

DIFC Conference Centre, Du
December 8-9 2025

The #RISK GCC Agenda 2025
The agenda is here! Check out the agenda below.
DAY 1
December 8, 2025 | DIFC Conference Centre & DIFC Academy
AI Governance as an Innovation Enabler: A Framework for Accountable Growth
9:30 AM - 10:00 AM
The rapid adoption of Artificial Intelligence presents a profound duality for modern enterprises: the immense potential for innovation set against a complex new landscape of ethical, regulatory, and reputational risk. In this environment, many organizations view governance as a necessary brake on progress. This session argues for a paradigm shift: viewing robust AI governance not as an inhibitor, but as the essential foundation that builds trust and enables sustainable innovation. Akshay Dalalwill explore a practical framework for balancing accountability with agility. Attendees will learn how to operationalize ethical principles, embed responsibility throughout the AI lifecycle, and build an enabling governance program that fosters confidence, manages risk, and unlocks AI's true transformative potential.
Speakers:
- Akshay Dalal, Google
No More Secret Agents: Demanding Transparency in the Age of Autonomous AI
10:00 AM - 10:45 AM | Click to expand
As AI agents become more autonomous — making decisions, generating content, and even initiating actions — the need for transparency has never been more urgent. Who’s behind the output? What data is being used? What are the rules of engagement? This panel will examine the risks of “black box” AI agents operating without clear oversight, and the emerging calls from regulators, consumers, and industry leaders for greater disclosure, explainability, and traceability.
Moderator
- Douglas Clarence, Independent Consultant
Speakers:
- Dominic Baillie, Technology entrepreneur & AI Expert
- Renato Leite, VP - Privacy and Data Protection @ e&. Former Global Head of Privacy @ X / Twitter.
- Saravanan Thirumuruganathan, Associate Professor of Practice, Computer Science, Mohamed bin Zayed University of Artificial Intelligence
Coffee Break
10:45 AM - 11:00 AM | Click to expand
Check out our amazing exhibitors and grab yourself a cup of coffee to reflect on this mornings sessions!
Data Protection Laws 2.0: A New Era for Compliance and Accountability
11:00 AM - 11:45 AM | Click to expand
With data privacy regulations undergoing sweeping changes across the GCC and beyond, businesses are facing a renewed mandate to reassess their data governance frameworks from the ground up. This panel explores the latest iterations of data protection laws in key jurisdictions, examining how shifts in enforcement, cross-border data transfer rules, and individual rights are reshaping compliance strategies. Legal and data privacy experts will discuss what "starting over" really means—whether it's building privacy programs from scratch or overhauling legacy systems—and share practical guidance on aligning with evolving regulatory expectations. If your organisation touches personal data, this session is essential.
Moderator
- Stevan Stanojevic, Director, PrivacyOneStop
Speakers
- Don O'Shaughnessy, Founder of DGPP
- Charmian Aw, Partner, Hogan Lovells Lee & Lee
- Mabs Ahmed, Data Protection and AI Governance leader
- Nicholai Pfeiffer, Managing Partner at White Label Consultancy
Strengthening Supply Chain Resilience in the Middle East
11:45 AM - 12:30 PM | Click to expand
The Gulf region is a hub for global trade and logistics, but supply chains remain vulnerable to geopolitical tensions, regional conflicts, and international trade disruptions. This session will explore strategies for building resilient supply chains in the GCC, including risk identification, contingency planning, and leveraging technology to maintain operational continuity. Participants will share insights on best practices for managing supplier and partner risks specific to the Middle East context.
Speakers
- Talal Darras, Strategic Risk Consulting Leader, International and IMEA, Marsh
- Arjun Manoharan, Commercial Head at Shory Insurance Brokers
- Sabrine Makkes, LLM, Esq. Attorney At Law
Advancing Risk Management with AI-Powered GRC
12:30 PM - 13:00 PM
As organizations across the Middle East navigate rapid transformation, evolving regulations, and increasing cyber and operational risks, modernizing risk management has never been more critical. In this session, discover how regional and global leaders are moving beyond manual spreadsheets to adopt AI-powered GRC solutions that deliver greater efficiency, accuracy, and strategic value.
Learn how Diligent’s integrated platform streamlines core risk processes, enhances real-time reporting, and enables benchmarking against industry peers. We’ll explore how AI can surface meaningful insights, strengthen governance, and support more confident, risk-informed decision-making—empowering organizations to elevate their ERM maturity and stay ahead in a dynamic risk landscape.
Speakers:
- Jay Cameron, Diligent, Senior Director, Product Marketing
- Tom Faraday, Diligent, Vice President, Product Management
Lunch
13:00 PM - 14:00 PM
Generative AI in GRC: Balancing Opportunity and Oversight
14:00 PM - 14:30 PM | Click to expand
As Generative AI reshapes how organisations create, process, and govern information across the enterprise, GRC professionals face a dual challenge: harness its innovative potential while managing associated risks and regulatory responsibilities. This session brings together industry leaders to explore:
Emerging Use Cases: How Generative AI is being deployed in areas like compliance automation, risk modeling, and decision support.
