By Rafael Luque Ocaña

The AI Officer who didn't know they were one: AI governance in the SME without a department

In most SMEs, AI governance falls to someone who never asked for the job: the IT person, the quality lead, the HR manager. That emerging role deserves structure, without confusing it with a legal figure the AI Act doesn't require.

In large companies, AI governance has an owner: a team, a committee, a budget. In the SME, the picture is different. Responsibility for AI being used well falls, almost always, on someone who doesn't have that job in their role description. It's the IT lead who "understands technology", the quality manager who already runs the audits, the HR manager who handles the personnel tools. One day people start asking them questions about the AI Act, and they discover, without having asked for it, that the AI governance role is theirs.

For practical purposes, we call that figure the AI Officer. And before explaining how to give it structure, something important needs clarifying, so as not to oversell it.

First things first: the AI Act doesn't require you to appoint an AI Officer

It's worth stating clearly, because the opposite claim circulates. The AI Act does not require designating an "AI Officer" or an "AI lead" as a legal figure. It isn't the DPO.

The DPO — Data Protection Officer — is a figure with a direct legal basis: the GDPR requires designating one in certain cases, defines their functions and protects their position. The AI Officer has no such status. It's a methodological internal control: an organisational good practice that helps you comply, not an obligation the law imposes.

Why insist on this? Because the difference matters for making sound decisions. If someone tells you that "not having an AI Officer means you're breaking the law", they're selling you an obligation that doesn't exist. What the AI Act does require are documented measures — AI literacy measures, human oversight, transparency, assessments where they apply. Having someone coordinate them is the most efficient way to keep them in place and on record, not an end in itself.

Why it's still worth having one

Not being mandatory doesn't mean it's dispensable. AI governance without an identified owner scatters: the inventory gets maintained by whoever has time, the policy was written by someone who has since left, nobody knows who reviews the classifications. When responsibility belongs to everyone, in practice it belongs to no one.

An AI Officer — even part-time and with another primary role — solves that. It gives you a single point of coordination, someone to ask, someone accountable for keeping the register alive. In an SME, this doesn't need to be a senior legal or technical profile. It needs an explicit mandate, allocated time and backing from management.

What it does, in practice

The AI Officer's work in an SME is more operational than strategic. It looks like this:

  • Keeping the AI systems inventory alive, including the AI that arrives unannounced through software updates.
  • Coordinating the classification of each system by its risk level, drawing on expert judgement when the case is doubtful.
  • Safeguarding the AI use policy and ensuring it's known and followed.
  • Taking AI literacy measures for staff (Article 4) and keeping the evidence of it.
  • Acting as the link with the DPO on matters of data, and with management on matters of decisions.
  • Preparing the evidence for the day someone — an authority, a client conducting an audit — asks.

It isn't a role that demands full-time dedication in most SMEs. It demands consistency and a method.

The AI Officer and the DPO: don't confuse them, don't merge them without judgement

Two distinct figures that sometimes fall to the same person. It can work, but the difference is worth understanding. The DPO has independence and functions protected by the GDPR, and their scope is personal data. The AI Officer coordinates AI governance in a broader sense, one that includes systems and uses that don't always revolve around personal data.

If the same person holds both roles in your organisation, make sure the workload is realistic and that the DPO hat keeps the independence the law requires of it. Merging roles for convenience, without weighing whether it makes sense, is a shortcut that can prove costly.

How to give it structure without building a department

For an SME, professionalising this role doesn't require hiring anyone or creating a unit. It requires three things:

  1. Explicitly naming the person and giving them the mandate in writing, with recognised time.
  2. Giving them a method: a clear process for taking inventory, classifying, training and documenting, instead of improvising every time.
  3. Backing them from management: without the authority to request information from teams and to stop misuse, the role stays purely decorative.

The SME's AI Officer is an emerging, real role, even though the AI Act doesn't name it. Recognising it, giving it structure and not selling it as a legal obligation it isn't: that's doing AI governance honestly. If that figure is you, and you arrived without asking for it, the good news is that the work has a method. And with a method, it's entirely manageable.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.