AI & Machine Learning

FPF AI Governance Workshop: Advanced Issues in Agentic Deployment

Wednesday, October 21 @ 12:00pm PT

Overview

Agentic systems are transforming how consumers manage their data and make important decisions, from managing health records, to managing a financial portfolio, to negotiating everyday transactions. Within enterprises, the responsibility for building and governing AI agents is spread between functions that rarely sit in the same room: AI governance, security, engineering, legal, risk, and privacy. As these systems begin to act autonomously on a user’s behalf, the hardest questions do not always have clear owners: what an agent is actually authorized to do, and what data it should touch as it operates. 

Join senior AI governance leaders and practitioners on Wednesday, October 21, 2026, from 12:00–5:00pm PT for an in-depth workshop on advanced questions in agentic AI deployment. The day begins with a welcome lunch, followed by small-group discussions to develop a workable, shared taxonomy of agentic AI. The workshop will be co-hosted with Orrick and held in-person at their offices in Menlo Park, CA. A summary of the session will also be published as a resource.

Request to attend the workshop by October 9th. Space is limited; attendance will be reserved for senior leaders and practitioners. 

For questions about the event or eligibility, please email [email protected].

Parking Information

Orrick Menlo Park is located at 1100 Marsh Rd, Menlo Park, CA 94025.

Complimentary onsite parking is available in the Orrick Menlo Park office parking lot.

Agenda

Wednesday, October 21, 2026

Time

Event

Speakers

12:00 pm –
1:00 pm PT

Networking Lunch

1:00 pm –
1:30 pm PT

Opening Discussion — Building a Shared Agentic Taxonomy

1:30 pm –
2:45 pm PT

Tabletop 1 — Authorization & Consent

What did a user actually authorize their agent to do, and how can you prove it? Working from a realistic consumer-agent scenario, tables will work through where blanket authorization ends and per-action consent is required; when consent for one purpose carries to another; and what evidence of authorization an organization would need to produce.

2:45 pm –
3:00 pm PT

Break

3:00 pm –
4:15 pm PT

Tabletop 2 — Data Flows and Integrity Across the Pipeline

When an agent picks its own tools and decides what data to share or request: how are those decisions made? From an enterprise scenario in which an agent decomposes a task into a pipeline of tool calls — including a third-party service and a hand-off to another organization’s agent — tables will work through what a minimization discipline for agent pipelines looks like, and what should happen at the boundaries where one organization’s governance stops and another’s begins.

4:15 pm –
4:55 pm PT

Closing Panel — Lessons and Next Steps

Discussion of what was learned and future work.

4:55 pm –
5:00 pm PT

Closing Remarks

Speakers

William Bartholomew

Director of Public Policy, Office of Responsible AI, Microsoft

William Bartholomew is Director of Public Policy in Microsoft’s Office of Responsible AI,
working across engineering, AI governance, standards, and public policy. He focuses on
agentic AI, evaluation and assurance, transparency, incident response, and translating
regulatory requirements into practical governance.
Previously, he held software engineering and product roles at Microsoft and GitHub,
with experience in cybersecurity, open source, and software supply chains.
He co-chairs MLCommons’ Safety Working Group, is Co-Vice Chair of IEEE-USA’s AI
Policy Committee, and belongs to OECD.AI’s Expert Group on AI Incidents. He has
contributed to a range of technical and policy publications, authored a technical book on
software engineering infrastructure, and holds a patent related to cloud security.

Amy Chang

Head, AI Threat Intelligence and Security Research, Cisco

Amy Chang is a renowned AI security and cybersecurity expert with almost two decades of practitioner, academic, and government experience. She currently leads the AI Threat Intelligence and Security Research team at Cisco, developing first-in-class AI threat intelligence capabilities to monitor the threat landscape and to build defensive capabilities to secure enterprises from AI risk. Amy’s work also focuses on developing scalable and sustainable frameworks for AI security. Amy is also Adjunct Faculty in Cybersecurity & Emerging Threats at Middlebury Institute of International Studies. Prior, Amy also served numerous senior roles at start-ups, corporations, government, military, and non-profits, including as an Executive Director for Global Cybersecurity Operations at JPMorgan Chase, where she led cyber threat intelligence teams and uplifted JPMorgan’s intelligence-driven cybersecurity defense. She was formerly a Staff Director in the House Foreign Affairs Committee and worked on Asia policy and legislation. She also served as an officer in the U.S. Navy. Amy is a graduate of Harvard University and Brown University.

Alvaro Marañon

AI Policy Manager, Meta

Alvaro Marañon is an AI Policy Manager at Meta, where he works on AI legislation and regulation with a focus on risk and agentic AI. He is a graduate of American University Washington College of Law and the University of New Hampshire.

