Skip to main content

This article was adapted by "A Privacy-First AI Strategy: What It Looks Like and Why It Matters" episode on the DPM podcast.

Key Takeaways

Regulated Advantage: Regulated industries can reuse established governance, compliance, and incident-response practices to deploy AI responsibly.

Risk Split: Separating internal tools from product features helps organizations assess AI risks, controls, and accountability more accurately.

Privacy First: A privacy-first AI strategy protects personal data, proprietary information, and security while clarifying expected business value.

Shared Ownership: Organizations should define their beliefs about data ownership before setting ethical principles or designing AI policies.

Practical Accountability: Cross-functional teams, risk matrices, employee training, and vendor scrutiny help prevent shortcuts and support confident decisions.

Most people assume that heavily regulated industries — financial services, healthcare, energy, telecom — are destined to move slowly on AI, weighed down by red tape while less regulated sectors race ahead. According to Lauren Wallace, strategic advisor and former Chief Legal Officer at RadarFirst, that assumption gets it backwards.

Wallace, who has held legal and business development roles at Apple, Microsoft, and Nike, argues that regulated businesses actually have a head start when it comes to building compliant, responsible AI programs. This article breaks down her framework for a privacy-first AI strategy: what it looks like at the component level, how to build organizational buy-in, and where the biggest risks — and opportunities — actually sit.

Create a Free Account to Read More

Unlock this piece and join a community of forward-thinking leaders discovering tools, playbooks, and insights for thriving in the age of AI.

This field is for validation purposes and should be left unchanged.
Name*
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
By submitting you agree to receive occasional emails and acknowledge our Privacy Policy. You can unsubscribe at any time.

Why Regulated Industries May Already Have a Head Start

The core principles behind AI governance — transparency, accountability, bias monitoring — aren't new inventions. As Wallace explains, "the principles that underlie AI governance, like transparency, accountability, bias monitoring, prevention…they're already baked into existing regulatory frameworks." That includes GDPR, but also fair lending laws, equal opportunity laws, and a host of other civil rights and consumer protection frameworks.

The principles that underlie AI governance, like transparency, accountability, bias monitoring, prevention…they’re already baked into existing regulatory frameworks.

DPM Podcast – Lauren Wallace – Headshot-57440

Lauren Wallace

Chief Legal Officer

Banks, for example, have operated under "model management rules" for algorithmic decision-making for years — rules that, in Wallace's words, "easily translate into what we're looking at with all these AI tools." Organizations in these sectors typically already have compliance programs, dedicated governance resources, and enforcement tooling built around these frameworks.

That extends to incident response too. Wallace is direct on this point: "It doesn't matter where the incident arises, whether it arises from a misdirected fax or from an AI that you've enabled to use personal information. An incident is an incident." Security and privacy notification rules don't carve out an exception for AI, and, as she puts it, "you certainly can't just pin the blame on your AI."

So where's the real risk? Not with the enterprises you'd expect. "I actually think the bigger challenge is for the mid-size businesses," Wallace says. "They may be facing these regulatory headwinds for the first time when they implement AI into their workflows, and now they’re wondering where to start.”

Separate Your Use Cases Into Two Vectors

Wallace recommends splitting AI initiatives into two categories from the outset: 

  1. Internal uses of AI for productivity, replacing existing tools, or for functional enhancements.
  2. Product development AI use cases.

As she notes, "there's very different considerations for each of those" — treating AI strategy as one undifferentiated effort makes it harder to assess risk accurately.

Join the DPM community for access to exclusive content, practical templates, member-only events, and weekly leadership insights - it’s free to join.

This field is for validation purposes and should be left unchanged.
Name*
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
By submitting you agree to receive occasional emails and acknowledge our Privacy Policy. You can unsubscribe at any time.

Start With Privacy by Design — But Don't Stop at Personal Data

A privacy-first approach extends beyond protecting customer information. Wallace points to the need to protect "not just of personal information, but protection of the company's proprietary information," since "you get a whole bunch of new risks when you put company information into an LLM like ChatGPT."

