Legal
Privacy Policy
Last updated: September 3, 2026
Introduction
Regulating AI (“we,” “our,” or “us”) is a non-partisan platform for policymakers, researchers, executives, and practitioners working at the intersection of artificial intelligence and public policy. We convene stakeholders, produce public interest content, host events and summits, operate the RegulatingAI Podcast, publish policy analysis and reports, maintain the AI Law Tracker and Capitol Connects programs, and provide access to PolicyOra, our AI policy intelligence platform built for CAIOs, compliance teams, and government officials.
This Privacy Policy applies to all personal information collected through our website (regulatingai.org), our community platform, our newsletter, our events and summits, our podcast and associated content distributed across YouTube, LinkedIn, Instagram, Facebook, and X (@RegulatingAI), and all other services and programs operated under the Regulating AI brand (collectively, “Services”).
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Services.
Data Controller
The data controller for personal information collected through the Services is:
Regulating AI
PO Box 407, Great Falls, VA 22066, USA
Email: info@regulatingai.org
Website: regulatingai.org
For questions about this Privacy Policy or your personal data, please contact us at info@regulatingai.org.
Information We Collect
We collect personal information across the following categories, depending on how you interact with the Services:
Information You Provide Directly
- Newsletter Registration: full name, work email address, and organization name, submitted when signing up for the weekly AI Policy Briefing or other Regulating AI newsletters.
- Community Platform Registration: name, work email, professional title, organization, areas of policy interest, and any profile information provided when joining the Regulating AI community platform.
- Event and Summit Registration: name, email address, job title, organization, country, dietary or accessibility requirements, and payment details for ticketed events and summits, including in-person and virtual formats.
- Expert Network Applications: professional biography, credentials, areas of AI governance expertise, institutional affiliation, geographic region, and CV or LinkedIn profile submitted when applying to join or be listed in the Regulating AI Expert Network.
- Advisory Board Participation: professional details and correspondence submitted in connection with Advisory Board membership and engagement.
- Podcast Guest Participation: name, title, organization, image, likeness, voice, and statements made during recorded podcast episodes.
- PolicyOra Access and Demo Requests: name, work email, job title, organization, and jurisdiction submitted when booking a PolicyOra demo or requesting platform access.
- Partner and Sponsor Inquiries: company name, contact name, email address, and inquiry details submitted through partner or sponsor contact forms.
- General Contact and Media Inquiries: name, organization, email address, and message content submitted through the contact form or directly to info@regulatingai.org.
Automatically Collected Data
- Website Usage Data: pages visited, content accessed, time spent, search queries, and interaction logs collected when you visit regulatingai.org.
- Device and Browser Data: IP address, browser type and version, operating system, device identifiers, and referring URLs.
- Cookies and Tracking Technologies: as described in Section 7 below.
- Third-Party Platform Analytics: aggregated and anonymized audience and engagement data provided by YouTube, LinkedIn, Instagram, Facebook, and X in connection with podcast episodes, videos, and content published on those platforms. We do not receive individually identifiable data from these platforms unless you contact us directly through them.
Information from Third Parties
- Single sign-on providers (such as LinkedIn or Google) where you choose to authenticate through those services to access the community platform or other gated content.
- Event co-organisers and venue partners who share limited registration or attendance data in connection with jointly hosted events and summits.
- Publicly available sources including government databases, regulatory repositories, and public professional profiles used for policy research and expert network verification.
Legal Bases for Processing (GDPR)
Where the General Data Protection Regulation (GDPR) or UK GDPR applies to your personal data, we rely on the following legal bases:
- Contractual Necessity: to process event registrations, community memberships, PolicyOra access requests, and expert network participation.
- Legitimate Interests: to operate and improve the Services, produce and distribute public interest content on AI governance, conduct outreach to policymakers and practitioners, and maintain the security and integrity of our platform, where these interests are not overridden by your fundamental rights.
- Consent: for newsletter subscriptions, marketing communications, non-essential cookies, and podcast recording and publication. Consent may be withdrawn at any time.
- Legal Obligation: where processing is required to comply with applicable law, tax obligations, or legal process.
How We Use Your Information
We use personal information for the following purposes:
- To operate and deliver the Services, including the community platform, newsletter, events, podcast, Expert Network, PolicyOra, AI Law Tracker, and Capitol Connects.
- To process event registrations, manage attendee logistics, and send event-related communications including confirmations, updates, and post-event materials.
- To produce, edit, publish, and distribute podcast episodes and related content across YouTube, LinkedIn, Instagram, Facebook, and X, including the name, title, image, likeness, voice, and statements of podcast guests.
- To send the weekly AI Policy Briefing and other newsletters to subscribers who have opted in.
- To respond to contact, partner, sponsor, media, and demo inquiries.
- To maintain and develop the Expert Network and Advisory Board.
- To provide access to PolicyOra and facilitate demo bookings and onboarding.
- To conduct policy research, produce reports, analysis, and thought leadership content using aggregated and anonymized data.
- To track AI legislation and regulatory developments for the AI Law Tracker and related publications.
- To improve and secure the Services and our website.
- To comply with applicable legal and regulatory obligations.