Gabriel Nicholas

Public Policy - Agents, Anthropic

Gabriel Nicholas leads Anthropic’s policy work on AI agents as part of the company’s Product Public Policy team. He is also a member of the Agentic AI Expert Group at the OECD. Previously, he served as a Senior Policy Advisor at the National Telecommunications and Information Administration, where he advised the White House and Department of Commerce on domestic and international AI policy, and as a Research Fellow at the Center for Democracy & Technology.

Austin Ruckstuhl

AI Policy Manager, Meta

Austin Ruckstuhl is an AI Policy Manager at Meta, where he leads policy advising and policy development for the company’s agentic AI product teams. His work covers Muse, Meta’s personal AI agent, along with novel agentic products and AI integrations across Meta’s Reality Labs portfolio. He has been with Meta’s Public Policy team since 2022 and was previously a Policy Advisor at the Internet Society and an Internet Governance researcher at the United Nations University.

Dr. Ellie Sakhaee

Lead, AI & Emerging Tech Policy Research, Google

Dr. Ellie Sakhaee leads AI & Emerging Tech policy research at Google, where she focuses on frontier technologies, AI agents, robotics, and AI for scientific discovery. Her background spans academic research, public and corporate policy, and AI R&D. As a Machine Learning scientist with a PhD in Computer Science, she has led engineering teams, published extensively on AI safety research, and led teams building AI models and developing risk assessment and mitigation strategies for cutting-edge AI systems. Prior to Google, Ellie worked at Microsoft’s Office of Responsible AI and served in the U.S. Congress, advising on technology policy.

Lily Tsai

Researcher and Engineer, SystemsResearch@Google (SRG)

Lily Tsai works as a researcher and engineer at SystemsResearch@Google (SRG), currently investigating frameworks for better security and privacy in agentic systems. In 2024, Lily earned her PhD from MIT, advised by Frans Kaashoek in the PDOS group and Malte Schwarzkopf in the Brown ETOS group, where her research focused on systems for better data protection and security in web applications. Beyond data privacy and security, Lily is also broadly interested in multicore performance and scalability, and the application of formal methods in systems. Besides research, Lily loves playing violin, reading, hiking, climbing, and exploring the world around her!

Shannon Yavorsky

Partner, Global Chair, Cyber, Privacy & Data Innovation, Co-head of AI, Orrick, Herrington & Sutcliffe, LLP

Shannon Yavorsky co-leads Orrick’s global Cyber, Privacy & Data Innovation group and Artificial Intelligence practice. Qualified in California, England and Wales, she advises global organizations on AI governance, privacy, cybersecurity and the evolving U.S. and EU regulatory landscape.
Shannon works with companies across technology, life sciences, health technology, financial services, private equity, insurance and social media to build practical, risk-based AI governance programs. Her work includes the EU AI Act, GDPR, the NIST AI Risk Management Framework, U.S. state privacy laws and sector-specific requirements.

She helps clients design AI use policies, assess and mitigate AI risks, establish governance frameworks, negotiate agreements for AI-enabled products, and integrate responsible AI principles into business operations. Shannon also advises on privacy and cybersecurity issues arising from emerging technologies, including generative AI and quantum computing.
A recognized thought leader, Shannon regularly speaks at industry events and trains corporate legal teams on AI regulation, governance, emerging risks and responsible innovation.

Polina Zvyagina

Director and Executive Counsel for AI and Data Governance, General Motors

Polina Zvyagina is Director and Executive Counsel for AI and Data Governance at General Motors, where she leads the design and operationalization of enterprise governance frameworks for responsible AI deployment across products, engineering, manufacturing, and corporate functions. Her work focuses on translating principles into practical operating models, risk assessments, policies, evaluation thresholds, human-oversight requirements, and lifecycle controls, including for agentic AI, embodied AI, robotics, and advanced manufacturing. She advises senior leaders on the intersection of innovation, safety, privacy, cybersecurity, regulatory strategy, and commercial adoption, with a particular focus on building governance that is embedded into product and industrial workflows through rigorous product-counseling.

Before joining GM, Polina was Director of AI Policy and Governance at Meta, where she built and led a global AI Policy organization, advised on the release of Llama models and other research systems, created Meta’s AI Policy Risk Matrix, and directed a developer responsibility framework that informed the company’s regulatory positioning. She has engaged with policymakers, regulators, and leading AI institutions worldwide, and has contributed to influential scholarship on foundation-model accountability, transparency, and liability allocation. Earlier in her career, she held senior privacy, product, and compliance roles at Airbnb, Uber, and Apple, building privacy-by-design programs, advising on global product expansion, and embedding law-enforcement compliance into global privacy programs. Across these roles, she has developed a reputation for combining legal rigor, policy fluency, and operational judgment to help organizations advance ambitious technology responsibly.

Location

Orrick Menlo Park, 1100 Marsh Rd, Menlo Park, CA 94025