We have a stunning new attack surface with AI. So, you have to make sure your security is dialed.

DPM Podcast – Lauren Wallace – Headshot-57440

Lauren Wallace

Chief Legal Officer

She also flags security posture directly: "We have a stunning new attack surface with AI. So, you have to make sure your security is dialed." But above all, she stresses internal alignment — "getting your internal conversation going to understand what you want to do with AI, what you think you can do with AI, and what the real ROI is that you hope to achieve."

Pick the High Watermark, Not the Lowest Common Denominator

Different privacy regulations share similar underlying values but implement them differently. Wallace's advice: "Try to find that high watermark. Try to find what's consistent across the regulatory environments that you're operating in, and treat everyone as if they were subject to that same high principled approach."

The alternative — trying to do the bare legal minimum everywhere — backfires. "That might seem like that's going to save you some regulatory exposure," she says, "but it's going to cost you so much more in implementation and in headspace when you're trying to do interesting things."

It's not just about regulatory exposure, either. "It's going to encourage an ethical approach to the work that you do," Wallace explains, "even where you don't have the regulatory obligations spelled out somewhere that you can point to chapter and verse." Legal risk can come from unexpected places — "a class action," "some entrepreneurial legal team," or "your competitors" — not just a regulator.

Decide Where Your Organization Stands on Data Ownership

Before drafting a list of AI ethics principles, Wallace argues organizations need to answer a more fundamental question first. She lays out three competing global philosophies on data ownership:

On the EU model: "Privacy is a fundamental human right, and the right of determination around the use of your personal information belongs to the data subject — the human."

On the historical U.S. model: "We've treated the value of that personal information as belonging to the company that collected it because they extract value from it, and so surely if they extracted the value, it must belong to them."

On a third model seen elsewhere: "The value of the personal information, in fact, the specific content of the personal information, is deemed to belong to the state, because the state is going to use it in the best interests of the data subject."

Her point is that companies need to consciously choose where they stand rather than backing into it: "Do we as an organization believe that we serve by extracting value from personal information? [Or do] we believe that we serve by helping our customers use personal information for the benefit of the data subject?" That decision, she says, should come before the list of ethical principles — "it's not with a list of principles like fairness, accountability, bias mitigation at the core" is where you have to start.

The Hidden Cost of Data Enrichment

Individual data points can look worthless in isolation, but Wallace warns that aggregation changes the equation: "The information that you provided to this one vendor in this one instance – may be standing alone, not having a ton of value. But aggregated and enriched and resold to third parties that can use it for other things, now the value is much higher."

She illustrates this with a real acquisition story: a major bank bought a startup specifically for a list of "4 million names of people who had bought their student loan services," paying around "$175 million" — reasoning that a hydrated, vetted list of prospects was worth roughly "a hundred dollars per person" compared to their typical customer acquisition cost of "150 or so dollars." The catch: "they found out those 4 million names were fake. They'd been synthetically generated using some kind of AI program," and the deal collapsed.

Her takeaway is a challenge to how casually people treat their own data: "This big bank thought you were worth at least a hundred bucks. So would you [the consumer] do something different with that data knowing its value?”

Build Accountability Into the Project Team, Not Just the Boardroom

"Tone at the top" matters, Wallace says, but "that only gets you so far where we're operating at the project level." Real accountability requires bringing a genuinely cross-functional group to the table for every AI initiative — "you have product at the table, engineering at the table, security at the table" — plus functions people often overlook:

Customer success: "Do they understand the functionality well enough that in the absence of the script they could at least have vocabulary to surface the question to someone else?"

Marketing: "Do you know whether they're in that allergic to AI category or at the other end, very eager to try new things category? How are you gonna tone and tune your messaging so that when you talk about new features?”

Legal: "You may have customers in your portfolio that prohibit the use of AI on the products they buy from you. That can be buried in the contract somewhere. It might say algorithmic decision making or using models. You might have a 10-year-old contract that prohibits this use."

