AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, Caleb Tolin welcomes Ojas Rege of OneTrust for a practical, wide-ranging conversation on how data privacy and governance must evolve alongside enterprise AI adoption.
Ojas explains why AI fundamentally changes the privacy conversation: the same systems that enable organizations to move faster can also cause harm faster when guardrails aren’t in place. From agentic AI systems that dynamically repurpose data to general-purpose models that blur traditional notions of “intended use,” the challenge isn’t just compliance—it’s trust.
The discussion dives deep into purpose limitation under GDPR and the EU AI Act, clarifying where organizations commonly misunderstand consent and where AI training introduces entirely new risks. Ojas emphasizes a simple but powerful test: are you using personal data for the same purpose you originally received consent for—or has AI quietly expanded that purpose?
The conversation then shifts to cloud and data sovereignty, particularly for European organizations navigating geopolitical uncertainty. Ojas outlines why data mapping, prioritization, and software supply chain visibility matter more than ever—and why perfection is less realistic than smart prioritization.
Ultimately, this episode reframes governance as an enabler. When privacy and data governance are embedded early, organizations can innovate faster, build lasting trust, and deploy AI with confidence in an increasingly complex global environment.
What You’ll Learn
Why AI scales privacy risk just as fast as business value
How purpose limitation breaks down with general-purpose AI models
When AI use requires new consent—and when it doesn’t
Why transparency is foundational to long-term customer trust
How data sovereignty concerns extend beyond cloud providers
Where software supply chains create hidden privacy blind spots
How good governance can accelerate, not block, AI deployment
Episode Highlights
[00:02:00] AI Scales the Good—and the Bad How AI accelerates both innovation and privacy harm.
[00:04:00] Purpose Limitation Meets AI Reality Why general-purpose models challenge traditional consent frameworks.
[00:06:30] Trust as a Business Risk Why transparency matters as much as legal compliance.
[00:07:30] Cloud & Data Sovereignty Explained What European organizations can do today to reduce risk.
[00:10:30] The Software Supply Chain Blind Spot Why third parties make sovereignty harder in the AI era.
[00:12:30] Data as Economic Power How nations now view citizen data as an AI asset.
[00:14:00] Governance That Enables Speed Why governing early helps organizations move faster later.