance | Cybersecurity law
TORONTO
4-7 May
AI Vendor Risk Management: Navigating Uncharted Regulatory Territory
Monday, 4 May
14:30 - 15:30 EDT
Intermediate level
Privacy and artificial intelligence governance professionals face unprecedented risk management challenges in areas where legislative frameworks remain underdeveloped and evolving. This panel brings together practitioners across industries who have developed practical approaches to AI vendor oversight in a dynamic risk landscape. Panelists will cover essential AI contract provisions, risk assessment methodologies and mitigation strategies for companies of all sizes. They will explore real-world scenarios including algorithmic transparency gaps, data processing ambiguities in AI training and inference, cross-border AI data flows, and liability allocation in AI-driven decision making. Attendees will learn how to identify and mitigate AI-specific risks that traditional vendor management approaches often miss, including emerging concerns around AI model updates, training data provenance and unexpected algorithmic behaviours. This session provides actionable strategies for professionals building robust AI vendor risk programs in the absence of comprehensive regulatory guidance.
What you will learn:
• Unique vendor risks that emerge from AI systems, including algorithmic transparency issues, training data concerns and liability gaps not covered by traditional frameworks.
• Actionable methodologies for assessing AI vendors, including contract provisions, technical assessments and ongoing monitoring strategies tailored to AI-specific challenges.
• Real-world approaches for managing AI vendor relationships when regulatory requirements are unclear, including risk allocation.
Moderator and speakers

Nic Wall
CIPP/C
Senior Associate
Torys

Shreya Gupta
Director, Legal Counsel - Technology, AI and Privacy
Loblaw Companies Limited

Natasha Anzick
Director, Legal; Chief Privacy Officer
Wealthsimple