From Berlin to Hong Kong and Washington, conversations around AI are moving beyond data protection... From Berlin to Hong Kong and Washington, conversations around AI are moving beyond data protection toward a larger question: how much of ourselves should we have to reveal in order to participate in the digital world?
September 2026 has brought several important international discussions around artificial intelligence, privacy and digital identity.
On 29–30 September, the Privacy Conference 2026 in Berlin brings together regulators, companies, academics and technology experts under the theme of “next-generation privacy.” Its programme connects AI governance with GDPR, the EU AI Act, risk reduction, digital confidence and the practical challenge of building trusted AI at scale.
Just days earlier, the Asian Privacy Scholars Network conference in Hong Kong focused on Privacy and Data Protection in the Age of Intelligent Systems. Its discussions extended beyond conventional data security to questions of AI governance, human vulnerability, data sovereignty and whether existing privacy frameworks remain sufficient for intelligent systems.
And on 24 September in Washington, D.C., the Internet Governance Project's “Identity Online” workshop approached the problem from another direction: digital identifiers and trust.
The questions are becoming increasingly fundamental.
Are we interacting with a person, a bot or a synthetic representation? How should identity be verified? Who controls the infrastructure through which identity is established? And how much personal information should someone have to disclose simply to prove that they can be trusted?
These discussions point toward an important shift.
For years, digital privacy has largely been discussed in terms of data protection: what information is collected, where it is stored, who can access it and whether consent has been obtained.
AI introduces another layer:
The privacy of presence itself.
As AI-generated faces, voices, avatars and synthetic identities become increasingly capable, the question is no longer only how to protect the data behind a person.
We also need to ask how that person chooses to appear.
This distinction matters.
An AI avatar can create new privacy risks when someone's face, voice or likeness is replicated without meaningful consent. Discussions around AI avatars and content provenance have already highlighted the importance of transparency, consent, control and protection against unauthorized replication.
But the same technology invites another possibility.
What if an AI identity is created deliberately not to expose the private individual behind it?
A person could remain professionally present, communicate knowledge, speak multiple languages and participate in digital environments without automatically revealing every element of their physical identity, location or private life.
This is the direction I describe as Privacy-First AI Identity.
It does not mean anonymity by default, nor does it mean hiding from accountability. It means designing digital presence around purpose, consent and controlled disclosure.
This is precisely the space we are exploring at ONLINEDelux.
Our work on Privacy-First AI Identity starts from a different question: instead of asking only how to protect personal information after it enters a digital system, can we design the person's digital presence to disclose less in the first place?
A Custom AI Avatar can become more than a synthetic face. Properly designed, it can function as a controlled interface between a private individual and the public digital world.
Our AI Avatar Identity Passport develops this idea further: a defined AI identity created for a specific role, with its own visual identity, voice and communication function — without requiring the private individual behind it to become the public product.
The principle is simple:
Presence without unnecessary exposure.
The international discussions taking place this September approach the problem from different directions — regulation, data protection, governance, digital identifiers and trust.
Together, they raise a question that deserves a place alongside the discussion of AI regulation:
Not only “How do we protect our data?” But “How much of ourselves should we have to reveal at all?”
Dr. Yulia B. · Founder, Onlinedelux
Sources & current discussions
Privacy Conference 2026 — Berlin, 29–30 September 2026
Official conference page
Asian Privacy Scholars Network — Privacy and Data Protection in the Age of Intelligent Systems — Hong Kong, 23–25 September 2026
Official conference page
Identity Online: Shaping Governance Through Digital Identifiers — Washington, D.C., 24 September 2026
Official workshop page
Top comments (0)