The Consent Layer AI Skipped: Building Governance That Ships

About this session

AI governance usually stops at the policy document. The harder problem is building consent and data rights into the access layer itself, so terms are set, verified and enforced at the moment an AI system reaches for content. This session draws on a working model: the voluntary privacy framework that brought more than 90 percent of the commercial web into compliance in 18 months, without a mandate. Lori Fena, who built that framework as the founder of TRUSTe, walks through what made voluntary consent infrastructure reach adoption then, and what an open, machine-readable consent layer looks like for the agentic AI era now, where the entity requesting access is a bot and enforcement has to happen in production.

Speaker

Key takeaways

  • Consent belongs in the access layer. Governance that sits in a document does nothing at the moment an AI system reaches for content. Enforceable consent sets terms, verifies the request and settles it while the access is happening.
  • Voluntary frameworks work when the infrastructure works. TRUSTe reached more than 90 percent of the commercial web in 18 months with no mandate, because the system made compliance the path of least resistance. The same mechanism applies to AI consent now.
  • The requester changed, and enforcement has to catch up. The web was built for human visitors and for crawlers that honored a polite request. AI agents operate at machine speed and treat that request as optional. Consent that is machine-readable and enforced at the point of access is what the agentic era needs.

Related sessions