Risk Landscape: Understanding threats such as misinformation, bias, intellectual property exposure, and cascading errors.
Ethical & Regulatory Frameworks: Review current regional and global frameworks
Strategic Integration: Practical guidance on embedding Generative AI into GRC programs while ensuring oversight, transparency, and auditability.
Moderator
- Magdalena Konig, General Counsel for AIQ
Speakers
- Kelly Forbes, AI Asia Pacific Institute
- Ghassan Zeidan, Founder and CEO, Paragon Consulting Partners
Learning from the Mistakes of Others: How the GCC Can Get Digital Governance Right
14:30 PM - 15:00 PM
Around the world, digital laws are emerging at speed across privacy, AI, cybersecurity, online safety, competition and interoperability. Yet the system lacks coherence, with piecemeal rules leading to conflicting requirements, uneven expectations and growing burdens on regulators, organisations and citizens alike.
Drawing on the Centre for Information Policy Leadership’s comparative insights and research on accountable data and AI governance, this session distils what has and has not worked elsewhere. It highlights the pitfalls the GCC can avoid as digital transformation accelerates, and sets out a coherent model for governance frameworks that support trust, innovation and effective risk management from the outset.
Speaker
- Stephen Almond, Vice President of Policy and Consulting, CIPL, Hunton Andrews Kurth (UK) LLP
Growing Up Online: Children's Data and Digital Safety in the GCC
15:15 PM - 15:45 PM | Click to Expand
As children across the GCC spend more time online — learning, socializing, and playing — the need to protect their personal data and digital well-being has become urgent. With emerging national data protection laws and evolving global standards like the UK’s Age-Appropriate Design Code and the EU's GDPR, the region faces important questions: What does meaningful online safety look like for minors? Who is responsible for enforcing it? And how can tech companies, regulators, and parents work together to create safer digital spaces?
Moderator
- Dino Wilkinson, Partner | Commercial, Tech & Transactions | Data & Cyber | IP, Baker & McKenzie LLP
Speakers:
- Salma Syed, Data Protection Manager, Office of the Commissioner of Data Protection, DIFC
- Maryam Ehsani, Founder & CEO, Child Safe ME
- Masha Ooijevaar, Legal Director, CMS
- Hamza Saghir, Head of Privacy & AI Trust Leader, KPMG Middle East
Our Moment: The evolution and revolution of personal data in the future of today
15:45 PM - 16:15 PM | Click to Expand
Speaker:
- Michael Clark, Data Scholar, Industry Advisor, and Innovation Evangelist
Evening Reception Sponsored by Meta
16:15 PM - 17:00 PM
DAY 2
December 9, 2025 | DIFC Conference Centre & DIFC Academy
People at the Center: Managing Talent, Health, and Transformation Risk
9:15 AM - 10:00 AM
Moderator
- Thenji Moyo, Partner, Gateley Middle East
Speakers
- Sophie Best, CEO, Knowledge Nexus
- Deepali Patil, Chief People Officer, SAIL Legal
- Douglas Clarence, Independent Consultant
- Simona Musat, Mercer Marsh Benefits Multinational Leader- UAE, Marsh
Regulation 10 in Focus: Certification and Enforcement in the DIFC Data Protection Regime
10:00 AM - 10:45 AM | Click to expand
Moderator
- Raza Rizvi, Partner, Simmons & Simmons Middle East LLP
Speakers:
- Tahir Latif, Expert Regulatory Advisor - Responsible AI and Data Privacy
- Federico Marengo, Associate Partner, White Label Consultancy
- Khaled Shivji, CEO - Exec X AI (DIFC) & S.AI.L
Coffee Break
10:45 AM - 11:00 AM | Click to expand
Check out our amazing exhibitors and grab yourself a cup of coffee to reflect on this mornings sessions!
Know Your Importer: Rethinking Trust in Cross-Border Data Sharing, The Role of Multilateral Frameworks and the Rise of the RDM Consortium
11:00 AM - 11:30 AM | Click to expand
As data flows across borders at unprecedented scale, governments and businesses alike face a pressing question: Who are you sharing data with — and can they be trusted? In response to mounting concerns over surveillance, data misuse, and regulatory divergence, new multilateral frameworks are emerging to rebuild trust. At the forefront is the RDM Consortium, a new initiative focused on Responsible Data Management in international data transfers.
