It was always about trust

and trust runs on being able to show what you did with what someone gave you

2 min read
It was always about trust

In June, I sat on a panel at the Future of Privacy Forum, alongside senior counsel from IBM, Anthropic, Meta, and Medidata. The topic was what we're actually doing with AI agents now. I ended up giving an answer that's really about the last fifteen years of my career.

I've spent that time on privacy. I workeed on a data classification system at Box. I deepend up a global privacy program at Atlassian. I was general counsel at Grindr in its earliest days as a start up, where privacy wasn't a compliance exercise, it was the difference between safety and harm for the people who trusted us with who they were. Every one of those roles taught me the same lesson. Privacy was never about data. It was about trust, and trust runs on being able to show what you did with what someone gave you.

That's the question I brought to the panel, pointed at AI agents. When an agent moves money, or acts on someone's behalf, a policy tells you what should have happened. It doesn't tell you what did. The gap between those two things is where trust breaks, the same way it broke in every privacy failure I've worked on.

I've started calling the answer a Certificate of Action: a record of what an agent was authorized to do, what it did, and the proof connecting the two. New name, old instinct. It's the thing I've been trying to build my whole career, now pointed at a system that acts on its own.

Privacy taught me that the damage happens in the gap between what a company promised and what it actually did, usually before anyone thinks to check. Agents widen that gap. They act fast, on behalf of people who will never see the decision get made. When one of those people finally asks what the agent did, I want us to have ananswer better than "trust us." Fifteen years in, building that answer is the work I  can't put down.