/ 2 min read

Who owns the AI Act in your company? The DPO?

Who is responsible for AI Act compliance? Many organisations still have no clear answer. Their data protection officers do: They think it's them. That is the main finding of a survey by the French data protection authority, CNIL, published on 22 September 2026, together with the French Ministry of Labour and the French DPO association AFCDP.

The fifth edition of the DPO Observatory looks at how AI and the AI Act are changing the DPO's role. Some of the key figures:

  • 70% of the organisations that responded use or plan to use AI. Among those, 81% use generative AI.
  • Two-thirds buy their AI solutions from external providers. Only 22% develop them in-house.
  • Fewer than a quarter have a formal AI strategy or policy. Only 31% have started preparing for the AI Act.
  • 55% of DPOs say the AI Act already falls under their responsibility, and 71% want their role extended to cover it.
  • Only 27% of DPOs say they know the AI Act well, and 85% have had no specific AI training.

The CNIL notes that the AI Act does not mention the DPO at all. As a result, the DPO's role in AI governance is not clearly defined. 

The survey is French, but the picture looks very familiar in other EU countries. AI ownership can be seen with the DPO, with members of the compliance department (AI officer) or the IT (security) department. In most organisations, this decision is based on available resources, subject matter expertise, and fitting into the existing governance structure. Organisations are aware that AI law is not just an add-on that can be added onto the plate of a person that is already fully utilized for other tasks. 

Three practical steps:

  1. Assign responsibility. Decide who owns AI Act compliance internally. The DPO could be a natural candidate, but they need a clear mandate, resources and training; and there may be other candidates.
  2. Use what you have. Most AI use cases involve personal data, so you can build on existing GDPR processes such as records of processing and DPIAs. AI requires a different governance structure than privacy or IT security, because it's broader. But organizations are best advised to use existing structures where possible. 
  3. Look at your contracts. If two-thirds of AI comes from external vendors, AI contracts need to allocate the AI Act roles and duties properly.

AI Act compliance is not a one-person job, but it needs one owner. 

"While there is no doubt that the DPO must be involved whenever AI processes personal data, the question of extending the DPO's skills to compliance with the AI Act remains fully open."

Read more