IAPP Europe Congress 2026
Privacy | AI governance | Cybersecurity law
BRUSSELS
16-19 November
Contract to Code: Navigating Vendor Compliance in the API Age
Wednesday, 18 Nov.
16:45 - 17:45 CET
Intermediate level
The rise of API integrations and recent introduction of autonomous AI agents has transformed business operations, yet it introduces profound risks to the third-party supply chain. As external systems move from passive data-sharing to active decision-making, traditional oversight is no longer enough. This panel explores the critical transition from contract to code, focusing on how companies can proactively enforce vendor compliance within agentic workflows. We will dive into the technical reality of AI governance, examining how to ensure that external models and autonomous agents adhere to ethical, legal and regulatory standards. By moving beyond "paper-based" security, we demonstrate how to transform legal intent into verifiable technical requirements, ensuring your vendor ecosystem remains resilient in an era of automated interactions.
What you will learn:
- Strategies to move from static API oversight to dynamic accountability for autonomous AI agents and methods for turning complex legal obligations into automated, technical guardrails.
- Practical frameworks for embedding data protection directly into the code of vendor integrations.
- Security Engineering techniques to defend against next-generation attacks, such as prompt injection and unapproved agentic actions.
Featured in this session

Jiri Balek
AIGP, CIPP/E, CIPM, FIP
Data Privacy and Ethics Manager
Celonis

Victoria Hordern
AIGP, CIPP/E, CIPT
Partner
Digiphile

Ben Kamber
Senior Staff Privacy Engineer and Manager

Michael Will
President
Bavarian State Office for Data Protection Supervision