The AI you didn't build: From black box to defensible risk


Contributors:
Darren Abernethy
AIGP, CIPP/A, CIPP/C, CIPP/E, CIPP/G, CIPP/US, CIPM, CIPT, FIP, PLS
Shareholder
Greenberg Traurig, LLP
Joanne Furtsch
CIPP/C, CIPP/US, CIPT, FIP
VP, Privacy Knowledge
TrustArc
Hilary Wandall
AIGP, CIPP/E, CIPP/US, CIPM, FIP
Chief Ethics and Compliance Officer
Dun & Bradstreet
Brought to you by TrustArc
Broadcast date: 24 Sept. 2026
Time: 08:00–09:00 PDT, 11:00–12:00 EDT, 17:00–18:00 CEST
Most AI risk today isn't homegrown, it's embedded in the third-party software you already use. When privacy and risk teams can't inspect the model, "high risk" isn't a defensible answer.
A practical framework is needed for discovering AI hidden in vendor products, mapping it to data and business processes, and scoring risk in a way that holds up to leadership, auditors, or regulators. The outcome: separating inherent from residual risk, translating findings into procurement and contract terms, and building the evidence trail to answer, "How did you arrive at that number?"
Key takeaways:
- How to identify AI embedded in third-party products, even when vendor documentation is incomplete.
- A repeatable structure for scoring third-party AI risk using data sensitivity, purpose, autonomy, and consequence.
- How to distinguish inherent risk from residual risk, without treating vendor assurances as mitigation by default.
- How to translate a risk assessment into contract terms, monitoring obligations, and escalation triggers.
If you registered for this sponsored web conference and subsequent related follow-up emails, you submit your registration information to the IAPP and the co-host and sponsor for that particular web conference, which includes attendee names, titles, organizations, countries, state and email addresses.
This web conference is co-hosted and sponsored by TrustArc and free of charge to you. The IAPP and the sponsor will use your registration information each in compliance with its own privacy notices.
If you do not wish to submit your information to the web conference sponsor(s), you should not sign up for this free, live web conference. You can access the recording of the web conference without providing information to sponsors.
The co-sponsor's privacy notice is available here: TrustArc Privacy Notice
You may contact the sponsor directly in order to express your preferences with regard to direct marketing communication at privacy@trustarc.com
You may also contact the IAPP’s data privacy officer at privacy@iapp.org with any questions about the IAPP's processing of personal information or the IAPP's privacy notice.
Eligible CPEs: AIGP, CIPP/A, CIPP/C, CIPP/CN, CIPP/E, CIPP/US, CIPM and CIPT.
1.0 CPE credits