Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises.
We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first.
Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.
The Web Privacy Podcast - Mark Sanders
===
Ethan Prete: [00:00:00] Good morning, good afternoon, and good evening, privacy professionals alike, and welcome back to the Web Privacy Podcast, where I get to live out my dream of bringing privacy professionals together from all around the world to talk through ideas that are shaping how our data is actually being used. Today, our guest has spent over two decades as in-house counsel at some of the biggest names in tech, including Adobe and eBay, before landing a role that barely existed five years ago. Mark, who currently sits as the product and AI data privacy counsel at Tekion, which is an AI-native platform reshaping how car dealerships run their business. Today, we're covering a lot of ground in a short window. What it actually looks like to sit inside product development as counsel, how a company earns an AI governance certification like ISO, and since this is a web privacy podcast, we're going to zoom out partway through and talk plain old web privacy as well. So Mark, you've spent a lot of time at companies like Adobe, eBay, and now Tekion. What pulled you from general privacy [00:01:00] counsel toward more of this specific lane of AI and product counsel?
Mark Sanders: Yeah. So I started about, like I said, about 30 years ago, and I started during the dot com boom. And my career path has been focused on opportunities ~that~ where new technology meets new law, right? So very early, I started off with digital signatures, so ESIGN Act. I was the general counsel of a company that was a precursor to DocuSign and co-authored the patent that became DocuSign, part of that was purchased by DocuSign over time.
And ~from then,~ from there, my trajectory went through, mobile, through IoT, through cloud services. And as it progressed, data became a thing. And early on, we, there was really no concept in the legal world of data. There was technology and there was software and all of that, and of course, data was zeros and ones were the core part of it.
But from a personal data standpoint, there were no rules or regulations around that, no way of handling of that, [00:02:00] certainly not domestically ~and, ~and nor globally. And then, of course, GDPR came along~ our first comp- well,~ the first comprehensive law. And then, we've seen the US struggle with a very disparate patchwork network not going that route.
But all of that during that time, the emphasis on data, on zeros and ones, personal data, sensitive data, the handling of it, the sharing of it, the consent for it, that became a real thing, right? And that was codified, again, GDPR and the state rules. And so it just, for me, was just a huge area of interest, both because it was a new law, there were new laws, GDPR, CCP, CPRA, CCPA, all of those, and state laws, but also new technology, right?
When I say new technology that was making data, personal data use so much more important~ for the~ for the business model, for the company services or platform. And then it became everything, right? Like zeros and ones are the currency. ~They are, ~they're the fuel that drive everything.
And so obviously, zeros and ones, the majority of them are personal or sensitive in nature over [00:03:00] time in certain ways. And that flow of it and the management of it and the regulations and rules around it became something that really needed to be put in place. And during that time as it was just emerging and these things were being put in place, it was so interesting to be able to advise on data privacy because it was such a new thing, as we mentioned earlier.
What we saw during that time was, the IAPP and all of these, these lawyers at large law firms that really became the data privacy lawyers. That never existed before. ~That wasn't a,~ that wasn't a thing, right? And when that became a thing, we also saw the attention, the focus, and sort of the business models, both like you saw it within the IAPP and you see it with these law firms of really focusing on data because that's made sense both from a standpoint of that's what companies were looking for to be able to understand how to utilize and navigate through the regulatory framework.
But also from a pure business standpoint, it made sense for the organizations like the IAPP to focus on that as well as these large law firms that [00:04:00] became experts in those areas. So we saw those two things. And jumping ahead now, we're seeing a transition from that same concept of those, of data privacy moving to now the world of AI, meaning with data privacy what we saw, what we see now is it's become not as scary, right?
It's just another consumer regulation at the end of the day is really what it is. And so that means that there's less intense work to be done around it. And those lawyers that used to do it, and same thing with the IAPP, now have moved to the world of AI, and that makes sense, that shift, because in a sense, AI's sort of overtaken privacy.
