Loeb recently hosted another AI Summit in Chicago on July 14, 2026, where I had the pleasure of leading roundtable discussions focused on privacy questions. Participants from different backgrounds and industries engaged in a robust conversation about managing privacy compliance at the intersection of internal and external AI applications. The discussion raised several practical concerns faced by organizations today:
- Companies continue to navigate the complex task of defining the roles of each party to a transaction, particularly as these roles evolve in scenarios where data may be used to train underlying AI models. Increasingly, organizations can face challenges in maintaining a position that company data cannot be used for any model training—with implications for contracts, external disclosures and compliance measures.
- Many companies continue to adopt a risk-based approach to AI use cases involving personal data and privacy obligations. But simply accepting risk is not necessarily a comprehensive solution. A risk-based approach still requires a thorough understanding of the risks being assumed, including potential financial liabilities, regulatory inquiries and possible class action claims. To truly assess risk, organizations must fully understand their AI use cases and associated data flows. Achieving this level of insight demands transparency from all parties involved.
- Accurate and comprehensive contract terms, compliance programs and disclosures are critical right now across all industries and sectors. Even companies that may not have historically faced significant regulatory scrutiny have to stay vigilant. Regulatory oversight extends to everyone these days—and in the privacy space, regulators are particularly attentive and active.
The roundtable sessions underscored that there is no one-size-fits-all solution for managing risks and compliance obligations related to privacy and AI. As AI use cases continue to expand and evolve, companies are prioritizing careful vendor and contract management, together with documentation of risks and mitigation strategies.