No, the AI Act does not require you to appoint an AI officer: nothing in Regulation EU 2024/1689 creates an equivalent to the data protection officer. Yet three very real obligations assume someone is accountable by name.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
No, the AI Act does not require you to appoint an AI officer. Nothing in Regulation EU 2024/1689 creates an equivalent to the data protection officer required by the GDPR. Three very real obligations, however, assume that someone is accountable by name. So the question is not whether the role is mandatory, but who currently carries those three obligations in your organisation.
Confusing a nomination requirement with a governance need produces two mirror-image mistakes. Some SMEs create a pointless role out of fear of a penalty that does not exist. Others, more commonly, let AI spread across every department without a single identified person knowing how many tools are in circulation. If you are starting from scratch, the EU AI Act compliance guide for SMEs and nonprofits sets out the general framework; this article deals only with the role and its mandate.
Regulation EU 2024/1689 never mentions the designation of an internal AI officer. That is a substantive difference from the GDPR, whose Article 37 requires a data protection officer in three specific cases: public authorities, large-scale systematic monitoring, and large-scale processing of sensitive data. The AI Act contains nothing comparable.
The regulation reasons in terms of economic roles, not org charts. It separates the provider, who develops an AI system and places it on the market under its own name, from the deployer, who uses it under its own authority in a professional context. Almost every French SME and nonprofit is a deployer and nothing else. To check your exact position, AI Act: who is affected? breaks down the four roles defined by the text.
The practical consequence: nobody will fault you for having no AI officer. They may fault you for failing one of the obligations below, and the next question will invariably be "who was in charge of this?".
Three provisions create accountability that cannot stay collective.
The first is Article 4, applicable since 2 February 2025. It requires providers and deployers alike to take measures ensuring a sufficient level of AI literacy among their staff, taking into account technical knowledge, experience and context of use. The obligation targets an outcome, not a format: no set duration, no set curriculum, no mandated training body. Someone still has to decide who is trained on what, and keep a record of it. AI Act Article 4: is AI training mandatory? covers this in detail.
The second is Article 26(2), applicable from 2 August 2026 for the high-risk systems listed in Annex III. It requires deployers to assign human oversight of those systems to natural persons who have the necessary competence, training and authority, as well as the necessary support. The text refers to identified individuals holding authority. You first need to know whether you operate a system in scope: CV screening, candidate scoring, employee evaluation and credit access decisions all fall within it, as explained in AI Act Article 6: high-risk AI systems.
The third is Article 26(7). Before putting a high-risk AI system into service in the workplace, an employer acting as deployer must inform workers' representatives and the affected workers. An information duty implies a designated sender and a timetable that holds. The overlap with employment law and the GDPR is covered in AI Act and employee data.
None of these three obligations says "appoint an officer". All three become unmanageable without one as soon as the company passes a few dozen people.
The right person is the one who already has access to the tools and the standing to say no, not the one who knows AI best.
| Profile | What they bring | Main blind spot |
|---|---|---|
| DPO or GDPR lead | Compliance reflexes, register methodology, experience with regulators | Tends to treat AI as just another data processing activity; little grip on undeclared business-side usage |
| IT manager | Real view of the estate, ability to block or approve a tool | Security and procurement angle; output quality and staff training often escape them |
| Director or executive committee member | Immediate arbitration authority, budget | Availability; the topic slides down the pile at the first busy quarter |
| Business lead already driving AI | Detailed knowledge of actual usage, credibility with teams | No authority over other departments; risk of becoming unpaid technical support |
In an organisation under 50 employees, the combination that works best pairs an operational owner from the business side with an executive sponsor who arbitrates. Where a DPO exists, they stay within their data remit rather than inheriting the topic by default: the two regulations pursue different objectives, as set out in AI Act vs GDPR.
One frequently overlooked point: an external DPO bills by time spent and holds no internal line authority. Handing them the role effectively outsources an arbitration function, which rarely survives six months.
An AI officer without a written mandate is a volunteer, and volunteers arbitrate nothing. The document fits on one page and covers six points.
This mandate is written once and attaches naturally to the internal AI policy, which carries usage rules for all staff.
For an SME of 20 to 100 employees operating no high-risk system, the role is a moderate but permanent commitment, not a full-time job.