Now privacy is still, there's a ~con-~ concentric circle. There's still an overlay ~between,~ an overlap~ that,~ that moves constantly between the two, right? Because you've gotta have data, zeros and ones for AI obviously, and the use of data, zeros and ones in AI are going to raise privacy concerns, so it makes sense.
And then also what is, what we're seeing are the lawyers that did data privacy [00:05:00] who were very adept at navigating a fragmented regulatory framework like the US which is what it's setting up to be very similar for AI. Those lawyers that have done that are very well suited to navigate a fragmented network of, a framework for AI.
So ~that's ~that's how I look at this transition from privacy to AI right now, right? Now for me that transition's been really, really exciting because as I mentioned earlier on my career track, it always focuses on new technology and new laws, and there couldn't be a better place to be right now for, new technology and new laws with AI
Ethan Prete: Yeah, of course. And it's interesting, a lot of our, a lot of our listeners, a lot of our network actually, they're trying to define what that looks like right now between privacy and AI and where those overlap, where they don't. And to be honest with you, despite this being a web privacy podcast, a lot of our audience actually works in adjacent fields as well, so analytics, marketing. Now, would you mind taking a second, Mark, and just maybe give us a quick overview of Tekion, what that is, and then also what your team [00:06:00] structure looks like and how you guys have divided those, those responsibilities?
Mark Sanders: Yeah. So Tekion is one of three main companies that are in the DMS space, which is the automotive dealer management software space, right? Tesla started this, I think, twenty years back. And the goal would be is to control and enable the relationship for a consumer from the minute they go to your website, a dealer's website or an OEM's or a third party like CarGurus or Cars.com, all the way through the selection, the negotiation, the purchase, services, sale, and repurchase of a car, the entire life cycle journey.
That's the Holy Grail, right? The three companies, two of them are much older, and so all three of us are trying to capture AI and implement AI, obviously. But of the three, Tekion ~is much more well-suit--~ is more well-suited to do that because being the newest company, we were able to really incorporate AI early [00:07:00] on, becoming a true AI-native platform versus the two competitors where there's more of a bolt-on.
So it's like anything in our world of technology and software when you do that versus ground up, you get, a clunky bad user experience, right? Generally speaking. And that's what Tekion does. Our team is a very small, relatively small team less than fifteen people. The team that I am a part of is the product team.
The product team, ~subject area domain, subject--~ the legal domains or subject area expertise is required for three areas. One is AI, one is privacy, and the other is regulatory, consumer regulation. And again, all three are so tightly tied together, ~th- ~really at the end of the day for what we do come under consumer regulation because that's really where our focus is.
So those are the three areas of domain. And that's all-- those are all advised and supported by our work with the product team. So we work directly with the product team and the engineers. For example, we would ~rev-review, ~Figmas ~or, or--~ and images of data flow to make sure that ~the--~ there's a [00:08:00] proper consent in place when ~that--~ those data elements are being captured, shared or processed, right?
As an example. And so that's where we spend our time
Ethan Prete: That's very interesting. ~I,~ I would guess that a lot of the individuals that I interact with in this space don't have ~inty,~ like at all any interface with product or engineering. I'm sure they've never even talked to an engineer at their company before. And so ~a l-~ a lot of our listeners today are more of like a review and approve model, where legal gets a looped in at the very, very end after something's already been built, and it's basically just how do we make this work? You're describing something almost radically different in that you're embedded from the earliest design conversations. So ~h-~ how did you get to that point? ~Was it,~ was Tekion already kind of hell-bent on doing this strategy, or did you guys have to push for that? ~H-~ how did you guys get to this point?
Mark Sanders: Yeah, no, not at all. In fact, what you've described which is correct is the true role of a product attorney. So the concept of product attorneys are relatively new also, right? Relatively speaking. And 'cause before that, before the product attorneys were truly embedded, if you will, with [00:09:00] product engineering, you had the lawyers sitting in the legal team just doing what you said basically, right?
