Key takeaways
- For each show, here’s what I think it gets right about the privacy conversation, and the one question I’d bring to the table.
- I’d come with a research angle, not a product. The question I’d bring: I built STRATA-Bench to measure how AI agents handle fragmented information — here’s what my data says about hallucinating agents as a data-leakage vector, and why security teams should care.
- But the adjacency is getting less adjacent by the month. The question I’d bring: As AI agents start making financial decisions for consumers — comparing, applying, negotiating — where do dark-pattern rules meet agentic manipulation, and who’s liable when the agent is the one doing the nudging?
The good conversations aren’t in whitepapers anymore
Somewhere along the way, the most interesting thinking about AI and privacy stopped happening in conference proceedings and started happening in long-form audio. There’s something about a microphone and an hour of unhurried time that gets people past the talking points. Hosts ask the follow-up question. Guests admit what they don’t know. Nuance survives.
That’s exactly what this moment needs. AI agents are colliding with privacy law in real time — agents that read your email, book your travel, and touch production data while regulators in Quebec are enforcing Law 25 with real teeth and the OPC is ruling on what OpenAI owes Canadians. I spend my days in this collision zone: I’m a data protection and security specialist at The Globe and Mail, a CIPP/C consultant, and I built STRATA-Bench to measure how AI agents handle fragmented information (spoiler: hallucinating agents are a data-governance problem, not just an accuracy problem).
So I’m putting together a podcast circuit — shows I’m pitching myself onto, one by one, because each of them is asking a version of the question I care about. This is my list, honestly framed: these are conversations I’d love to have, not appearances I’ve made. For each show, here’s what I think it gets right about the privacy conversation, and the one question I’d bring to the table.
If you host or produce one of these shows, my pitch is real and my inbox is open — reach me via /contact/.
Canada first
The Law Bytes Podcast
Michael Geist has been doing something rare for years: treating Canadian technology law as a subject worthy of its own sustained, expert conversation rather than a footnote to American or European debates. Bringing in outside experts — like Lisa Given on what Canada can learn from Australia’s youth social media ban — is the show’s signature move, and it’s the right one. Canadian privacy law has its own texture, and it deserves its own explainers.
The question I’d bring: Quebec’s Law 25 is now arguably the most aggressively enforced privacy regime in North America — what should Canadian regulators borrow, and what should they refuse to borrow, from how other countries are policing AI agents’ data practices?
Shared Security Podcast
Tom Eston, Scott Wright, and Kevin Tackett get something a lot of privacy commentary misses: privacy is a security discipline. The weekly cadence, the practitioner guests, the explicit welcome for topic suggestions — it all adds up to a show that treats privacy as something you do, operationally, not something you opine about. That insider-threat episode with Dr. Helen Ofosu is a good example of the show’s range.
The question I’d bring: Most incident response plans still treat an AI agent’s unauthorized data access differently from a breach — should they? And what does that mean for the DPOs being handed these plans?
Cybersecurity Today
David Shipley’s show, via IT World Canada, does the unglamorous and essential work of keeping Canadian practitioners current — current episodes, current threats, outside experts who actually know things. In a news cycle where AI developments age in dog weeks, a show that stays current without going breathless is a genuine public service.
The question I’d bring: What does “reasonable security safeguards” actually mean when the system in question is an autonomous agent touching production data — and are Canadian organizations even asking their vendors that question yet?
Hashtag Trending
Jim Love’s Hashtag Trending is where Canadian tech news gets translated for people who have decisions to make. The weekend editions that bring in external experts are the sweet spot for me — that’s where the headlines turn into implications. Decision-makers don’t need another AI hype cycle; they need someone to tell them what it means for the data they’re responsible for.
The question I’d bring: When AI news moves faster than policy, how should business leaders make privacy calls under genuine uncertainty — and what separates a defensible judgment call from negligence?
The international circuit
The Cyberlaw Podcast
Stewart Baker’s show has run 558+ episodes at the intersection of law, national security, and technology, with guests like Gen. Michael Hayden. That longevity matters: this is a show with institutional memory. It remembers what the last three hype cycles promised, which makes its take on the current one worth hearing.
The question I’d bring: As AI agents start executing multi-step tasks across borders — booking, buying, negotiating — where does data residency law actually bite, and where is it just theater?
A Class Act: Conversations in Data & Leadership
Michael Young and Shannon McKechnie frame data as a leadership problem, not a plumbing problem — and a 2026 episode on agentic AI in financial services shows they’re tracking exactly the collision I’m interested in. Governance failures are almost never technology failures first; they’re leadership failures with technology symptoms.
The question I’d bring: What should a data leader require from their teams before an AI agent touches customer data — and how do you make that a promotion-worthy behavior rather than a compliance tax?
