“Who is responsible for AI in your organisation?” When a supplier questionnaire arrives, that question tends to sit near the top — and it is the one you cannot produce at short notice. This page sets out who to appoint, what the role really covers — and what it expressly is not.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
No. That belongs at the top, because a good deal of anxiety is sold at this exact point. The AI Act contains no counterpart to Article 37 GDPR, which requires a data protection officer in defined circumstances. There is no headcount threshold at which an “AI officer” must be appointed, no notification to any authority, and no prescribed qualification.
Anyone selling you a certificate on the basis that a missing AI officer exposes you to a fine is arguing past the law. That fine does not exist. Article 99 lists the penalised obligations exhaustively, and none of them concerns an appointment.
The duties in the regulation fall on the company. A company cannot do anything, though — people do things. Without a named person, what usually happens is exactly nothing. Everyone assumes somebody else is dealing with it.
There is also a practical trigger. Business customers now ask for the role as a matter of routine. Ticking “not appointed” rarely loses you the contract outright, but it starts a round of follow-up questions that costs three weeks.
Article 2 sets the scope of the AI Act by effect rather than by registered office. It reaches providers placing AI systems on the EU market wherever they are established, deployers located in the Union, and providers and deployers in a third country where the output produced by the AI system is used in the Union. A firm in London, Dublin, Zurich or New York whose AI output lands in the EU is in scope for that activity.
That has one consequence for this role and one only: whoever you appoint needs to know which of your activities produce output used in the Union, because those are the ones the transparency and literacy duties attach to. It is a column in your register, not a second job. There is a separate matter — the authorised representative under Article 22 — but that duty falls on providers placing systems on the EU market, not on ordinary deployers.
The common assumption that this has to be someone from IT is misleading. Ninety per cent of the work is organisational: asking, recording, deciding, reminding. Technical depth is not required. Access to the management is.
| Candidate | In favour | Against |
|---|---|---|
| A director, in firms up to about twenty people | Decision-making authority already there, no approval loops | The time budget is almost always overestimated and the task gets displaced by operational work |
| Executive assistant to the management | Sees every part of the business, has a short route upwards, documents things anyway | Needs express authority to decide, or every approval sits waiting |
| Head of IT | Knows the system landscape, most likely to spot shadow AI | Tends towards a purely technical view; other departments feel policed |
| Quality management | Thinks in processes, documentation is daily business | Often does not exist below fifty employees |
| Data protection officer | Closest subject-matter fit, already knows the records and the contracts | Possible conflict of interest where the officer is internal — see below |
Putting both roles in one pair of hands is an obvious move. It is permissible, but not without care. Under Article 38(6) GDPR the data protection officer performs a monitoring function and must not take on tasks that give rise to a conflict of interests. Someone who approves AI tools themselves then goes on to review their own decision.
The clean split: the AI lead decides on approvals. The data protection officer is consulted before each approval and may object. Two people, one decision, recorded so the reasoning is visible afterwards. Where the data protection officer is external, the dual role is usually unproblematic, because no operational approval authority sits there in the first place.
This list belongs in the letter of appointment more or less verbatim. It is also the answer to the follow-up question “what does that person actually do?”, which almost always arrives with the questionnaire.
This boundary decides whether anyone accepts the job. Without it, the appointment reads as a liability trap, and it is not one.
For a company that uses AI rather than builds it:
| Size | Initial set-up | Ongoing, per month |
|---|---|---|
| Up to 20 employees | half a day | 1 to 2 hours |
| 20 to 100 | one to two days | 2 to 6 hours |
| 100 to 250 | three to five days | 6 to 12 hours, often split between two people |
The largest item in the initial set-up is not writing documents. It is the stocktake: finding out what is genuinely in use. Skip that part and you save a day, then document an inventory that is wrong.
One page is enough. It only gets longer when somebody copies a template written for a listed group.