Advising ad hoc, always coming behind, not fully integrated with the team, seeing from the concept being born all the way through getting it on the roadmap, all the way through, design, production and release, right? And so by... Especially in heavy tech companies like Tekion, you have to have strong product lawyers.
But those product lawyers, there's two pieces to it that are critical. One piece, the most critical piece truly, the hardest piece is understanding and working with product engineers. Forget about the law, but product engineers are very different than attorneys, right, or salespeople. Product engineers are black and white, or this is zero and one.
It's binary. Just tell me in clear, concise terms where I put this disclaimer. Tell me the exact language. Show me when I, when I click the button, what is it supposed to do? [00:10:00] Lawyers, we're gonna hedge or we're gonna say, it's gonna be a best practice for this," or, "We're giving this...
Our guidance right now is conditioned on this and this," right? And that doesn't translate. It's very difficult. And and it's a challenge for the lawyers as well as for the product engineers to come together and do that. So that's actually the ~biggest- ~Biggest important tool that I would say that a lawyer who's going into product wants to have.
Secondary to that, what you would think is the most important really isn't. That's the subject matter domain, right? We're all lawyers in certain, in subject matter. That's what we do, right? We're, quote-unquote, experts in privacy or AI or regulatory work or, in my world, and to some extent, we have to be all three for what we do. But ~that is~ that's the big thing given, right? 'Cause, but for that knowledge, ~you will not be a product--~ you won't be working with product to try to give them advice. And but~ the-~ they don't teach you in law school or anywhere else how to be a product attorney and sit and work with the product team and look at data flows and understand how product engineers think, right?
~So that's a real--~ that's really the biggest challenge between the two. And so answering your question directly true tech companies [00:11:00] that have heavy product eng teams will have embedded product attorneys who have expertise in whatever is being designed. In our case, AI ~pr- that, ~tools and ~p- and s- ~features of our platform that involve AI and privacy, thus impacting consumers with that.
And so ~we have to, I-~ we have to counsel on regulation. It's like~ imag-~ especially in areas like around communications, right? So opt-ins, ~com-~ communication channels, text, email. So you've got TCPA, CAN-SPAM, all of that kind of stuff, right? That's the regulatory bucket. The AI bucket, you may have CPRA, CCPA .
And in the AI bucket right now, we can talk about this later, where the triggers are for regulation in AI, what I looked at when I start paying attention to the regulation. It's very disparate right no- right now, and the laws that are coming up are really grouped on sort of the same areas, around, anything to do with kids and anything to do with communications, making sure that consumers understand they're chatting with a, with [00:12:00] AI, right?
So those. And then the third one would be high risk. So when you get into high-risk things, and there's lots of things, those are triggering the statutes. But those are right now are the three biggest areas. But it's very disparate. There aren't that many states.
Ethan Prete: Interesting. You called this out, but I'm just gonna double tap on that for one second here. ~There,~ there is a gap. There's definitely a skill gap. There's a language gap. Sometimes it feels like the attorneys are speaking one language and the engineers are speaking Arabic, and they're just not hearing each other. What would be your advice for somebody who's trying to bridge that gap right now, who maybe is an attorney to get that technical affluency, or excuse me, fluency to really speak the same language as an engineer and to get on their roadmap, if you will? How did you get to that point, and what would you recommend to someone who's about to embark on that journey?
Mark Sanders: Yeah, actually that's a really good question. I got to that point, like I got to many points in my career, 'cause again, when I came out way back in the day, there wasn't even a technology lawyer. Technology didn't exist, right? The internet was just popping up. Literally, I think I had AOL and dial-up.
And so the only lawyers inside [00:13:00] companies even were only at the big companies, maybe like the Boeings of the world or the government. Microsoft, where I live, was just starting to be Microsoft, and I remember them first getting a legal team, and it was so confusing to me. ~Like, why are lawyers in a co-~ It didn't make any sense, right?