This panel will unpack:
- The strategic goals and implications of the RDM Consortium
- How "Know Your Importer" principles mirror financial KYC frameworks
- The shifting global landscape post-GDPR, CLOUD Act, and regional data localization laws
- What this means for GCC countries navigating between economic openness and digital sovereignty
Speakers:
- Lori Baker, Vice President – Data Protection & Regulatory Compliance, DIFC
- Omid Mahboubi, Founder, MENA Cloud Alliance
Climate Resilience and Catastrophe Risk: Preparing for the Next Disruption
11:30 PM - 11:50 PM | Click to expand
Speaker:
- Ernest Eng, Head of Analytics, Risk Finance & Captives, IMEA, Marsh
Autonomous Systems Officers & DPOs: The Front Line of AI Governance
11:50 AM - 12:30 PM
As AI systems become more autonomous, complex, and integrated into everyday operations, organizations need more than policies — they need people with the authority, skills, and oversight to put responsible AI into practice. Enter the Autonomous Systems Officer (ASO) — an emerging role that complements or extends the responsibilities of the Data Protection Officer (DPO).
This panel explores how AI governance is shifting from principles to implementation, and why roles like ASOs and DPOs are becoming critical to bridging the gap between legal, technical, and operational teams.
Moderator:
- Stevan Stanojevic, Director, PrivacyOneStop
Speakers:
- Federico Marengo, Associate Partner at White Label Consultancy
- Muneeb Imran Shaikh, Data Privacy, Cybersecurity & AI Governance Expert
- Stephen Priestly, Director - Data Protection, Group Legal and Compliance
Privacy as a Competitive Advantage: The GCC Opportunity
12:30 AM - 13:00 PM | Click to expand
Speakers:
- Renato Leite, VP - Privacy and Data Protection @ e&. Former Global Head of Privacy @ X / Twitter
Lunch
13:00 PM - 14:00 PM | Click to expand
Humans, Machines and Data: Building Trust and Accountability in the Age of Responsible AI
14:00 PM - 14: 45 PM
As we move beyond the ‘FOMO’ stage of AI adoption, and as artificial intelligence becomes embedded in decision-making, the relationship between humans, machines and data is being redefined. This panel explores how organisations can transform their digital and AI capabilities in a manner that is no just effective, but ethical, explainable and compliant. Drawing on perspectives from human behaviour, data privacy and governance, our speakers will examine how to balance innovation with accountability — ensuring that data remains lawful, machines remain transparent, and humans remain in control.
From privacy-by-design to AI governance frameworks, from cultural readiness to regulatory oversight, this session will offer practical insights for governance professionals seeking to embed trust at the heart of their AI strategy — particularly within the fast-evolving GCC regulatory landscape.
Key discussion points:
- Trust and Transparency: How do we ensure human understanding and oversight when machines make complex or automated decisions?
- Privacy-by-Design meets Responsible-AI-by-Design: Where do data-protection principles converge with AI ethics and governance?
- Human vs Machine Accountability: Who is ultimately responsible when AI systems act on personal or sensitive data?
- The Data Dimension: Managing data, consent, and cross-border flows under evolving GCC privacy frameworks (UAE PDPL, DIFC DP Law 2020, Saudi PDPL).
- Governance and Controls: How can GRC, privacy and internal audit functions collaborate to assure responsible use of AI?
- Culture and Capability: What behaviours, mindsets and skills are needed for effective human–machine collaboration?
- Looking Ahead: How will the role of data-privacy and governance professionals evolve as AI regulation matures in the region?
Moderator
- Michael Lucas, BRAVE Pioneer
Speakers
- Carolyn Clarke, Non-Executive Director and VP of the Institute of Internal Auditors and a Partner at BRAVE
- Renato Leite, VP - Privacy and Data Protection @ e&. Former Global Head of Privacy @ X / Twitter
- Rachel Linhares, Brave Architect
- Gaia Camillieri, former Executive Director at Standard Chartered
Global Shifts, Regional Impact: Managing Geopolitical Risk
14:45 PM - 15:30 PM
The Gulf region plays a pivotal role in global trade, energy, and finance, leaving businesses particularly exposed to geopolitical shifts. This session will explore strategies for identifying, assessing, and mitigating geopolitical risks that could disrupt operations, supply chains, and strategic decision-making. Delegates will share insights on scenario planning, risk monitoring, and building organisational resilience in a dynamic international landscape.
Moderator
- Kelly Forbes, AI Asia Pacific Institute
Speakers
- Mubin Kozandagi, Senior Risk and Resilience Professional, Marsh
- Emna Krichene, Privacy Policy Manager, Meta
- Hamza Saghir, Head of Privacy & AI Trust Leader, KPMG Middle East
Careers in AI Governance: What You Need to Know — and How to Get There
15:30 PM - 16:15 PM | Click to expand
As AI reshapes industries and societies, a new field is rapidly emerging at the intersection of technology, ethics, law, and policy: AI governance. But what does a career in this space actually look like? What skills are in demand, who’s hiring, and how do you break in — whether you're coming from law, tech, academia, or something entirely different?
Moderator:
- Douglas Clarence, Independent Consultant
Speaker:
- Kelly Forbes, AI Asia Pacific Institute
- Muneeb Imran Shaikh, Data Privacy, Cybersecurity & AI Governance Expert
- Manzoor Khan, Professor of Practice, Computer Science, Mohamed bin Zayed University of Artificial Intelligence


