AI Risk Is Business Risk: Bridging Legal, Cybersecurity and the Boardroom
Download resourcesAbout this session
Atoussa Mahmoudpour, founder of AMR Law, walks a hypothetical Canadian company through the legal questions raised when a customer-service AI assistant scope-creeps from product manuals to old emails to an entire shared drive. She frames three overlapping but distinct questions: may we use this information this way (a privacy question about lawful basis), can we protect it while we use it (a security question about access and vendor controls), and when should we stop keeping it (a retention question). She walks through Canada's layered privacy regime (PIPEDA federally, distinct provincial laws in Quebec, Alberta and British Columbia), Quebec's privacy-impact-assessment requirement and its safeguard for decisions based exclusively on automated processing, and the still-unenacted Bill C-36 and Bill C-8. On vendors, she lists six negotiation questions (purpose, data flow, deletion, incident notice, exit, evidence) and warns that contract terms and actual configuration must match. On retention, she gives a three-question test (must we preserve it, do we still need it, has both ended) and distinguishes closing an account, deleting data and true anonymization, citing the Loblaw/PC Optimum finding. She closes on a four-step incident-response sequence and a take-home exercise, then takes two audience questions on fourth-party AI risk and data-labeling maturity.
When an organization adopts AI, who owns the risk—and who makes the decisions when something goes wrong?
Key takeaways
- Separate the three questions when approving an AI use case: may we use this data (privacy/lawful basis), can we protect it (security), and when must we stop keeping it (retention); one answer does not settle the others.
- Write approvals that name the specific documents, employees and data categories in scope, so that a later request to add more sources (like old customer emails) is visibly a new approval, not a silent expansion.
- Before signing an AI vendor, get clear answers on purpose of processing, data flow and subprocessors, deletion timelines, incident notice, exit rights and audit evidence; check that contract terms match the actual product configuration.
- Do not treat 'hosted in Canada' as equivalent to compliant; a transfer between provinces (Quebec to another province) can still trigger a Quebec assessment obligation.
- Apply a three-question retention test per record category (must we preserve it, do we still need it for a lawful purpose, have both ended) instead of picking one retention period for all AI data.
Speakers

Atoussa Mahmoudpour is the Founder and Principal of AMR Law, a woman-led business law firm focused on life sciences, technology and artificial intelligence. A corporate lawyer, entrepreneur and strategic adviser, she helps founders, boards and… Read moreRead less
Atoussa Mahmoudpour is the Founder and Principal of AMR Law, a woman-led business law firm focused on life sciences, technology and artificial intelligence. A corporate lawyer, entrepreneur and strategic adviser, she helps founders, boards and executive teams navigate growth, commercial partnerships and cross-border transactions.
Previously, Atoussa served as National Chair of Life Sciences and Technology at Cozen O’Connor Canada and as Chief Legal Officer and Chief Privacy Officer of WELL Health Technologies, where she led more than 65 acquisitions in under three years. Her approach combines international legal experience, executive-level judgment and a founder’s commercial perspective.
A four-time recipient of WXN’s Canada’s Most Powerful Women: Top 100 award and a 2025 Hall of Fame inductee, Atoussa is also Chair of the CBABC Health Law Section, a WXN ambassador and an advocate for women’s advancement. She is fluent in English, French and Farsi.