The goal, Wallace says, is a team that holds itself accountable in the moment.

Separate Inadvertent Misuse From Intentional Risk-Taking

Wallace draws a clear line between accidental exposure and deliberate corner-cutting. On the accidental side: "Most of these tools that we go by do have configurations that you can enable that allow you to control whether your personal information or your corporate confidential information gets exposed.” 

The harder problem is the deadline-driven shortcut — someone deciding to "upload this data set to a public LLM" because "we've gotta deliver by Friday." Wallace's response to that scenario is blunt: "Just don't do that."

Give Teams Permission to Say No

Saying no isn't punitive, Wallace says — it's a discipline: "There's no pleasure in it, right? It's not like some sort of vindictive thing." Her recommended tool is a simple risk matrix — "likelihood going up one side and severity going across the other side" — that lets an organization have "a real candid conversation about finding your dot in that field" and agreeing collectively where the line sits.

She's candid about applying this herself while vetting vendors at RadarFirst: "We looked at hundreds of vendors over the course of the year. There was a pretty high proportion that we declined. We said, "we don't have enough information, or they haven't posted a trust center that we can really dig into, or they're using underlying models that they're not disclosing to us."

And ignorance isn't a defense after the fact: "I can't go to a vendor and say, ‘I didn't really understand what you were doing when I bought it from you.’ Ignorance is no defense under the law. It never has been. It never will be."

I can’t go to a vendor and say, “I didn’t really understand what you were doing when I bought it from you.’ Ignorance is no defence under the law.

DPM Podcast – Lauren Wallace – Headshot-57440

Lauren Wallace

Chief Legal Officer

Build AI Literacy Across the Organization, Not Just Leadership

At RadarFirst, Wallace's team ran a recurring education series: "About a year and a half ago, we launched a monthly lunch and learned about ethical AI. We covered one topic in each session — human agency and oversight, transparency, or accountability." The sessions used the EU's AI guidelines as a foundation and leaned on real-world case studies from the AI Incident Database: "Shocking, hot-off-the-presses things that have implicated these principles of transparency or bias mitigation."

Wallace is clear the goal wasn't to change anyone's mind on the spot: "Maybe by the time they left the room, they hadn't changed where they were. Fair enough. But when they went back to their desks, they had a vocabulary to discuss concerns with their team, or escalate concerns to legal or to compliance, or to the product team as appropriate."

As for who should lead these sessions, she doesn't think it requires a dedicated AI ethics hire: "I could see where you could even share that assignment month to month among different people, and get a little different value every time."

Regulation Is Catching Up Slowly — Act on Your Own Ethics Now

Wallace frames law itself as a lagging indicator of shared values: "Law is just a way of writing down what our shared ethical principles are and putting it in someplace where people can find it." Litigation fills the gap in the meantime, handling issues "when they're novel, they're new, they haven't come up, there hasn't been time to process them through legislative cycles" — but that process is slow by design: "the wheels of justice grind slow, but exceedingly fine."

She points to Colorado's AI legislation as a cautionary tale: the state "acted pretty fast. They got something pretty good, and then they had to yank it because they couldn't figure out how to actually enact it." Companies that had proactively built compliance around it were left waiting.

Her recommendation is to stop treating regulatory catch-up as the finish line: "If you know what it means to be an ethical organization, if you know where your risk threshold is, you're gonna put your legislative or your litigation risk over on the right side of that category and say, okay, we're willing to face that if it comes to that. But we don't know enough right now — what we know about ourselves is what we believe is right and what we believe our customers expect of us. That, we can act on today."

Want more insights like these? Sign up for a free DPM account to hear from more experts like these.

Kristen Kerr

Kristen is an editor at the Digital Project Manager and Certified ScrumMaster (CSM). Kristen lends her over 6 years of experience working primarily in tech startups to help guide other professionals managing strategic projects.