Laura Ayre is a privacy and responsible AI leader working at the intersection of technology, governance, data sovereignty and organisational strategy. Her career spans telecommunications, entrepreneurship, privacy-enhancing technologies, open-source technology and international AI programmes, giving her a broad perspective on the human and technical dimensions of emerging technology.
Today, through her advisory work with Upper Harbour and experience at OpenMined, Ayre supports regulated AI and software teams with governance, strategic positioning, technology adoption and non-dilutive fundraising. Business Now spoke with Ayre about responsible AI, digital sovereignty, trust and how society can prepare as technology develops faster than institutions can adapt.
1. What experiences most shaped the leader you are today?
The discipline that has shaped my thinking came from anthropology; a field built on the conviction that what actually happened and what the evidence suggests happened are not always the same thing.
Forensic anthropology teaches you to examine what is actually present rather than what you expected to find. You have to account for who had the power to leave a record, whose story didn’t survive and how the evidence available to you may represent only a biased sample of a much larger reality.
That approach has become increasingly relevant to AI governance.
We are deploying AI systems at a pace that has no precedent in human technological history, while introducing them into institutions, communities and relationships that have evolved through thousands of years of gradual adaptation. The mismatch between technological development and human institutional adaptation is one of the defining governance challenges of this decade.
My years working with children reinforced that perspective. Child development is, in many respects, a useful analogy for reinforcement learning. A child explores an environment, receives feedback and gradually updates their understanding of how the world works. That process takes years because the developing human brain requires experience before sound judgment can emerge.
We would not place a child into a complex, high-stakes environment before they had developed the capacity to navigate it safely. Responsible AI requires a similar question: have the systems we are building been adequately prepared through training, testing and governance for the environments into. It is to close that gap with the same rigor that good science requires: examine evidence honestly, identify risks early and have which we are placing them?
Too often, the governance infrastructure hasn’t kept pace with the technology.
The answer isn’t to stop development. It is to close that gap with the same rigor that good science requires: examine evidence honestly, identify risks early and have the courage to say what you see before a problem becomes a crisis.
“Pattern recognition applied early, evidence examined honestly, and the courage to say what you see before the situation becomes a crisis—that is the methodology.”
2. What has been one of the biggest challenges you’ve faced?
The most complex professional challenges I’ve faced have involved multiple parties with legitimate but competing interests, high stakes if the process fails and no formal authority to compel agreement.
I’ve encountered that dynamic in international policy coordination, responsible AI deployment and coalition-building across civil society and technology communities.
The technology is rarely the hardest part. The human systems are.
One of the biggest lessons I’ve learned is that traditional stakeholder management doesn’t fully account for how people actually negotiate. We often assume that if we understand someone’s stated concerns and address them, we can reach agreement.
But people don’t always negotiate from their actual position. They negotiate from the position they can defend publicly.
The gap between those two positions is where many governance efforts break down.
Sustainable agreements require enough trust for people to explain their genuine constraints. That means creating relationships in which stakeholders feel they can be honest without immediately being pressured into alignment.
This lesson applies directly to international AI governance.

The EU AI Act, Canada’s evolving regulatory framework and the UK’s pro-innovation approach reflect different responses to common tensions: innovation versus precaution, competitiveness versus international alignment, and deployment speed versus governance depth.
Rather than asking which jurisdiction has the perfect model, I think we should be asking whether different jurisdictions can build enough trust to establish responsible pacing as a shared objective.
That requires understanding what other parties actually need, not simply trying to persuade them to adopt your preferred position.
“You don’t build trust by winning arguments. You build it by demonstrating, consistently, that you understand what the other party actually needs.”
3. What issue in responsible AI isn’t getting enough attention?
The AI governance conversation has focused heavily on regulation. Frameworks such as the EU AI Act, NIST AI RMF and GDPR are important, but regulation represents only one layer of the larger sovereignty question.
Digital sovereignty needs to be considered across three connected areas: infrastructure, procurement and strategy.
The infrastructure question is particularly important.
Organisations across Canada, the UK and the EU rely heavily on cloud infrastructure owned by a relatively small number of US-headquartered companies. The US CLOUD Act introduces an additional sovereignty consideration because US companies can potentially be compelled to provide data to US authorities regardless of where that data is physically stored.