“For the performance of these duties, [name] is entitled to obtain information from every department, to approve or block AI tools, and to raise matters directly with the management. A time budget of up to [number] hours per month is made available for the role. The duties of the management under applicable company law remain unaffected.”
The last sentence is not decoration. It makes clear that nobody is being pushed into the directors' own duty of care — and it makes it considerably easier for someone to say yes.
Providers exist who will take the role externally, much as they do for data protection. An honest assessment: for companies under a hundred people that only use AI, this is usually oversized. The task depends on knowing your own house. Someone who sees which tools keep appearing in marketing will find shadow AI; an external provider on a quarterly call will not.
External support earns its keep in three situations: high-risk systems in use, in-house AI development that puts you in the provider role, or a corporate customer who insists on independent confirmation. In every other case the combination of an internal person and a good external reference source is cheaper and works better.
Where you stand after those four weeks takes two minutes to check — the free quick check walks through the ten points the questionnaires ask about.
This is more common than people expect, and the reasons are almost always the same four. Each of them can be dealt with directly.
| Objection | What helps |
|---|---|
| “I have no time for this.” | A time budget as a number in the letter, and one existing task visibly handed over. A role without relief is extra workload with a new name. |
| “I do not know anything about AI.” | The task is organisational. Anyone who can keep a register and hold a deadline can fill the role. Technical questions are looked up, not memorised. |
| “Then I am liable if something goes wrong.” | The clarifying sentence about the directors' duty of care, above. The regulation addresses the company. |
| “Nobody listens to me anyway.” | Announcement by the management, not by the person themselves. Visible backing from the top decides whether the role functions. |
Check these after three months. The answers tell you more than any certificate.
Roles change — through resignation, parental leave or reorganisation. So that nothing is lost, four things belong in a defined location: the current inventory, the approval decisions with their reasoning, the training records, and the folder of provider contracts. Someone who keeps those four files hands over in an hour. Someone who keeps them in their own mailbox does not hand over at all.
Record where you check the legal position as well. One line with two or three addresses saves your successor the search, and saves you the worry that nobody notices when something changes.
A named person answers not one single question in a supplier questionnaire. The appointment is the precondition for the other documents coming into existence: inventory, policy, training record, labelling rule. Signing the letter and then doing nothing simply documents the gap more precisely. The twelve questions that arrive from procurement are the fastest way to see which documents you still owe yourself.
No. The AI Act contains no duty to appoint, unlike Article 37 GDPR for the data protection officer. There is no headcount threshold, no notification duty and no prescribed qualification. Many companies appoint one anyway, because the duties fall on the company and without a named person nobody discharges them.
It is permissible, but only with a clean split of tasks. Under Article 38(6) GDPR the data protection officer must not take on tasks that give rise to a conflict of interests, and approving tools then reviewing your own approval is exactly that. A workable arrangement is: the AI lead decides, the data protection officer is consulted and may object. Where the officer is external, the dual role is usually unproblematic.
Not under the AI Act. Fines under Article 99 are directed at the company. The directors' own duty of care remains with the management and does not transfer to the appointed person. Internally, ordinary employment law principles apply.
Up to twenty employees, one to two hours. Up to a hundred, two to six hours. Above that, six to twelve hours, usually split between two people. Initial set-up runs from half a day to five days depending on size.
Name and function, the list of duties, the authority granted (information from every department, the right to approve and block tools, direct access to management), a time budget expressed as a number, a named deputy, and signatures with a date. One page is enough.
In most companies under a hundred people, no. The task depends on knowing your own organisation. External support earns its keep where high-risk systems are in use, where you develop AI yourself and take on the provider role, or where a large customer insists on independent confirmation.
No. There is no counterpart to the notification of a data protection officer under Article 37(7) GDPR. The appointment operates internally and towards business partners.
If any of your AI output is used in the Union, the AI Act reaches that activity under Article 2, and someone has to be able to say which activity it is. The role is the same; the register simply needs a column recording, per tool, whether the output lands in the EU.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free