

Most privacy vendors have shipped βAIβ. Almost none of it does the work. Breaking down the three categories of AI in privacy software today β chatbots, MCP servers, and multi-agent orchestration β gives privacy and GRC leaders a plain-English test for telling them apart. Because knowing your DPA is missing a required term and having that term fixed are two very different things.
Every privacy vendor has shipped AI. The press releases have been enthusiastic.
Here's what almost none of it does: the work.
The AI privacy compliance tools market is full of products, and most of them stop at telling you about a problem rather than closing it.
Knowing your Data Processing Agreement (DPA) is missing a required CCPA term is not compliance. Finding it matters. Fixing it is what compliance looks like. The distinction between a tool that tells you about a problem and a system that closes it is the entire difference between useful software and agentic privacy.
Letβs break down the capability hierarchy β chatbots, MCP servers, and multi-agent orchestration β and explain why only the last category can actually run a privacy program.
β
β
Not all "AI-powered privacy" tools are created equal. They fall into three distinct categories based on what they can and can't do, and specifically, whether they can reason across the three domains that define a real privacy program:Β
β
β
A chatbot is a conversational interface layered over a knowledge base. In privacy software, that knowledge base typically consists of your uploaded policy documents, regulatory summaries, and compliance templates.
Chatbots are genuinely useful for answering questions. They're fast, accessible, and better than searching a document repository. If you want to know whether your privacy policy mentions data retention, a chatbot will tell you in seconds.
What a chatbot cannot do: act. A chatbot is reactive by design. It responds when asked. It doesn't continuously monitor your systems. It doesn't detect when a configuration change creates a gap between your documented policy and your operational reality. It doesn't flag a new enforcement action against a retailer in your sector because nobody asked it to look. And it certainly doesn't execute a fix.
The honest test: upload all your documents to a general-purpose AI assistant and ask it your compliance questions. If the answer you get is functionally equivalent to what a privacy vendor's chatbot gives you, that chatbot isn't adding meaningful value. It's a familiar interface over a capability you already have.
Model Context Protocol (MCP) servers expose privacy tools β data access, policy retrieval, system queries β to AI agents and engineering workflows. They're valuable infrastructure. They make it possible for AI systems to interact with privacy data programmatically.
What MCP servers are not: a privacy program. An MCP server exposes tools. It doesn't orchestrate them. It doesn't reason across your regulatory environment, your policy documents, and your live configurations simultaneously. It doesn't decide which tool to invoke, in what order, with what inputs, to solve a specific privacy problem. That reasoning layer β the intelligence that turns tools into outcomes β isn't in the MCP server. It's in the team that builds workflows on top of it.
If closing a privacy gap requires your engineering team to build the workflow, you haven't automated the privacy work. You've given engineers more tools to build the automation themselves. That's progress. It's not an agentic privacy platform.
A multi-agent orchestration platform reasons across multiple data domains simultaneously β without waiting for a human prompt β and executes actions when it identifies changes that need to be made. This is categorically different from a chatbot or a copilot.
The difference isn't the sophistication of the AI. It's the scope of the reasoning, and where that reasoning happens.
Chatbots see what you show them. A multi-agent system is continuously ingesting your regulatory environment, your policy documents, and your operational system configurations β looking for daylight between them in the background, without being asked. It monitors. It prioritizes. It acts.
But you can still talk to it. The same interface you'd use to ask a question or run a quick analysis is the front door to a system doing considerably more on your behalf behind the scenes. On the surface, it feels like a conversation. Underneath, a network of agents is continuously reconciling your legal obligations, your stated policies, and your operational reality β surfacing gaps, flagging risks, and taking action on the ones it's been authorized to resolve.
One platform. Two modes of engagement: the conversation you initiate, and the work that's already in progress.
β

Before accepting a vendor's AI claim at face value, ask these three questions.
This is the continuous monitoring test. A system that finds gaps on demand is a search tool. A system that finds gaps continuously, the moment they emerge, is an agent.
If the answer is no, it's a chatbot or a dashboard. Both are useful. Neither is agentic.
This is the execution test. Detection without remediation is observation. A compliance report that lists gaps is better than nothing, but it still requires a human to read it, prioritize it, and take action. In an environment where the number of potential gaps exceeds the team's capacity to close them manually, observation-only tools create a backlog, not compliance.
If the answer is no, it's a monitoring tool. Better than a chatbot. Still not agentic.
This is the breadth test. Privacy risk lives in the gaps between domains, not within any single domain. A tool that analyzes your regulatory environment is useful but incomplete.
A tool that reviews your policy documents is useful but incomplete. A tool that audits your system configurations is useful but incomplete. The insight that matters β "your vendor DPA is missing required CCPA terms, which contradicts your stated policy, which violates your current California regulatory obligations" β requires all three domains in the same reasoning context.
β
"Knowing your DPA is missing a required term is not compliance. Finding it matters. Fixing it is what compliance looks like."
β
If the answer is that it sees one domain at a time, it's a point tool. It may be excellent at what it does. It cannot replace the work of reconciling across all three.
The data privacy software market has shipped a lot of AI in the past 18 months. Most of it falls squarely in Categories 1 and 2.
Chatbots layered over policy document repositories. MCP servers that let engineering teams build privacy workflows. AI-assisted assessment templates that still require humans to answer all the questions. Risk dashboards that display gap reports and wait for someone to act.
These are incremental improvements on manual processes. They're not wrong, they reduce effort, improve accessibility, and make information easier to find. But they leave the hardest work exactly where it was: with your team.
The gap that none of them close is the continuous reconciliation problem. What regulations require. What policies commit to. What systems actually do. The gap between those three things is where every enforcement action, demand letter, and regulatory finding lives. And as long as closing that gap requires a human to gather the context, prioritize the issues, cross-reference the obligations, and execute the fix, the hard work is still human work.
β
β
The Ketch Agent Network was built specifically for the reconciliation problem. It reasons continuously and simultaneously across all three domains: legal obligations, documented policies, and operational reality.
It doesn't wait for a prompt. It ingests enforcement actions as they're published, cross-references them against your current configurations and policy commitments, and flags the issues that apply to your program. It synthesizes your vendor DPAs, extracts the specific terms that are missing or outdated, and cites the regulatory requirement they violate. It auto-populates agentic risk assessment templates from live system data so your privacy team is reviewing an 80%-complete draft, not starting from blank.
β

β
When it finds a gap and your team approves the remediation, it executes the fix inside Ketch platform. The gap doesn't sit in a report.
That's not a chatbot. It's the difference between knowing your DPA is missing a required term and having that term added, reviewed, and documented.
β
β
Every AI agent your organization deploys creates new data processing activities. New sub-processor relationships. New consent questions. New DPIA obligations. New potential gaps between what your policies say and what your systems do.
The compliance surface area of an AI-powered enterprise is growing faster than any manual process can keep up with. The only viable response is a system that governs AI data at AI scale, one that continuously monitors, reasons across all three domains, and executes without waiting for a human to catch up.
The privacy vendors who shipped chatbots did something useful. They made information easier to find. They didn't answer the reconciliation problem, they made it more comfortable to sit with.
That problem is still open, and it's getting more expensive every quarter that enforcement accelerates.
The question for every privacy leader is not whether their vendor has AI. It's whether the AI their vendor shipped actually does the work, or just talks about it.
β