
Who Controls AI? Governance and Privacy with Francesc Aguilera
Who decides what we allow artificial intelligence to do? In this episode of the Torras AI Podcast, I speak with Francesc Aguilera, manager of AI governance and privacy at one of Europe's leading financial institutions. We discuss how organizations can put AI to work while protecting data, choosing acceptable risks, and keeping people accountable for decisions.
Francesc brings three decades of experience in large organizations and a technical background that grew into work on data governance, privacy, and AI. His perspective connects the technology with the people and processes that determine whether it delivers value. The conversation is in Catalan. A summary of the conversation appears below.
Watch the conversation
Highlights from the conversation
Curiosity connects technology with the business
Francesc began in computing and became curious about how large companies actually worked. An MBA helped him understand their mechanics, while project roles taught him to translate business needs into technical requirements. That combination of curiosity and the ability to speak both languages eventually took him into big data, privacy, and AI governance.
He describes a large organization as something like a living organism. Moving between roles can feel like changing companies, with new problems to understand and new people to learn from. His career is a reminder that understanding an organization is an ongoing part of working with its technology.
AI governance begins with deciding what to do
Francesc gives governance a broad scope. It includes selecting the uses of AI that support the company's strategy, deciding which risks are acceptable, identifying and mitigating those risks, and building the knowledge employees need to use the technology well.
For example, an organization may decide that a particular system can make recommendations while a person retains the final decision. That boundary is a governance choice. So is the decision to pursue one application and leave another aside. These choices belong in the everyday work of business teams, developers, and the people who use AI.
Governance earns its place by adding value
When I ask how governance can help innovation without becoming bureaucracy, Francesc's answer is direct: the governance team needs to contribute something useful. Getting involved as an idea develops makes it possible to spot risks, clarify requirements, and help the team build a system it can trust.
He points to confidence as a central contribution: confidence that a system meets the organization's standards and ethical commitments as well as its legal obligations. We also discuss the NIST AI Risk Management Framework, a voluntary framework for incorporating trustworthiness into the design, development, use, and evaluation of AI systems.
From personal productivity to redesigning processes
Francesc distinguishes several stages of adoption. An employee first uses AI to do familiar work faster or better. A team then inserts AI into an existing process. A further step is to reconsider the entire process and ask how it should work with AI available from the beginning.
He discusses fraud prevention, cybersecurity, and anti-money-laundering work as examples of areas receiving attention in financial services. The broader opportunity, in his view, is to combine knowledge of business processes with knowledge of AI. Some steps may become faster; others may no longer be necessary. Understanding the whole process helps determine which changes are useful.
Before sharing data with AI, ask whether it is needed
The first privacy question Francesc proposes is simple: does the system need this information? Could the task be completed with less data, or with information that does not identify a person? Giving a model everything available should not be the default.
We discuss data minimization, the purpose of processing, and the importance of reviewing how personal information will be used. The European Commission's explanation of the GDPR principles provides useful background on these topics.
Francesc also emphasizes classification and metadata. A system needs usable information about which data is personal, internal, or confidential if the organization expects different handling rules to apply. That connects AI governance with the work data teams have been doing for years.
Choose autonomy deliberately and keep responsibility visible
An assistant that drafts an email and an agent that sends it create different consequences. Francesc frames the choice in terms of benefits and acceptable risks. His personal preference today is to use AI to prepare work, check information, and verify results while retaining human control over consequential actions.
Our discussion of responsibility raises difficult questions about who built, adapted, deployed, and used a system, and how to establish a connection between its actions and a harmful outcome. We explore those questions without treating them as settled. Saying that an AI acted on its own does not explain the permissions, instructions, and decisions that made its actions possible.
Keep human judgment when a system sounds human
The conversation also turns to our tendency to attribute human qualities to systems that communicate fluently. Francesc cautions against assuming that today's AI has human judgment or a social conscience. We briefly explore speculative questions about consciousness, while keeping the practical discussion focused on the systems people are using now.
I compare conventional software to driving a car and working with AI to riding a horse: steering does not always produce the same predictable response. The analogy leads us back to the need to understand a system's limits and to think carefully about the actions we allow it to take.
Surf the wave by choosing problems worth solving
Francesc sees the speed and reach of this technology as a defining difference from earlier waves. New capabilities arrive directly in people's hands, putting pressure on organizations to make choices quickly. He compares the challenge to surfing: timing, direction, and judgment determine whether the wave carries you forward.
Large organizations can generate an enormous number of ideas. Selecting among them starts with asking what problem each idea solves and what value it could create. Costs belong in that assessment too. We discuss tokens as a real operating expense and the importance of choosing a model that is sufficient for the task, rather than assuming every application needs the most capable option.
Connect with Francesc Aguilera
Francesc recommends LinkedIn as the easiest way to reach him. Thank you, Francesc, for sharing your experience and helping make AI governance concrete: choosing useful work, understanding the data, and deciding where human judgment belongs.





