Skip to content
SimpleAct Logo

AI Act · Roles and responsibility

As of 9 October 2026, after the Digital Omnibus

Do we need an AI officer?

The AI Act does not know an “AI officer”. Still, it requires in several places that specific people are responsible, trained and authorised. This page explains what the law actually requires, which tasks such a role can bundle and what matters when filling it.

Short answer

The AI Act contains no general obligation to appoint an AI officer. Unlike the data protection officer (Art. 37 GDPR), there is no duty to appoint and no threshold. The Regulation does require responsibilities, though: measures on AI literacy (Art. 4), human oversight of high-risk AI by competent and authorised people (Art. 26(2)) and, for providers, a quality management system that sets out responsibilities (Art. 17(1)(m)). Many companies therefore bundle these tasks in one role on a voluntary basis.

What the law requires

Responsibilities, not an appointment duty

These provisions require specific people or functions to be responsible. Which of them apply depends on the company’s role and on the risk of the AI system.

  • Art. 4 as amended

    AI literacy

    Providers and deployers take measures to support the development of AI literacy of their staff and other persons dealing with AI systems on their behalf. Applies to all AI systems, not only high-risk AI.

  • Art. 26(2)

    Human oversight (deployers)

    Deployers of high-risk AI systems assign human oversight to natural persons who have the necessary competence, training and authority, and give them the necessary support.

  • Art. 26(5)

    Monitoring and reporting (deployers)

    Deployers monitor the operation of high-risk AI systems on the basis of the instructions for use and inform providers and authorities of risks or serious incidents. This needs a responsible function in-house.

  • Art. 17(1)(m)

    Responsibilities in the QMS (providers)

    The quality management system of providers of high-risk AI includes an accountability framework setting out the responsibilities of management and other staff.

  • Art. 22(1), Art. 54(1)

    Authorised representative (non-EU providers)

    Providers established in third countries appoint, by written mandate, an authorised representative established in the Union before placing on the market, for high-risk AI systems (Art. 22) and for general-purpose AI models (Art. 54). This is an external function, not an internal officer.

The terms “AI officer” or “KI-Beauftragter” do not appear in the text of the Regulation. Using them describes a voluntary organisational decision. Application: Art. 4 since 2 February 2025; the high-risk obligations (Art. 17, 22, 26) from 2 December 2027 for AI under Annex III and from 2 August 2028 for AI under Annex I.

Tasks of the role

What an AI officer typically takes on

  • Keep the AI inventory: which AI systems are in use, for what and by whom
  • Classify risk: prohibited practices (Art. 5), high-risk (Art. 6, Annex III), transparency (Art. 50)
  • Plan and document AI literacy measures (Art. 4)
  • Name and support the people responsible for human oversight (Art. 26(2))
  • Set internal rules, for example an AI policy for generative AI
  • Review vendors and models, collect contracts and evidence
  • Record incidents and know the reporting channels (Art. 26(5), Art. 73)
  • Coordinate with data protection, information security and the works council

Comparison

AI officer and data protection officer

Statutory duty to appoint?
Data protection officerYes, under the conditions of Art. 37 GDPR (and national law, e.g. § 38 BDSG in Germany)
AI officerNo, voluntary role
Position regulated by law?
Data protection officerYes, Art. 38 GDPR (independence, protection against dismissal for performing tasks)
AI officerNo, defined by the company
Tasks
Data protection officerArt. 39 GDPR
AI officerBundles obligations from Art. 4, 17, 26 AI Act depending on the role
Can one person hold both roles?
Data protection officerPossible if there is no conflict of interest (Art. 38(6) GDPR)
AI officerPossible, check for conflicts of interest

If the data protection officer also takes on the AI role, they should not be responsible for AI deployments that they monitor as data protection officer.

Staffing

Who can take on the role

The law does not prescribe a fixed profile. What matters is that the person understands the AI systems in use, knows the obligations of the AI Act and has enough authority in the company to enforce decisions. For high-risk AI, Art. 26(2) explicitly requires competence, training and authority for human oversight.

In small companies this is often management, the head of IT or the data protection officer. Larger companies often set up a committee of IT, legal, data protection and business units with one coordinating person.

A certificate is not required by law. Training does, however, help to demonstrate the necessary competence in a traceable way.

Implementation

How SimpleAct supports the role

  • Art. 4, Art. 26

    One place for all responsibilities

    In SimpleAct, each AI system has its classification, obligations, responsible people and evidence. Every change is recorded in the audit trail.

  • Art. 4

    Document training

    The SimpleAct Academy and the training register record who was trained on which AI topic and when.

FAQ

Frequently asked questions about the AI officer

No. The AI Act contains no obligation to appoint an AI officer. It does require responsibilities, such as measures on AI literacy (Art. 4) and, for high-risk AI, human oversight by competent and authorised people (Art. 26(2)).
There is no threshold because there is no duty to appoint. Whether a dedicated role makes sense depends on how many AI systems are in use and whether high-risk AI is among them.
Yes, if this does not create a conflict of interest (Art. 38(6) GDPR). They should not be responsible for AI deployments that they monitor as data protection officer.
No, the law does not require a certificate. For high-risk AI, however, the people in charge of human oversight must have the necessary competence and training (Art. 26(2)). Documented training is the simplest evidence.
Providers from third countries must appoint, by written mandate, an authorised representative in the EU for high-risk AI systems and general-purpose AI models (Art. 22(1), Art. 54(1)). This is an external function with tasks set by law, not an internal AI officer.
There is no fine for not having an AI officer, because there is no duty to appoint one. If obligations such as human oversight under Art. 26 are not met, however, this falls under Art. 99(4)(e) (up to EUR 15 million or 3 % of worldwide annual turnover; for SMEs the lower amount applies, Art. 99(6)). These high-risk obligations apply from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.

Make responsibilities clear

Record your AI systems, assign responsible people and keep training and evidence in one place. We will show you how this looks in SimpleAct.