The workload splits into three distinct blocks. Launch concentrates most of the effort: department-by-department review of tools in use, interviews with teams, drafting of the first rules. Expect several full days spread over six to eight weeks, once.
Then comes steady state: updating the inventory, handling requests for new tools, answering questions from teams. Half a day a month is enough in most organisations of that size, provided the request process is formalised.
The third block is training, which follows its own logic and runs in waves rather than continuously. If you need to budget for it, market price ranges and funding mechanisms are set out in AI training costs for businesses.
The equation changes if you operate a high-risk system under Annex III. Article 26 adds monitoring of operation, log retention and information of affected workers. A conformity assessment then becomes the starting point rather than the finish line.
The first is appointing without offloading. Adding AI officer duties to an already saturated job description produces a title with no content. Six months later, the inventory still dates from day one.
The second is placing the role too low in the hierarchy. An officer who cannot say no to a sales director in a hurry to deploy a scoring tool is not an officer, they are a point of contact. Article 26 explicitly refers to necessary authority, and that requirement is not decorative.
The third is mistaking the role for technical expertise. The person does not need to understand how a language model works, or the mechanics of a hallucination. They need to ask three questions of every new tool: what data goes in, who reviews the output before a decision is made, and what happens if the result is wrong. The rest can be learned or outsourced.
Below a certain size, formal appointment makes no sense: the director carries the role, and traceability becomes the real issue.
In a ten-person nonprofit, nobody has twenty percent of their time for a coordination function. What matters comes down to three artefacts: a table listing the tools in use and the data flowing through them, a one-page note on what is allowed and what is not, and a record of awareness sessions. Those three documents answer most of what an inspection would check, without creating a role.
The regulation supports that logic. Article 99 provides that for SMEs and start-ups, the fine ceiling is the lower of the two applicable amounts, whereas larger companies face the higher one. Thresholds and concrete cases are covered in AI Act sanctions: what you risk in 2026. A proportionate approach remains the correct reading of the text, provided you can document it.
For nonprofits, whose funding and governance constraints differ markedly from a standard SME, the AI Act practical guide for SMEs offers benchmarks suited to small headcounts.
Is an AI officer mandatory under the AI Act? No. Regulation EU 2024/1689 sets out no obligation to designate an internal AI lead, unlike the GDPR, which requires a data protection officer in three specific situations. Appointment is an organisational decision, not a legal requirement.
Can the DPO become the AI officer? Yes, and it is common, but not automatic. The DPO brings solid compliance method and documentation habits. What they often lack is visibility of undeclared business usage and authority over tool choices. Where the DPO is external, the arrangement rarely holds over time for want of internal authority.
Does the officer have to be declared to a regulator? No. The regulation provides for no such declaration, unlike the designation of a data protection officer, which is communicated to the national data protection authority. The mandate stays an internal document.
What training does an AI officer need? No diploma or certification is imposed. Actual needs cover three areas: the content of the regulation and its deadlines, the risks specific to the tools used in the company, and change management with teams. A targeted AI training programme for business usually covers all three in two days.
What happens if nobody is appointed? Nothing in itself, since the absence of an officer is not a breach. But in the event of an inspection or an incident, accountability falls to the director, who will have to demonstrate that the obligations of Articles 4 and 26 were met. Without an identified person, that demonstration is hard to produce.
At what size should the role be formalised? There is no legal threshold. In practice, formalisation becomes useful once more than one department uses AI without coordinating, or as soon as an Annex III system goes into service, whatever the size of the organisation.
Can an external provider hold the role? On method, inventory and training, yes. On arbitration, no: Article 26 requires an authority that a provider does not have. The arrangement that works pairs an internal officer holding a mandate with external support on the technical and regulatory side.
GrowthPerf is a Qualiopi-certified training organisation working with SMEs and nonprofits that come to the subject without a dedicated legal team. Our work covers three concrete points: an inventory of the AI systems actually in use across your departments, drafting the officer's mandate including scope and arbitration power, and building the skills of the designated person and the teams concerned under Article 4.
Our programmes are eligible for OPCO funding under the usual coverage conditions, which shifts the conversation from budget to scheduling.
If you are unsure where to start, a 30-minute audit will place your exposure level and tell you whether formalising the role is worth it in your case. For the full picture of obligations and deadlines, go back to the EU AI Act compliance guide for SMEs and nonprofits.
Book your free AI training audit (30 minutes).