TeqTalk
Jas Kaur brings CXOs and data/AI leaders to the mic — the people actually signing off on agentic deployments. I like the builder-executive perspective: it keeps the conversation anchored in what ships, not what ought to ship. The gap between those two things is where privacy risk lives.
The question I’d bring: How do CTOs balance shipping agentic features against data-minimization obligations — and is anyone measuring the privacy cost of “move fast” in agent deployments?
Caveat
Dave Bittner and Ben Yelin’s weekly show for N2K Networks takes the premise right in the name: caveat — let the listener beware. With guests like Brad Carson, Igor Volovich, and Andrew Burt, it consistently finds the policy nerve inside the technology story. It’s the rare show comfortable saying “this is complicated” and then actually doing the complication.
The question I’d bring: Do our current consent models even survive the agentic era — or do we need a new legal theory for machines that act on our behalf with our data?
Serious Privacy
Dr. K Royal, Paul Breitbarth, and Ralph O’Brien run the deep end of the pool: serious, global, practitioner-grade privacy law, with guests like Gabriela Zanfir-Fortuna, Marty Abrams, and Michelle Dennedy. This is the show where you go when you want the actual doctrine, not the LinkedIn version.
The question I’d bring: Quebec’s Law 25 enforcement is producing real case studies in real time — what should the EU and the US be learning from how it’s landing on the ground, practitioner to practitioner?
Digital Transformation Podcast
Kevin Craine treats AI governance as a transformation story, which is exactly right for the enterprise audience actually doing the work. His AI-governance episodes show he understands that governance isn’t a department — it’s what happens when an organization’s habits meet a new technology.
The question I’d bring: How do you operationalize AI governance inside companies that still treat privacy as legal’s problem — and what does the first 90 days of a real program look like?
Paul’s Security Weekly
Paul Asadoorian’s long-running show is a fixture of the practitioner security community, with 2025–26 coverage including Black Hat USA 2026. The show’s guest format explicitly distinguishes editorial interviews from vendor sales pitches — which tells you everything about its priorities. I’d come with a research angle, not a product.
The question I’d bring: I built STRATA-Bench to measure how AI agents handle fragmented information — here’s what my data says about hallucinating agents as a data-leakage vector, and why security teams should care.
The Data Exchange
Ben Lorica’s show takes the data-centric view of AI risk, and a September 2026 episode on AI IP protection, risk, and governance shows it’s right on top of the current questions. When everyone else is talking about models, The Data Exchange talks about the data — which is where the privacy liability actually sits.
The question I’d bring: When agents synthesize information across multiple sources, who owns the privacy risk of the composite — and how do you even begin to audit it?
AI & Data Driven Leadership Podcast
Dean Guida brings the CEO lens: an August 2026 episode 73, and an episode 72 that covered AI data governance and the EU AI Act with a GDPR/DPO guest. Getting governance onto the CEO agenda is half the battle, and this show is fighting it in the language executives actually speak.
The question I’d bring: What should boards be asking about AI agents and personal data before they approve deployment — and what answers should make them nervous?
DM Radio
Eric Kavanagh has been hosting DM Radio weekly since 2008 — that’s institutional memory you can’t fake — with 2026 episodes on AI-ready data architecture. The long-running panel format means ideas get stress-tested by practitioners in real time, which is where the interesting disagreements live.
The question I’d bring: Everyone says they want “AI-ready data architecture” — but what does that phrase mean for privacy by design, concretely, in the systems being built this year?
Practical AI
Daniel Whitenack and Chris Benson’s Changelog show is resolutely practical and builder-focused — weekly, active, allergic to hype. That’s the audience I most want to reach: the engineers deciding what the agent does with the data it touches. Privacy that doesn’t survive contact with the build process isn’t privacy.
The question I’d bring: How do you build privacy into agentic systems from day one — as an engineering property, not a compliance checkbox bolted on before launch?
Consumer Finance Monitor
Alan Kaplinsky’s Ballard Spahr show is the stretch pick on my list, and I’ll own that: it’s a consumer-finance show, and my pitch is adjacent rather than core — data practices, dark patterns, and how financial institutions handle consumer information. But the adjacency is getting less adjacent by the month.
The question I’d bring: As AI agents start making financial decisions for consumers — comparing, applying, negotiating — where do dark-pattern rules meet agentic manipulation, and who’s liable when the agent is the one doing the nudging?
Come talk to me
Sixteen shows, sixteen conversations I’d genuinely love to have. If you’re a host or producer on any of them — or you run a show asking adjacent questions — my pitch is real, my calendar is real, and I’d love to make the case in person. Reach me via /contact/.
And if you’re a listener rather than a host: subscribe to a few of these. The AI-privacy conversation is happening out loud right now, and it’s better than the whitepapers.