This creates an important distinction: an organisation can be compliant with privacy regulation while still being dependent on infrastructure it does not fully control.
The second issue is procurement.
Every procurement decision is effectively an infrastructure decision. When organisations automatically choose incumbent vendors because they are familiar, inexpensive or easy to integrate, they are making long-term technology and sovereignty decisions.
Developing Canadian, European and UK alternatives shouldn’t necessarily be viewed through a protectionist lens. It can also be viewed as strategic investment in resilient infrastructure and long-term technological independence.
The third pillar is sovereign AI strategy.
Canada has an opportunity to occupy an important position between the EU’s rights-centred approach and the US innovation-first model. Its relationships and institutional credibility could allow it to act as a bridge between different approaches to AI governance.
But strategy needs to connect to infrastructure and procurement. Otherwise, sovereignty remains a policy aspiration rather than an operational capability.
There is also considerable potential for Canada, the EU and UK to collaborate around privacy, democratic governance and the rule of law. Shared values could provide the foundation for aligned procurement standards, infrastructure initiatives and AI governance.
The conversation therefore needs to move beyond regulation alone.
“The governance conversation needs to expand from regulation to the full stack: infrastructure, procurement and strategy together.”
4. What have you personally built or learned that has had a meaningful impact?
The most significant thing I’ve built isn’t on my resume.
Over the last several years, I navigated some very complex circumstances in my life. I’ll keep the specifics private because they belong to people other than me. What I can talk about is what those experiences taught me about resilience, meaning and continuing to build when you cannot see where the path leads.
For years, I thought resilience meant mastering uncertainty—eliminating it, predicting it or planning around it.
I eventually realised that resilience is something different.
It is the ability to keep taking action in the right direction without certainty about the outcome.
What sustained me during that period wasn’t professional achievement, although work continued. It was making things.
Creative work has a therapeutic dimension that I think our culture undervalues. When you create something with care and attention, you’re practicing agency. You’re making meaning rather than simply completing tasks or achieving goals.
That perspective feels particularly relevant as AI changes the nature of work.
AI will increasingly take on many of the time-consuming tasks that currently structure people’s working lives. When that happens, the important question won’t only be what happens to productivity or employment. It will also be what people do with their time and where they find meaning.
Creative pursuits, community connection and care for one another aren’t simply leisure activities. They are part of what gives human life identity and purpose.
For much of human history, meaning was embedded in community—through shared work, rituals and physical spaces. Modern life has already weakened many of those structures, and AI-driven efficiency could accelerate that trend if we aren’t deliberate about preserving them.
I believe building genuine, local and human communities may become increasingly important as technology becomes more capable.
I came through the last several years with a much stronger focus on what is real: the work that matters, the relationships that sustain us and the creative practices that keep us grounded.
“Resilience is the capacity to keep taking action in the right direction without certainty about the outcome.”
5. What advice would you give someone building a career at the intersection of AI, privacy and governance?
Don’t start with the technology.
Technical fluency is necessary, but it isn’t sufficient. In many cases, technical knowledge is actually the easier part to acquire.
What is harder—and more valuable—is the ability to understand human systems.
Learn why organisations behave the way they do. Learn to identify the difference between what stakeholders say they want and what they actually need. Learn to recognise whose perspective is missing from the evidence.
Every AI deployment challenge I’ve encountered has ultimately had a human-system problem underneath it.
There are also practical foundations for anyone entering this field.
Understand the regulatory landscape in your jurisdiction accurately. Don’t treat regulation as an abstract policy topic. Understand the obligations organisations actually face and how those requirements translate into operational decisions.
Then learn to understand sovereignty separately from regulation.
Knowing what a privacy regulation requires doesn’t necessarily tell you who can access the data, where your technology dependencies exist or how much control your organisation actually has.
Map both layers.
Most importantly, develop the patience to work between where institutions are and where they need to be.
The most important governance work isn’t always writing the framework. It is creating the trust that allows the framework to be implemented effectively.
That work can be slow and difficult to measure. It requires humility, listening and the willingness to remain engaged when there isn’t an immediate solution.
But that is where lasting change happens.
AI development will continue. The central question is whether the people and institutions responsible for governing it can develop the judgment, relationships and capacity to keep pace.
That is the work worth doing.
“Technical fluency is necessary but not sufficient. The harder skill is learning to read the human systems in which technology operates.”