← Glossary

AI Officer

Internal function an organisation may assign to coordinate the governance of its AI systems. It is not a figure of the Regulation: the expression does not appear in the articles.

It is an organisational decision, not a legal requirement, and confusing the two is costly in both directions.

Which obligations it carries

An internal methodological control, with no legal mandate. The Regulation does not require designating anyone with this name or with any equivalent function. What does exist are the obligations that someone inside the organisation has to meet: those of Article 26 for the deployer, applicable from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I, and those of Article 4, in force. Assigning those tasks to a specific person is a good management decision and does not turn that person into a regulated figure.

What it is not

It is not the data protection officer. The DPO is a GDPR figure with its own designation regime in Article 37 — applicable from 25 May 2018 —, its own tasks and its own guarantees of independence. The AI Officer has none of the three. It is not mandatory, and nobody can demand its designation by invoking the Regulation. And it is not an accreditation: there is no AI Officer certification, register or authorisation that the Regulation recognises.

The nuance almost nobody captures

The costly error runs in both directions. Presenting it as a legal obligation is false and exposes whoever claims it. But dismissing the function because it is not mandatory leaves the obligations of Article 26 and Article 4 without an internal owner, and those do exist. What is not mandatory is the post; what lies beneath the post is.

To find out more

Reviewed on 18 August 2026. Dates according to Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJ of 24 July 2026, in force since 27 July 2026).