KlarComply
HomeKnowledge › Appointing an AI lead

Appointing an AI lead — the first question on every questionnaire

“Who is responsible for AI in your organisation?” When a supplier questionnaire arrives, that question tends to sit near the top — and it is the one you cannot produce at short notice. This page sets out who to appoint, what the role really covers — and what it expressly is not.

By , Founder of KlarComply · Reviewed on

Infographic: Appointing an AI officer: a name, not a title cult — The EU AI Act does not require an “AI officer” — but without a named person, nobody is in charge.
The key points of this article as a graphic — feel free to share or download it.

Is there a legal duty to appoint anyone?

No. That belongs at the top, because a good deal of anxiety is sold at this exact point. The AI Act contains no counterpart to Article 37 GDPR, which requires a data protection officer in defined circumstances. There is no headcount threshold at which an “AI officer” must be appointed, no notification to any authority, and no prescribed qualification.

Anyone selling you a certificate on the basis that a missing AI officer exposes you to a fine is arguing past the law. That fine does not exist. Article 99 lists the penalised obligations exhaustively, and none of them concerns an appointment.

Why the role is still needed in every company

The duties in the regulation fall on the company. A company cannot do anything, though — people do things. Without a named person, what usually happens is exactly nothing. Everyone assumes somebody else is dealing with it.

There is also a practical trigger. Business customers now ask for the role as a matter of routine. Ticking “not appointed” rarely loses you the contract outright, but it starts a round of follow-up questions that costs three weeks.

A note if you are established outside the EU

Article 2 sets the scope of the AI Act by effect rather than by registered office. It reaches providers placing AI systems on the EU market wherever they are established, deployers located in the Union, and providers and deployers in a third country where the output produced by the AI system is used in the Union. A firm in London, Dublin, Zurich or New York whose AI output lands in the EU is in scope for that activity.

That has one consequence for this role and one only: whoever you appoint needs to know which of your activities produce output used in the Union, because those are the ones the transparency and literacy duties attach to. It is a column in your register, not a second job. There is a separate matter — the authorised representative under Article 22 — but that duty falls on providers placing systems on the EU market, not on ordinary deployers.

Who should take the role

The common assumption that this has to be someone from IT is misleading. Ninety per cent of the work is organisational: asking, recording, deciding, reminding. Technical depth is not required. Access to the management is.

CandidateIn favourAgainst
A director, in firms up to about twenty peopleDecision-making authority already there, no approval loopsThe time budget is almost always overestimated and the task gets displaced by operational work
Executive assistant to the managementSees every part of the business, has a short route upwards, documents things anywayNeeds express authority to decide, or every approval sits waiting
Head of ITKnows the system landscape, most likely to spot shadow AITends towards a purely technical view; other departments feel policed
Quality managementThinks in processes, documentation is daily businessOften does not exist below fifty employees
Data protection officerClosest subject-matter fit, already knows the records and the contractsPossible conflict of interest where the officer is internal — see below

The conflict with the data protection officer

Putting both roles in one pair of hands is an obvious move. It is permissible, but not without care. Under Article 38(6) GDPR the data protection officer performs a monitoring function and must not take on tasks that give rise to a conflict of interests. Someone who approves AI tools themselves then goes on to review their own decision.

The clean split: the AI lead decides on approvals. The data protection officer is consulted before each approval and may object. Two people, one decision, recorded so the reasoning is visible afterwards. Where the data protection officer is external, the dual role is usually unproblematic, because no operational approval authority sits there in the first place.

What the role covers — eight tasks

This list belongs in the letter of appointment more or less verbatim. It is also the answer to the follow-up question “what does that person actually do?”, which almost always arrives with the questionnaire.

  1. Maintain the AI inventory. Which tools, which purpose, which data, which risk class. None of the other tasks is possible without this register — see building an AI inventory.
  2. Decide on new tools. Receive requests, assess them, approve or refuse, each with a short reason and a date.
  3. Classify risk and record the reasoning. The reasoning is the evidence, not the class.
  4. Commission and record training. Basic training, an annual refresher, onboarding for new joiners.
  5. Watch the labelling. Check that chatbots, AI images and synthetic voices carry a disclosure where one is required.
  6. Be the contact point for incidents. Anyone who has put customer data into a public tool by accident reports it here — and does so without consequence.
  7. Track the legal position. Twenty minutes a quarter is enough once you know where to look.
  8. Answer questions. From business customers, auditors, employee representatives, and if it ever comes to it, from a market surveillance authority.

What the role expressly is not

This boundary decides whether anyone accepts the job. Without it, the appointment reads as a liability trap, and it is not one.

The time cost, quantified honestly

For a company that uses AI rather than builds it:

SizeInitial set-upOngoing, per month
Up to 20 employeeshalf a day1 to 2 hours
20 to 100one to two days2 to 6 hours
100 to 250three to five days6 to 12 hours, often split between two people

The largest item in the initial set-up is not writing documents. It is the stocktake: finding out what is genuinely in use. Skip that part and you save a day, then document an inventory that is wrong.

The letter of appointment — six components

One page is enough. It only gets longer when somebody copies a template written for a listed group.

  1. Name, function, effective date.
  2. List of duties — the eight points above, shortened if you like, but not replaced by “and all related matters”.
  3. Authority. Without this paragraph the appointment is worthless: a right to information from every department, the right to approve and block tools, and direct access to the management.
  4. Time budget. A number, not a statement of intent. “Up to four hours a month, more by agreement where needed” is a number.
  5. Deputy. A second person, by name. Holiday and illness are the most common reason processes quietly stop.
  6. Signatures from the management and the appointed person, with the date.

