Who Owns AI Act Compliance? Mapping Governance Roles from CISO to DPO
As the August 2026 deadline looms, organizations are struggling with a fundamental question: who is actually responsible for AI Act compliance? This guide maps the key governance roles — from the Chief AI Officer to the DPO — and explains how to structure accountability.
The Accountability Problem
In conversations with compliance teams across Europe, one question comes up more than any other: "Whose job is AI Act compliance?" Unlike GDPR, which has a clearly defined role — the Data Protection Officer — the AI Act does not mandate a specific compliance officer. This creates an organizational gap that companies must fill proactively.
The challenge is compounded by the fact that AI Act compliance spans multiple disciplines: legal, technical, ethical, risk management, product development, and procurement. No single existing role covers all of these dimensions, which means organizations need a deliberate governance structure that assigns clear accountability while enabling cross-functional collaboration.
Key Governance Roles
The Chief AI Officer (CAIO) or AI Governance Lead
A growing number of organizations are creating a dedicated Chief AI Officer or AI Governance Lead role to serve as the single point of accountability for AI Act compliance. This role typically owns the organization's AI system inventory and ensures all systems are classified by risk level, coordinates the quality management system required under Article 17, serves as the primary point of contact with national competent authorities, reports to the board or executive committee on compliance status, and oversees the conformity assessment process for high-risk AI systems.
Data Protection Officer (DPO)
For organizations that already have a DPO under GDPR, there is a natural overlap with AI Act compliance — particularly regarding data governance for training, validation, and testing datasets (Article 10), Fundamental Rights Impact Assessments (FRIA), which closely resemble Data Protection Impact Assessments (DPIAs), transparency obligations around automated decision-making, and incident reporting which may involve both data breaches and AI system malfunctions.
However, the DPO should not be the sole owner of AI Act compliance. The regulation's requirements extend well beyond data protection into areas like technical robustness, accuracy testing, and cybersecurity that fall outside the DPO's traditional competence.
Chief Information Security Officer (CISO)
The CISO plays a critical role in AI Act compliance through the cybersecurity requirements of Article 15. High-risk AI systems must be designed with an appropriate level of cybersecurity protection, including resilience against adversarial attacks such as data poisoning, model manipulation, and adversarial examples. The CISO's responsibilities in the AI Act context include ensuring AI systems meet accuracy, robustness, and cybersecurity standards, conducting adversarial testing (red teaming) of AI models, managing supply chain security for AI components and third-party models, and contributing to incident response procedures for AI system failures.
Legal / General Counsel
Legal teams are essential for interpreting the AI Act's requirements and assessing regulatory risk. Key responsibilities include risk classification (determining whether AI systems fall under Annex III or qualify for the Article 6 exception), contractual frameworks (ensuring provider-deployer agreements address AI Act obligations), liability assessment (understanding exposure under both the AI Act and the proposed AI Liability Directive), and regulatory engagement (managing communications with market surveillance authorities).
Product / Engineering Leadership
The AI Act's requirements for technical documentation (Annex IV), risk management (Article 9), data governance (Article 10), and human oversight (Article 14) cannot be met without deep involvement from the teams that actually build and deploy AI systems. Product and engineering leaders are responsible for implementing design-phase compliance, creating and maintaining technical documentation that meets Annex IV requirements, designing human oversight interfaces that enable meaningful human control, and conducting testing and validation activities to demonstrate accuracy and robustness.
Structuring the Governance Framework
The Three Lines Model
| Line | Function | AI Act Role |
|---|---|---|
| First Line | Product, Engineering, Operations | Day-to-day compliance: documentation, testing, monitoring, human oversight |
| Second Line | AI Governance / CAIO, Legal, Risk, DPO | Oversight: policies, standards, risk classification, compliance monitoring, FRIA |
| Third Line | Internal Audit | Independent assurance: audit AI Act compliance, report to board |
Common Mistakes to Avoid
- Assuming GDPR compliance covers the AI Act: While there is overlap, the AI Act introduces requirements that go well beyond GDPR, including technical robustness, accuracy testing, conformity assessment, and CE marking
- Treating compliance as a one-time project: The AI Act requires ongoing risk management, post-market monitoring, and documentation updates
- Ignoring the deployer perspective: Many organizations focus on their provider obligations but forget that they also deploy AI systems from third parties, which carries separate obligations
- Siloing compliance in legal: Legal teams are essential, but they cannot conduct adversarial testing or build human oversight interfaces alone
Action Checklist
- Designate a single accountable executive for AI Act compliance (CAIO or equivalent) before June 2026
- Map all existing governance roles (DPO, CISO, GC, Product) to specific AI Act requirements
- Establish a cross-functional AI Governance Committee with clear terms of reference
- Create RACI matrices for key compliance activities (risk classification, documentation, conformity assessment, incident reporting)
- Invest in AI literacy training for all governance roles — Article 4 requires that staff involved with AI systems have sufficient understanding
- Budget for ongoing compliance, not just initial implementation
Need help structuring your AI governance framework? Search our directory for consultants specializing in AI governance design and organizational readiness.