You didn't teach this in law school. And then realizing, oh man, this is the coolest thing ever. This is the best place to be a lawyer, right? And then watching how LCF-- One of these change acronyms a million times, but how that development... Of course, we got Amazon and we got Starbucks, and we started watching all the lawyers go in there, and then everything in Silicon Valley.
And so all of a sudden it's like, wow, this is like a real thing. And so to answer your question, back in the day, there was no way to do this. And the ones that were successful, just a side note, one of the things, not so much now, but one of the really interesting things, because there was no pathway to be in-house counsel ever, right?
~You-~ That was not a law school thing. And so what would happen is during back in the day, the lawyers, us inside these companies, we'd work with outside counsel. Every once in a while, outside counsel would be so excited and they'd want to move inside these technology [00:14:00] companies, right? But when they would do that, ~they--~ it was not uncommon for them to fail miserably.
Why? Because they were not used to having clients that didn't care about what they were saying, right? And didn't-- I shouldn't say it that. In a law firm, your client comes to you and pays the money and sits down and is "Just dial in," like you're giving counsel. When you're inside a company working with these teams, sometimes the teams are siloed, so you're counseling one team on something that doesn't get to another, and you're-- ~The,~ the joke is you're always running behind.
Always. The release went and you're like, "We didn't even do a review of that new AI agent," right? And so that's a huge challenge. And so ~y- there's no you-- There was--~ That was not taught in schools, and that was not, And I don't even know if it even is now. But as I was saying, technology we then have these, what we call technology lawyers, and they were doing some license agreements maybe at Microsoft, writing some privacy terms and just some general stuff, right?
Transactions. And then those things really started going in the Microsofts and the Amazons of the world. They're like, "Wow, we-- our regulation, our-- [00:15:00] the laws are so critical and impacting all of these features and functions so directly. We need lawyers to... We can't rely on outside counsel and running behind at the end of the day.
And so we need people to sit inside, sit next to these teams." And the natural progression where typically where software engineers like would go to law school, right? They also tend to be more IP-focused, patent and that kind of stuff. But that was a natural progression. For me, I just naturally fell into it.
~I just--~ I enjoy working with product engineers more than salespeople Let's just say that, right? You know what you get with product engineering people right? And so with salespeople it's ~a lit-~ it's a little different. So I gravitated that way over the years, and I just ended up here.
Specifically answering your question, how would you get here? I still believe that at least before AI, when people really were software, going to school for software engineers, when I... To have that programming software coding engineering background, I do think that helps from the mindset of understanding terminology concepts, but really just the individuals you're working with.
Because the biggest [00:16:00] challenge truly is, again, as I mentioned, working with them, especially if, over my time, the majority of my teams were in India, right? India is a giant country with very different dialects and, it's difficult or say it'd be difficult for somebody from India dealing with somebody that is from Oklahoma versus somebody that's from New Jersey, right?
Like there's ~a, ~the way we speak and so that can be very difficult. And understanding and really taking a moment to not just the subject matter or working with we're working with the tools, but really understand who you're working with, the people, both of their product engineers, but also they may be again, from a- another country speaking, where, English is maybe not their first language or if it is, the dialects.
And so that truly can be... It's one of these more intangible challenges, I would think. It wasn't one you would really think about, but it's a, it is a real world challenge. Just as it is for anybody from another country dealing on a team, dealing with people again in the US like it's just a human thing.
So you know that, that's really what I would focus on. Making sure that [00:17:00] if you don't have the engineering software background, you at least have a passion for it. You can understand it, ~pick up, pick, understand that,~ pick that up. Then that you're really wired to work with engineers who are very, binary and that third that, that soft skill would be understanding you, you may be with working with teams in different countries and that makes a challenge.
And also by the way, the time difference makes a huge... You're talking 12 hour time differences and that's a ~ch-~ huge challenge for in-house teams that are trying to advise on a product that's gonna roll out and all of a sudden you've got a 12 hour delay, and their 7:00 AM is my 7:00 PM. So that's, those are challenges too when, 'cause when you're working with outsourcing teams.
