AI Officer
An AI Officer is the individual or outsourced function designated by an organisation to lead its governance of artificial intelligence: ensuring compliance with the EU AI Act, the GDPR and sector-specific rules such as the MDR, and embedding responsible AI practices across the AI lifecycle. Unlike the Data Protection Officer, the AI Officer is not a role mandated by EU law; the AI Act instead imposes obligations on providers and deployers as organisations, requires AI literacy of staff (Art. 4) and, for high-risk providers, a quality management system (Art. 17). Many organisations nevertheless create the role, sometimes called Chief AI Officer, Head of AI Governance or Responsible AI Lead, to give these obligations an owner, and ISO/IEC 42001 expects top management to assign responsibilities and authorities for the AI management system.
Typical tasks include maintaining an inventory of AI systems and models in use or development; classifying each under the AI Act (prohibited, high-risk, transparency-only, minimal risk; provider or deployer role) and under sector law; overseeing risk management, data governance, technical documentation, human oversight and post-market monitoring for high-risk systems; coordinating FRIAs and DPIAs with the DPO; setting policies for staff use of generative AI tools; managing relationships with model providers and vendors; ensuring AI literacy training; reporting to management and boards; and acting as contact point for market surveillance authorities, notified bodies and the AI Office. In pharmaceutical companies the AI Officer also aligns with EMA and FDA expectations on AI in the medicinal product lifecycle and with GxP validation.
The AI Officer and the DPO are distinct but closely linked roles: the DPO's independence and statutory tasks under Art. 37 to 39 GDPR must be preserved, and the DPO cannot also be the person deciding on purposes and means of AI processing, whereas the AI Officer often has an operational mandate. Small and mid-sized life sciences companies frequently outsource both to the same provider to ensure coherence between AI Act and GDPR documentation. iliomad offers an outsourced AI Officer service and acts as EU AI Act authorised representative for non-EU providers.
