ARTICLE
21 August 2026

Today’s Podcast Release: The “Confidence Advantage”: Why Privacy, Cybersecurity And AI Governance Are Becoming Business Imperatives

BS
Ballard Spahr LLP

Contributor

Ballard Spahr LLP—an Am Law 100 law firm with more than 750 lawyers in 18 U.S. offices—serves clients across industries in litigation, transactions, and regulatory compliance. A strategic legal partner to clients, Ballard goes beyond to deliver actionable, forward-thinking counsel and advocacy powered by deep industry experience and an understanding of each client’s specific business goals. Our culture is defined by an entrepreneurial spirit, collaborative environment, and top-down focus on service, efficiency, and results.
How can privacy, cybersecurity, and AI governance be transformed from mere compliance obligations into strategic assets that build customer confidence and competitive advantage? This podcast episode explores a framework for integrating these traditionally siloed disciplines into a unified approach that treats digital trust as part of the product itself. Drawing on insights from a new book and legal expertise, the discussion reveals why evidence-based confidence matters more than trust, and how governance bu
United States Privacy
Ballard Spahr LLP are most popular:
  • within Insolvency/Bankruptcy/Re-Structuring, Environment, Government and Public Sector topic(s)

In the latest episode of the Consumer Finance Monitor podcast that we are releasing today, we explore a topic that is becoming increasingly important for financial services companies and virtually every other business operating in today’s digital economy: how privacy, cybersecurity, and AI governance can be transformed from compliance obligations into sources of customer confidence, resilience, and competitive advantage.

Alan Kaplinsky (founder, founder lease for 25 years and now Senior counsel of our Consumer Financial Services Group) hosts and interviews our guests. Our guests are Amy Reeder Worley, managing director at BRG and author of a new book entitled The Confidence Advantage: Optimizing Privacy, Cybersecurity, and AI Governance for Growth, and Greg Szewczyk, chair of Ballard Spahr’s Privacy and Data Security Group. Amy advises senior executives and boards on cybersecurity, privacy, and AI risk, while Greg regularly counsels clients on privacy, cybersecurity, data governance, incident response, and the rapidly evolving legal issues surrounding AI.

Amy’s book is available on Amazon.

From “trust” to evidence-based confidence

A central concept in Amy’s book is the distinction between trust and confidence. She describes trust as a feeling, while confidence is an evidence-backed belief. In her view, companies should not simply say that they want their customers to trust them with their data. They should be able to demonstrate why customers should have that confidence through evidence that the organization is doing the things it is supposed to do.

That distinction is particularly significant as companies deploy increasingly sophisticated AI systems. Customers, regulators, business partners, and investors are demanding greater assurance about how organizations collect, protect, use, and govern data—and how AI systems are developed and deployed.

Amy argues that digital trust should be viewed as part of the product or service itself, rather than as a compliance “bolt-on.” In other words, responsible stewardship of data and AI can become part of the value proposition that a company offers its customers.

Breaking down the privacy, cybersecurity and AI silos

One of the most interesting themes in this podcast show is the discussion about the need to move away from treating privacy, cybersecurity, and AI governance as separate disciplines operating in organizational silos.

As Amy puts it, “the data doesn’t care what silo it’s in.” Although organizations will continue to need privacy professionals, cybersecurity experts, and AI specialists, she advocates giving them a common vocabulary and shared risk framework focused on the underlying asset: data.

Greg has seen the same development from the legal side. In particular, AI governance is forcing privacy and information-security functions to work more closely together. Amy notes that organizations seeking to move aggressively into AI are also discovering “tech debt” which includes cybersecurity and other infrastructure work that previously had been deferred.

The result may be a fundamental change in how companies think about data governance. Rather than asking which department owns a particular issue, organizations increasingly need to ask how the enterprise as a whole is managing data risk and data opportunity.

“Confidence by design”

Amy describes a framework she calls “confidence by design.” Drawing on concepts from the NIST Responsible AI Framework, GDPR principles, and ISO 42001, she has developed 11 principles designed to give organizations a common language for incorporating privacy, cybersecurity, and responsible AI into their operations.

The objective is not to turn every employee into a privacy, cybersecurity, or AI expert. Instead, Amy wants organizations to create “issue spotters”—employees who recognize when something may require additional review or accountability.