Ethan Prete: 100%. L- let's actually pump the brakes on AI just for one second, because I'd be remiss, obviously, to not talk a little bit about privacy. And Mark, your background, as we mentioned, is very unique in that you spent an entire lifetime in privacy in big tech, and you're now more on the AI side on still tech, but slightly different team. Obviously dealers and their websites, they're still running all the classic privacy, so cookie consent, trackers, [00:18:00] ad tech audits, things like that. Obviously that, that world is changing a little bit and in a lot of ways it's getting a lot more complex every single day. Given where you sit now on the AI product side, what does your crossover look like with privacy? And I guess, what advice would you give to somebody who is still on that classic privacy side?
Mark Sanders: Yeah. And that's a really good-- And it's interesting something we mentioned in the pre-show was how it's changed for me, where my years at Airbnb and eBay and Adobe and some of those companies was, it was B2C. And the privacy issues were much more compelling than they are now in a B2B context where, again, our customers are large auto groups, right?
Think AutoNation. And then and obviously their consumers have personal information, some of it sensitive information. But we're once removed. So our obligation lands on designing a quote-unquote compliant platform service, right? And then making sure we understand where the delineation is on privacy or on any regulatory [00:19:00] obligation, where that handoff is.
When does it become the dealer's responsibility, right? Because we can only do so much, right? A dealer can choose to use our platform in a non-compliant way, right? It's our job to provide a compliant platform, have enough guardrails around it, whether it's privacy, AI, or regulatory stuff to keep the dealer square.
But always understand the dealer's gonna do what the dealer's gonna do. A little bit of a side note here, like the FTC and in California just came down hard on dealers, which has changed how we operate. And About three years ago, the FTC tried to promulgate something called the CARS Act, which was a pricing and transparency rule, basically saying, "Hey, dealers, we're tired of you abusing, consumers," right?
You show one number on the website, and then the dealer then you walk in and you're, you get another number, right? All that kind of stuff. That failed procedurally and did not get brought up with the current administration. But we knew that we had a good feeling that states would pick up where they left off.
California picked up and called it the [00:20:00] CARS Act, which really is doing the same thing. It focuses on pricing, how it's calculated, right? What is included in that price, how that price is displayed, and how you treat certain things that we call add-ons. So you make sure that, all of a sudden you don't have-- you're not paying for a theft deterrent system when there's already one built into the car, right?
By the OEM. Th-those kind of things, right? And so Those two laws and by the way, they have privacy. There's a little bit of touch points in there for privacy that come into play. But to answer your question on it, on, on what I would say, and understanding that it's the-- You also have to understand the lens you come through, right?
So at a macro level, are you a B2B or a B2C company? 'Cause that's gonna-- Your emphasis and focus is going to be very different. Now, I-I've done both, right? And it's very different, right? And you have to understand that things change when you move back from a B2C relationship and you're now in a B2B.
There's only so much you can do. And so when you talk about [00:21:00] privacy in terms of the website, and that's how a lot of people think of just general where privacy tends to come up at secondary to maybe cameras or whatnot. When you talk about that, we-- That's actually something that we really we focus on.
Obviously we have cookies, and we have privacy policy online. Because we're not consumer to consumer, that's not where my focus is right now. My focus is in designing a platform that handles consumer data in a in a compliant manner, right? And so again, the starting point of, okay, what's your lens, right?
And then jurisdictionally, what are you talking about? Do you have just a US domestic offering only? 'Cause that's gonna make things, easier from the standpoint that I'm, not dealing with the GDPR or with Brazil or with somebody else, right? But that still has its own unique issues because of the disparate patchwork way that we've created privacy here.
