IAPP Privacy. Security. Risk. + AI Governance Global 2026

SEATTLE

6-9 October

Back to conference agenda

You are Only as Safe as Your Suppliers: Governing Third-Party AI and Cyber Risk

Thursday, 8 Oct.

13:00 - 14:00 EDT

Intermediate level

BREAKOUT SESSIONAI GOVERNANCECYBERSECURITY LAWAI AND MACHINE LEARNINGDATA SECURITYLAW AND REGULATIONRISK MANAGEMENTSTRATEGY AND GOVERNANCEADVERTISING AND MARKETINGTECHNOLOGYLEGAL

As companies and institutions rapidly deploy artificial intelligence, regulators, attackers and plaintiffs are increasingly focusing on the vendors behind the models. From foundation model providers and AI APIs to data labeling firms and embedded tools, today’s AI supply chains introduce privacy, security and governance risks that traditional third-party programs were not designed to address. This session explores how AI governance, supplier cybersecurity and privacy risk are converging and what companies must do now to manage this expanded risk surface. Drawing on real-world scenarios, the speakers will walk through three common supplier-driven AI failures and examine how governance, contracting and cross-functional oversight could have mitigated the harm.

What you will learn:

  • How AI supply chains differ from traditional SaaS vendor relationships and why that matters for risk ownership.
  • Practical approaches to integrating AI risk into existing vendor cyber and privacy programs.
  • What legal, privacy and security teams should focus on in diligence, contracting and ongoing oversight.

Moderator and speakers

headshot of Abigail Devine

Abigail Devine

CIPP/US, CIPM

Director, Senior Counsel, AI and Cybersecurity

IBM

generic profile silhouette

Audrey Paquet

Counsel

Paul Weiss