Three Days in Portsmouth: Notes from Navigate 2026

Notes from Navigate 2026 - Kate Colleary

It is not every week you find yourself watching Ghana play England in the World Cup with the Ghanaian English and Irish data regulators or eating lobster to the sound of a Scottish bagpipe procession in a New Hampshire seaport town. But Navigate is not a standard conference.

From 24 to 26 June, the IAPP and Harvard’s Berkman Klein Center for Internet & Society brought together regulators, policymakers, technologists, academics and practitioners from around the world for Navigate 2026: Digital Policy Leadership Summit in Portsmouth, New Hampshire. I attended in two capacities, as IAPP Country Leader for Ireland and on behalf of Pembroke Privacy, and I want to share some of what I took from it.

Navigate is a retreat rather than a conference and the discussions took place under the Chatham House Rule. That means I can share the ideas but not the details of who said what, and frankly, this rule is the reason the conversations were as candid as they were. When attendees don’t have to worry about headlines, you get a chance to hear what they actually think. So, what follows is a tour of the themes, not a transcript.

Ireland was well represented

While Ireland may not (sadly) have been represented at the FIFA World Cup which was being played in North America also, the Irish presence at Navigate was hard to miss. Representatives from the Data Protection Commission, Coimisiún na Meán and ComReg all took part together with Irish MEP Michael McNamara and attendees from industry and civil society. The three Irish regulators, covering data protection, online safety and media, and electronic communications took active part in the discussions with their international counterparts. 

This is where regulation is heading. If there was one message repeated across the three days, it was that the bodies that oversee privacy, content, competition, consumer protection and cybersecurity are increasingly working together and this is likely to continue. The Pembroke Privacy team is seeing this in practice with some of our global clients fielding queries from regulators who are joining forces and sharing resources. It has never been more important for organisations to have robust frameworks in place covering privacy, AI governance and other relevant digital laws and to have a consistent, clear message about how that framework operates internally as well as a suite of accountability documentation that can be shared fluidly across each regulator on request. 

From the printing press to the present

One of the opening sessions compared the emergence of AI to the invention of the printing press. Both technologies redistributed power, unsettled established institutions and had societal impacts. The early discussions also considered two practical problems:

  • How do you build industry oversight structures whose independence is real rather than decorative? And 
  • How do you make policy at the speed that this technology demands without making bad policy?

While there were no immediate, easy answers to the questions, what emerged was a view that progress depends on the hard work of building trust across institutional divides and that digital trust gets built the same way ordinary trust does: through relationships and transparency.

Geopolitics, in the room where it happens

As a politics (and Hamilton!) junkie, I enjoyed the discussions around AI sovereignty and geopolitics, which were highly topical as those conversations unfolded in the very hours that the US Supreme Court was preparing to deliver its decision in Trump v. Slaughter. Sitting in a room discussing the intersection of technology, power and institutions while one of the defining institutional questions on American governance was being decided a few hundred miles away was exciting. We were reminded that digital policy is not made in a vacuum. It is shaped, hour by hour, by political and constitutional currents.

The sovereignty discussions noted that global convergence on AI standards remains a distant prospect, and debates over digital sovereignty and competing values create real friction between jurisdictions, even between individual European states. The mood remained optimistic however, as the standards space was highlighted as an area where organisations could be assisted in developing frameworks with the emergence of appropriate standards.

Regulators talking to each other, and to industry

In several jurisdictions, collaboration across privacy, content, competition, cyber and consumer regulation is already well advanced, with dedicated cooperation structures maturing fast. Domestic coordination also needs structured engagement with industry, including newer supervisory techniques such as sectoral and problem-specific sandboxes.

Ireland now has its own constellation of digital regulators, including the DPC, Coimisiún na Meán, ComReg and the CCPC, and how they coordinate on AI as the EU AI Act obligations take effect will shape the compliance landscape for every organisation. The joined-up models discussed at Navigate offer a preview of what that supervision could look like.

Two points from these sessions deserve particular emphasis. The first is the call for genuine industry leadership. Regulation matters, but whether people feel any real agency over the apps and AI in their pockets is decided at the design stage, and the trade-offs made there need to be visible to regulators and the public alike. The second will resonate with every compliance team I have ever worked with: assessment tools such as DPIAs should be treated as diagnostic opportunities rather than compliance theatre. This is a drum we beat constantly at Pembroke Privacy. A DPIA done well highlights risk while there is still time to engineer it out. A DPIA done grudgingly is paperwork that protects nobody.

There was also serious discussion of how responsibility and liability are being mapped across increasingly complex AI supply chains. The question of who is liable when things go wrong, whether developer, deployer, integrator or user, is a complex one. For advisers like Pembroke Privacy, there is a good deal of hard work in this area anticipated over the next few years.

Running through many sessions was the familiar balancing act: anticipating and managing harms, particularly to children and vulnerable groups, without stifling innovation and adoption. It was also interesting to hear first-hand examples of regulators using AI in their own operations, from public engagement to caseload management. The regulators are innovating too.

Lobster, bagpipes and why the social bits matter

Which brings me back to the bagpipes. Navigate’s real value lies as much in its social activities as in its agenda. Some of the most useful conversations of my three days happened nowhere near a breakout room. They happened on the sidelines – like watching the football with the Ghanaian, English and Irish regulators, where I can report that regulatory cooperation survives even World Cup rivalry, the traditional early morning run/walk, and at a genuinely wonderful lobster bake that opened, improbably, with a Scottish bagpipe procession working its way through the crowd.

At Navigate, that’s part of the point. The relationships formed over a lobster and a laugh are the same relationships that, months later, make a cross-border query easier to resolve or an emerging best practice easier to share. Every serious discussion at Navigate kept arriving at the same conclusion: policy and regulation are necessary; but so is trust, which is built on human connection.

What organisations should take from Navigate

I left Portsmouth grateful to the IAPP and Harvard’s Berkman Klein Center for creating the forum, and with a clear sense of homework. For organisations, the practical messages are these:

  • Expect your regulators to talk to each other and prepare for supervision that crosses traditional boundaries. 
  • Treat DPIAs, AI impact assessments and governance frameworks as instruments that improve your products, not paperwork to be endured. 
  • Watch the liability question closely as AI supply chains grow more complex. And 
  • invest in the relationships, internal and external, through which trust is actually built.

These themes will shape our advisory and training work at Pembroke Privacy in the months ahead. The technology is moving fast. On the evidence of three days in Portsmouth, so is the community determined to govern it well.

Author
Facebook
Twitter
LinkedIn

Send an enquiry

Name
Newsletter Subscribe
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

Contact Details

Get in touch