And it's, the concepts in privacy are pretty well baked in, right? It's just the application of it
Ethan Prete: Sure, that makes sense. And I don't think anyone's gonna disagree that it's very much a patchwork right now. As things are evolving, and I'm sure you're at the front row of this, but we're [00:22:00] starting to see things like AI agents that are showing up on customer-facing pages, chat widgets, service scheduling assistants, so on. Is there a point where a website AI feature starts raising the same questions that like a tracker would, and those almost become somewhat synonymous in terms of what data it's collecting and do those two worlds eventually just kinda combine again into one where the privacy people are now the AI people because all the AI features are the privacy features?
Mark Sanders: Yeah. Yeah, that last point the only thing about that last point, 'cause I can totally see that happening but the bar to be proficient at AI is pretty heavy. So I'm wondering how much that, people will naturally... They're gonna have to under- lawyers will have to understand how... But it'll be interesting.
But that is a thing. I could see that. The agent use. So most of my day with respect to AI, when there's AI, it's all around agents, right? And developing and launching these agents. That is also, I mentioned earlier, one of the three areas of consistent regulation right now [00:23:00] is on agents and the disclosure communication and privacy issue, data sharing with the agents, right?
So when you look at the agents, you may have. In my situation, you may have two different kinds of agents at the macro level. One is a internal agent, right? So for the service team, for example the service team may use an AI agent internally to identify a certain vehicle, and if that certain vehicle then historically has a failure with a transmission component on that vehicle that year, whatever, then, it would automatically order or be focused on searching, for that issue.
That would be an internal use of AI or maybe something on the analytics side internally, right? AI. Then the external-- and by the way, those would be-- those are agents in some of those contexts that the, the internal te- technicians are chatting with, right? And then on the external side, which is what we normally think about, which is the agents, and chatting with a consumer, right?
That's the more prevalent. That's what we typically think about. But there are two sides. [00:24:00] But we'll focus on the one that, that's more relevant, that is the consumer-facing one. So consumer-facing one is really interesting because it's AI, but it's also a communication channel. Meaning you've got-- And there's-- So there's three components.
There's actually four when you're looking at an agent potentially. There is the AI regulation around an agent itself, consent and high-risk activities and all of that. There's the privacy in component around it because there's data from a consumer. There is the AI com-- Or and then there's the regulatory component, which may be another consumer law just based upon the industry the agent's on.
So I guess there's three, is what I was saying. So those are the three views. So when I look at an agent, for me, and if I'm reviewing an agent, okay, what lens am I looking through, right? So I wanna understand how the agent functions, and then I'm gonna look-- I'm gonna review that agent for AI compliance, if you will.
And for example, if we have an agent that just is scheduling service appointments, that's [00:25:00] not what's called high risk. High risk, imagine how to create a bioweapon, right? How to, an agent that's, working as a counselor for kids, right? High risk, right? This is not high risk. So right now, I get-- I don't even have to look at a bunch of the statutes, right?
'Cause they're not triggered. Because it's not high risk. But I do have to look at them if the statutes talk about, even if it's not high risk, which some do the agent and how it operates and cons- consumes data discloses as an agent, that kind of stuff, right? And that would be then in the then that AI.
So that'd be an AI regulation on agents, and that would also dovetail into the privacy component too. That would be then the privacy review, and then the regulatory component of that would be the TCPA, for example, because of the communication where texting comm or a voice comm or email for, and that would be CAN-SPAM, right?
So those are the three it don't-- it views that I would take looking at an agent 360 for a compliance review
Ethan Prete: Interesting. We have about time for one question, Mark. [00:26:00] And the one I wanted to ask is just, this is for the audience mainly, but is there anything in your world in the AI space that you feel like keeps you up at night, freaks you out a little bit? And I'm thinking more so how that's gonna relate to our audience here, but is there any one thing that you feel like you'd want to share with the audience today of "Oh man, this is the one thing I'm keeping an eye on.
You should keep an eye on it as well"?
Mark Sanders: Yeah
Say this for everybody when you learn and think about, want to learn about AI, like really be discerning, like really focus on sort of the OGs or the five or six individuals, the early godfathers of AI, Hintons and whatnot, that started it were with the Googles and Anthropics and have left and started foundations.