Disclosure of Your Information
We do not sell personal information. We may share information in the following circumstances:
Service Providers
We engage third-party processors including website hosting providers, email delivery platforms, event management and registration systems, payment processors, community platform infrastructure providers, podcast distribution services, and analytics tools. All processors are bound by data processing agreements and may only use data as directed by us.
Event and Summit Co-Organisers
Where events are co-hosted with third-party organisations, venue partners, or institutional co-sponsors, limited attendee registration and contact data may be shared with those partners solely for event logistics purposes. Such partners are required to handle data in accordance with applicable privacy law.
PolicyOra
Where you request access to or a demonstration of PolicyOra, your contact and professional information will be shared with the PolicyOra platform team, which operates under the Knowledge Networks group. PolicyOra’s handling of your data is governed by the PolicyOra Privacy Policy available at policyora.ai.
Podcast Distribution Platforms
Podcast content published to YouTube, Spotify, Apple Podcasts, LinkedIn, Instagram, Facebook, and X is subject to the terms of service and privacy policies of those platforms. Regulating AI is not responsible for the data practices of those platforms.
Legal Requirements
We may disclose personal information where required by law, court order, or governmental authority, or where necessary to protect the rights, property, or safety of Regulating AI, our users, or the public.
Organizational Transfers
In the event of a merger, acquisition, or transfer of Regulating AI’s operations, personal data may be transferred as part of that transaction with prior notice to affected individuals.
Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to support core functionality, understand how visitors engage with our content, and improve the user experience. The types of cookies we use include:
- Essential Cookies: necessary for the operation of the website. These cannot be disabled without affecting core functionality.
- Performance and Analytics Cookies: used to collect information about how visitors use regulatingai.org, including which pages are visited most frequently and how users navigate the site.
- Functional Cookies: enable enhanced features such as remembering your preferences and login status.
- Marketing Cookies: used, where consented, to understand the reach and effectiveness of our content and newsletter promotion.
You may manage cookie preferences through your browser settings or via our cookie consent interface. Disabling essential cookies may affect the functionality of the website.
International Data Transfers
Regulating AI operates primarily in the United States and engages a global audience across 40+ countries. Personal data may be transferred to and processed in the United States and in other countries where our service providers operate. Where transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other jurisdictions occur, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms as required by applicable law.
Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including to maintain community memberships, newsletter subscriptions, event records, and podcast archives, and to comply with applicable legal obligations. Specifically:
- Newsletter subscriber data is retained until you unsubscribe, after which it is deleted within 30 days.
- Event registration data is retained for a minimum of three years for compliance and record-keeping purposes.
- Podcast episode content, including guest names, titles, and recordings, is retained indefinitely as part of Regulating AI’s public interest archive.
- Community platform account data is retained for the duration of your membership and for a period of 12 months following account closure, after which it is deleted or anonymized.
You may request deletion of your personal data by contacting info@regulatingai.org, subject to applicable legal retention requirements.
Data Security
We implement appropriate technical and organizational measures to protect personal information against unauthorized access, loss, alteration, or disclosure. These measures include encryption of data in transit (TLS/SSL), access controls, authentication protocols, and regular security reviews. No method of electronic transmission or storage is entirely secure. In the event of a data breach likely to result in a risk to your rights, we will notify you and relevant authorities as required by applicable law.
Your Privacy Rights
GDPR Rights (EEA and UK Residents)
If you are located in the European Economic Area or the United Kingdom, you have the following rights with respect to your personal data:
- Right of Access: to obtain confirmation of whether we process your data and receive a copy of it.
- Right to Rectification: to request correction of inaccurate or incomplete data.
- Right to Erasure: to request deletion of your data where there is no compelling reason for continued processing.
- Right to Restriction: to request that we limit processing of your data in certain circumstances.
- Right to Data Portability: to receive your data in a structured, machine-readable format.
- Right to Object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: with the supervisory authority in your member state if you believe we have not adequately addressed your concerns.
CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: what personal information we collect, use, disclose, and whether we sell it.
- Right to Delete: to request deletion of personal information we hold about you.
- Right to Opt-Out: of the sale of personal information. We do not sell personal information.
- Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights.
Exercising Your Rights
To exercise any of the rights described above, please submit a written request to info@regulatingai.org. We will respond within the timeframe required by applicable law (typically 30 days under GDPR; 45 days under CCPA). We may require identity verification before processing your request. Requests for deletion of podcast content that constitutes a public interest archive record may not be fulfilled in full.
Children’s Privacy
The Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has submitted personal information, we will take steps to delete it promptly. Please contact info@regulatingai.org if you have concerns.
Third-Party Links and Platforms
The Services and our content may contain links to third-party websites, platforms, and resources, including YouTube, LinkedIn, Instagram, Facebook, X, Spotify, Apple Podcasts, and PolicyOra. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices or content of external platforms. We encourage you to review the privacy policies of any platform through which you access Regulating AI content.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, programs, or applicable law. We will notify you of material changes by posting the updated Policy on regulatingai.org with a revised effective date and, where appropriate, by email notification to registered members and newsletter subscribers. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
Contact Us
For questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact:
Regulating AI
PO Box 407, Great Falls, VA 22066, USA
Email: info@regulatingai.org
Website: regulatingai.org
EEA and UK residents who believe their concerns have not been adequately addressed have the right to lodge a complaint with the supervisory authority in their member state or with the UK Information Commissioner’s Office (ICO).