Wording for the authority paragraph

“For the performance of these duties, [name] is entitled to obtain information from every department, to approve or block AI tools, and to raise matters directly with the management. A time budget of up to [number] hours per month is made available for the role. The duties of the management under applicable company law remain unaffected.”

The last sentence is not decoration. It makes clear that nobody is being pushed into the directors' own duty of care — and it makes it considerably easier for someone to say yes.

Outsourcing the role: when it is worth it

Providers exist who will take the role externally, much as they do for data protection. An honest assessment: for companies under a hundred people that only use AI, this is usually oversized. The task depends on knowing your own house. Someone who sees which tools keep appearing in marketing will find shadow AI; an external provider on a quarterly call will not.

External support earns its keep in three situations: high-risk systems in use, in-house AI development that puts you in the provider role, or a corporate customer who insists on independent confirmation. In every other case the combination of an internal person and a good external reference source is cheaper and works better.

The first thirty days after the appointment

  1. Days 1 to 3: sign the letter and announce it, on the intranet or by email to everyone. A role nobody has heard of receives no reports.
  2. Week 1: start the stocktake — ask departments individually, with an express amnesty. Details on shadow AI in the workplace.
  3. Week 2: set up the inventory and enter risk classes with reasoning. The method is on classifying AI risk.
  4. Week 3: check external channels for disclosure duties. Ready-made labels for chat windows, AI images and synthetic voices are free on our AI labels page.
  5. Week 4: write a short policy and announce the approval route. From this point, new tools go through approval.

Where you stand after those four weeks takes two minutes to check — the free quick check walks through the ten points the questionnaires ask about.

When nobody volunteers

This is more common than people expect, and the reasons are almost always the same four. Each of them can be dealt with directly.

ObjectionWhat helps
“I have no time for this.”A time budget as a number in the letter, and one existing task visibly handed over. A role without relief is extra workload with a new name.
“I do not know anything about AI.”The task is organisational. Anyone who can keep a register and hold a deadline can fill the role. Technical questions are looked up, not memorised.
“Then I am liable if something goes wrong.”The clarifying sentence about the directors' duty of care, above. The regulation addresses the company.
“Nobody listens to me anyway.”Announcement by the management, not by the person themselves. Visible backing from the top decides whether the role functions.

Four signs the role exists only on paper

Check these after three months. The answers tell you more than any certificate.

  1. When was the AI inventory last changed? If the date is more than a quarter old, the process is not running.
  2. How many approval requests have come in? Zero requests do not mean zero new tools. They mean nobody knows the route.
  3. Has an incident ever been reported? In a company with fifty users, mistakes happen. No report means the reporting route is not perceived as consequence-free.
  4. Does a randomly chosen colleague know the name? If not, the announcement was too quiet.

Handover and succession

Roles change — through resignation, parental leave or reorganisation. So that nothing is lost, four things belong in a defined location: the current inventory, the approval decisions with their reasoning, the training records, and the folder of provider contracts. Someone who keeps those four files hands over in an hour. Someone who keeps them in their own mailbox does not hand over at all.

Record where you check the legal position as well. One line with two or three addresses saves your successor the search, and saves you the worry that nobody notices when something changes.

What the appointment has not done

A named person answers not one single question in a supplier questionnaire. The appointment is the precondition for the other documents coming into existence: inventory, policy, training record, labelling rule. Signing the letter and then doing nothing simply documents the gap more precisely. The twelve questions that arrive from procurement are the fastest way to see which documents you still owe yourself.

Frequently asked questions

Is a company legally required to appoint an AI officer?

No. The AI Act contains no duty to appoint, unlike Article 37 GDPR for the data protection officer. There is no headcount threshold, no notification duty and no prescribed qualification. Many companies appoint one anyway, because the duties fall on the company and without a named person nobody discharges them.

Can the data protection officer also be the AI lead?

It is permissible, but only with a clean split of tasks. Under Article 38(6) GDPR the data protection officer must not take on tasks that give rise to a conflict of interests, and approving tools then reviewing your own approval is exactly that. A workable arrangement is: the AI lead decides, the data protection officer is consulted and may object. Where the officer is external, the dual role is usually unproblematic.

Is the appointed person personally liable?

Not under the AI Act. Fines under Article 99 are directed at the company. The directors' own duty of care remains with the management and does not transfer to the appointed person. Internally, ordinary employment law principles apply.

How much time does the role take each month?

Up to twenty employees, one to two hours. Up to a hundred, two to six hours. Above that, six to twelve hours, usually split between two people. Initial set-up runs from half a day to five days depending on size.

What has to be in the letter of appointment?

Name and function, the list of duties, the authority granted (information from every department, the right to approve and block tools, direct access to management), a time budget expressed as a number, a named deputy, and signatures with a date. One page is enough.

Do we need an external provider for this role?

In most companies under a hundred people, no. The task depends on knowing your own organisation. External support earns its keep where high-risk systems are in use, where you develop AI yourself and take on the provider role, or where a large customer insists on independent confirmation.

Does the appointment have to be notified to an authority?

No. There is no counterpart to the notification of a data protection officer under Article 37(7) GDPR. The appointment operates internally and towards business partners.

We are outside the EU. Do we need this role at all?

If any of your AI output is used in the Union, the AI Act reaches that activity under Article 2, and someone has to be able to say which activity it is. The role is the same; the register simply needs a column recording, per tool, whether the output lands in the EU.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 26 EU AI Act — obligations of deployers
Article 4 EU AI Act — AI literacy
Article 2 EU AI Act — scope, including third-country deployers
Article 38 GDPR — position of the data protection officer
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
European Commission — AI Act Service Desk
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.