And when they speak and they say, "We do not know why the model just did this," that's who you listen to, right? Not all the other hype about when there's gonna be super intelligence and all this stuff. Also, when the companies themselves are disclosing. So we've seen Anthropic started it, really disclosing some, some issues.
ChatGPT has done it. You have to keep, keep a grain of [00:27:00] salt around that, right? Because it's coming from the companies. But yeah. So the biggest concern is agents, we don't know what they do. We don't know why they do what they do, right? So in my context, a real quick example about three years ago in the, our space, somebody-- There was a company that had a service agent, you'd call the service to schedule a car service.
An individual called, he happened to be a software engineer. He got his service scheduled. He's like, "Hey, I'm gonna call back and see if I can ask the agent to code." The agent ran, a massive app, created a massive app, burned through all these tokens, caused hundreds of thousands of dollar, whatever it was, right?
So that's an example, right? That agent wasn't designed properly. And fair enough, nobody would have thought about that three years ago, right? With AI like that, people weren't thinking about those things, right? So we're always behind AI, right? AI is, it's getting to the point of what we call recursive learning, where it doesn't need us anymore.
It's now has enough to learn on its own, and then based on what it's each learning, it's learning more on its own, right? To the point where it's gonna create its own code that we won't be able to read, right? Those are my [00:28:00] concerns. And the jailbreaks that we've seen with Anthropic and ChatGPT with OpenAI, right?
Which we knew that those, those things were gonna happen. You can also watch the AI dumbing down responses now to make sure they don't get turned off. All sorts of stuff, right? So that's a concern
Ethan Prete: It's all so fascinating, and it's also the reason why I always say thank you every time I end a query, even though that costs me tokens, so
Mark Sanders: Yeah, . One last point that's really critical for privacy that actually, I probably should have led with, and that is AI is only as good as the data, right? And so all of these amazing tools that... And I worked on it and that the internal tools the teams are using they're only good if they can hit our data, if they can hit our database where our Juratecs or where Confluence or where the Figmas are, right?
No lawyer wants to ever give data access to a third-party vendor back in the day. Now, let alone with AI, right? It was just enough to give access back in the day. Now, you're giving access to AI. We don't know what AI is gonna do by virtue of it being AI. So that is the hugest thing right now.
If I was to focus on a practical privacy point with AI
Ethan Prete: [00:29:00] Love it. And it's, again, I don't know that anyone would disagree with you on that. It's a great point. Mark, if I took good notes here, and I'm gonna take a shot in the dark. The three things that were memorable and stuck out to me was the first one, you gotta move the counsel upstream. That's gonna save you time.
It's gonna be cheaper. You're gonna save a lot of money on rebuilds and disclosure gaps later. That's probably the number one point I'd call out. Number two is web privacy's still there. It might be quieter in some cases, especially on the B2B side, depending on where you fall in terms of size, but cookie and tracking compliance doesn't just disappear because AI is getting all the attention. And then the third one is make sure that you're understanding, make sure you have that fluency on the technical side. Make sure you're familiar with these AI tools, especially if you're trying to move counsel upstream. That way, again, you can have the empathy that you're speaking the same language as these product and engineering professionals who are building this on behalf of your company, and you're trying to, protect and mitigate risk.
Mark Sanders: I would just add I should have focused more on your first one with respect to with respect to the website. Adding AI to that is yes, is gonna make things... As when you add AI to [00:30:00] anything, changes things exponentially, right? Privacy concerns. And then also again, just the fourth one I would put would be the data access, API access into, into your customers' databases to be able to make AI useful to those people.
From a privacy standpoint, that's gonna be huge.
Ethan Prete: It's gonna be huge.
Mark, thank you so much for joining the Web Privacy Podcast.
This was a great one. To everyone listening, we'll catch you next time. Thank you for joining.