That concept has particular resonance for AI governance. Companies increasingly need employees throughout the organization to recognize when an AI system raises questions involving privacy, explainability, accountability, transparency, or other risks.

The danger of the “FOMO” approach to AI

We also discuss what Amy describes as the “FOMO” approach to AI: moving as quickly as possible to deploy AI tools and planning to establish governance later.

According to Amy, that approach can produce reversals and rollbacks when consumer-facing AI initiatives encounter problems that appropriate governance might have identified before deployment. A company can suffer not only a regulatory or legal problem but also a significant loss of customer confidence and damage to its brand.

The alternative is not to abandon innovation or move slowly. Amy argues that effective governance can actually allow companies to innovate faster once the appropriate structures are incorporated into the development process.

She advocates building “confidence by design” into the software development and product life cycles. Governance can also be embedded directly into technology through features such as traceability, alerts, and observability.

Where should companies begin?

For organizations that are just beginning to address these issues, Amy’s advice is surprisingly basic: start by determining what data the company has and where it is located.

Companies cannot effectively govern data that they cannot see. Amy describes data mapping and understanding data flows as the starting point for her engagements. AI makes that task even more important because AI systems can discover and infer information that an organization did not previously realize it possessed.

For companies using AI, she also recommends creating an AI inventory—not merely of approved AI tools, but of tools employees may be using without the organization’s knowledge.

Boards need to know who owns the risk

Another important message from the discussion is the growing role of boards and senior management.

Amy views privacy, cybersecurity, and AI as board-level risks. Boards should be asking management what risks are currently being tracked, who owns each risk, and how those risks are being managed. As she puts it, an organization isn’t really doing risk management if nobody has been assigned responsibility for a particular risk.

Greg expects board-level involvement in AI governance to become increasingly common as laws and regulations evolve. More sophisticated boards are already becoming involved before they are legally required to do so, and he expects regulation eventually to make board involvement more widespread.

Governance as a competitive advantage

Perhaps the most important message from the podcast is that good governance should not necessarily be viewed as a cost center.

Amy cites research indicating that organizations with greater maturity across privacy, cybersecurity, and AI governance were more likely to achieve significant EBIT growth. More fundamentally, she says that having clean, controlled, and mapped data gives companies greater opportunities to use that data to develop innovative products and services.

This is particularly important in financial services, where data is at the center of virtually every aspect of the customer relationship.

A rapidly changing legal landscape

We also discussed the extraordinary uncertainty surrounding AI regulation. Different jurisdictions are taking very different approaches, and Amy expects businesses to increasingly rely on private standards such as ISO 42001 and the NIST AI Risk Management Framework as organizations seek common, auditable standards even when the applicable law remains unsettled.

Greg highlights the particular challenges facing financial services companies, including the rapidly developing state-law landscape. He notes that additional legislation could materially alter the regulatory environment for financial institutions on relatively short notice.

We also discuss the emerging legal issues surrounding agentic AI. As AI systems become capable of acting with greater autonomy, traditional principles of accountability, contract law, privacy law, and tort law will increasingly be tested against new technologies. Amy notes that courts in several countries have already rejected the notion that an AI system itself can bear legal responsibility, instead placing accountability on the party deploying the system.

The bottom line

At the conclusion of the podcast, Alan identified four principal takeaways.

First, privacy, cybersecurity, and AI governance can no longer be viewed as separate compliance functions operating in organizational silos. They are increasingly interconnected and require an integrated governance framework.

Second, governance should not be viewed merely as a regulatory obligation or cost center. Responsible stewardship of data and AI can strengthen customer relationships, reduce risk, enhance reputation, and create competitive advantages.

Third, AI governance needs to be built into systems from the beginning. It cannot simply be bolted on after deployment.

Finally, digital trust—or, as Amy describes it, confidence grounded in evidence, transparency, and accountability—will become increasingly important. Customers, regulators, investors, and business partners will increasingly want assurance that organizations are using data and AI responsibly. We encourage our readers and listeners who are interested in these issues to listen to the full episode and to consider reading Amy’s book, The Confidence Advantage: Optimizing Privacy, Cybersecurity, and AI Governance for Growth. It provides a useful framework for thinking about an issue that is quickly moving from the privacy and technology departments into the boardroom.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More