AI Act · Roles and responsibility
As of 9 October 2026, after the Digital Omnibus
Do we need an AI officer?
The AI Act does not know an “AI officer”. Still, it requires in several places that specific people are responsible, trained and authorised. This page explains what the law actually requires, which tasks such a role can bundle and what matters when filling it.
Short answer
The AI Act contains no general obligation to appoint an AI officer. Unlike the data protection officer (Art. 37 GDPR), there is no duty to appoint and no threshold. The Regulation does require responsibilities, though: measures on AI literacy (Art. 4), human oversight of high-risk AI by competent and authorised people (Art. 26(2)) and, for providers, a quality management system that sets out responsibilities (Art. 17(1)(m)). Many companies therefore bundle these tasks in one role on a voluntary basis.
What the law requires
Responsibilities, not an appointment duty
These provisions require specific people or functions to be responsible. Which of them apply depends on the company’s role and on the risk of the AI system.
Art. 4 as amended
AI literacy
Providers and deployers take measures to support the development of AI literacy of their staff and other persons dealing with AI systems on their behalf. Applies to all AI systems, not only high-risk AI.
Art. 26(2)
Human oversight (deployers)
Deployers of high-risk AI systems assign human oversight to natural persons who have the necessary competence, training and authority, and give them the necessary support.
Art. 26(5)
Monitoring and reporting (deployers)
Deployers monitor the operation of high-risk AI systems on the basis of the instructions for use and inform providers and authorities of risks or serious incidents. This needs a responsible function in-house.
Art. 17(1)(m)
Responsibilities in the QMS (providers)
The quality management system of providers of high-risk AI includes an accountability framework setting out the responsibilities of management and other staff.
Art. 22(1), Art. 54(1)
Authorised representative (non-EU providers)
Providers established in third countries appoint, by written mandate, an authorised representative established in the Union before placing on the market, for high-risk AI systems (Art. 22) and for general-purpose AI models (Art. 54). This is an external function, not an internal officer.
The terms “AI officer” or “KI-Beauftragter” do not appear in the text of the Regulation. Using them describes a voluntary organisational decision. Application: Art. 4 since 2 February 2025; the high-risk obligations (Art. 17, 22, 26) from 2 December 2027 for AI under Annex III and from 2 August 2028 for AI under Annex I.
Tasks of the role
What an AI officer typically takes on
- Keep the AI inventory: which AI systems are in use, for what and by whom
- Classify risk: prohibited practices (Art. 5), high-risk (Art. 6, Annex III), transparency (Art. 50)
- Plan and document AI literacy measures (Art. 4)
- Name and support the people responsible for human oversight (Art. 26(2))
- Set internal rules, for example an AI policy for generative AI
- Review vendors and models, collect contracts and evidence
- Record incidents and know the reporting channels (Art. 26(5), Art. 73)
- Coordinate with data protection, information security and the works council
Comparison
AI officer and data protection officer
- Statutory duty to appoint?
- Data protection officerYes, under the conditions of Art. 37 GDPR (and national law, e.g. § 38 BDSG in Germany)
- AI officerNo, voluntary role
- Position regulated by law?
- Data protection officerYes, Art. 38 GDPR (independence, protection against dismissal for performing tasks)
- AI officerNo, defined by the company
- Tasks
- Data protection officerArt. 39 GDPR
- AI officerBundles obligations from Art. 4, 17, 26 AI Act depending on the role
- Can one person hold both roles?
- Data protection officerPossible if there is no conflict of interest (Art. 38(6) GDPR)
- AI officerPossible, check for conflicts of interest
If the data protection officer also takes on the AI role, they should not be responsible for AI deployments that they monitor as data protection officer.
Staffing
Who can take on the role
The law does not prescribe a fixed profile. What matters is that the person understands the AI systems in use, knows the obligations of the AI Act and has enough authority in the company to enforce decisions. For high-risk AI, Art. 26(2) explicitly requires competence, training and authority for human oversight.
In small companies this is often management, the head of IT or the data protection officer. Larger companies often set up a committee of IT, legal, data protection and business units with one coordinating person.
A certificate is not required by law. Training does, however, help to demonstrate the necessary competence in a traceable way.
Implementation
How SimpleAct supports the role
Art. 4, Art. 26
One place for all responsibilities
In SimpleAct, each AI system has its classification, obligations, responsible people and evidence. Every change is recorded in the audit trail.
Art. 4
Document training
The SimpleAct Academy and the training register record who was trained on which AI topic and when.
FAQ
Frequently asked questions about the AI officer
More questions? We're happy to help. Send email · Get started
Sources and status
As of · SimpleAct editorial team
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal
Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.
Make responsibilities clear
Record your AI systems, assign responsible people and keep training and evidence in one place. We will show you how this looks in SimpleAct.