
Amy Worley is Managing Director and Data Protection Officer at BRG (Berkeley Research Group), where she leads the firm's Privacy and Information Compliance practice group. A former trial lawyer with 16 years in legal practice, she previously served as Global Chief Privacy Officer for Merz Pharma Group. She holds CIPP/US, CIPP/E, CIPM, CISSP, AIGP, and CHPSE credentials and is the author of The Confidence Advantage: Optimizing Privacy, Cybersecurity, and AI Governance for Growth, which introduces her Confidence by Design framework.
Amy Worley is helping business leaders rethink privacy, cybersecurity, AI governance, and data protection as one connected challenge. As a Managing Director at BRG, Amy brings a rare mix of experience as a former trial lawyer, in-house privacy leader, consultant, expert witness, and author of The Confidence Advantage. BRG recently won an AI Excellence Award, recognizing work at the intersection of AI, privacy, cybersecurity, and governance.
In this episode, Russ and Amy explore why AI has made it harder for companies to treat privacy, security, and governance as separate functions. Amy explains how businesses often have legal teams talking about GDPR or HIPAA, cybersecurity teams talking about threat actors and attack surfaces, and AI governance teams working in still another language. Her Confidence by Design framework brings those worlds together through a shared set of principles, common language, and unified risk metrics.
Amy also shares how her career shaped her perspective. She began in law, moved through data privacy and breach response as the internet and privacy statutes evolved, then went in-house to build a GDPR program for a multinational pharmaceutical company. That experience taught her the gap between giving advice and actually building programs that work inside a business.
The conversation also covers what happens during data incidents, why communication and decision authority often break before technical response does, and how Amy uses a “pre-mortem” process to help companies identify what could derail a governance program before it starts.
Russ and Amy also discuss AI deployment, data debt, enterprise LLMs, accountability, board responsibility, chief trust officers, and why digital trust should not be treated as a cost center. Amy’s message is clear: in a digital first, AI powered world, evidence based trust can become a real business advantage.
Topics Covered:
[00:00] Welcome and intro, Amy Worley, BRG, and the AI Excellence Award
[00:22] What BRG does as a multinational expert services firm
[00:53] Amy’s background as a lawyer and privacy professional
[01:11] What a former trial lawyer sees in data breach response
[02:00] Moving from legal advice to building real privacy programs
[03:13] The Confidence Advantage and Confidence by Design
[03:33] Why privacy, cybersecurity, and AI governance need to be unified
[04:00] Building an 11 principle framework across three disciplines
[05:05] What breaks when privacy, security, and AI teams are siloed
[06:00] Creating a common language for executives and risk
[07:05] Whether one team should own the unified governance vision
[07:59] What day one looks like in a data incident or program build
[08:14] Communication rules and decision authority during incidents
[09:00] Using a pre-mortem to identify why a program might fail
[10:07] Common roadblocks: executive understanding and team bandwidth
[10:45] Defining what winning looks like before the work begins
[12:08] What courtroom experience teaches about documenting governance
[13:28] How AI responsibility has shifted from planning to cleanup
[14:15] Why companies now need diagnostics for AI bottlenecks
[15:00] Building agile governance and risk tiers for AI adoption
[16:03] Confidence by Design in thirty seconds
[16:40] Maximizing the value of business data
[17:32] Data debt, enterprise LLMs, and old information resurfacing
[19:49] How to identify who is truly accountable for risk
[20:09] Why AI governance is becoming a board level issue
[21:20] The case for a chief trust officer
[22:18] What leaders should do differently tomorrow
[22:31] Digital trust as a competitive advantage
[23:22] Final thoughts on AI, privacy, cybersecurity, and the future of trust









