AI deployment in the company – Who keeps track?

Jennifer Schülzky
by Jennifer Schülzky · 27.09.2026

Why companies need clear responsibilities

Artificial intelligence is making its way into more and more companies – often faster than the necessary framework conditions can be created. Clear responsibilities, a reliable overview of the systems in use, and binding rules for employees are crucial for a legally sound deployment. This brings into focus the role of an AI officer.

The AI Regulation as a new legal framework

With the AI Regulation (AI Regulation) The European Union has for the first time created a unified legal framework for the use of artificial intelligence. Regulation (EU) 2024/1689, Also known as AI Act The regulation came into force on August 1, 2024. It is not only aimed at providers of AI systems, but also at their operators, that is, companies that use AI systems.

The AI Act aims to ensure the safe and transparent use of artificial intelligence. The specific obligations the AI Act imposes on companies depend on their role, such as that of provider or operator, and on the risk class of the respective AI system.

At its core, it involves:

  • the assessment of risks and appropriate risk management measures,
  • documentation of the AI deployment and transparency towards the individuals affected,
  • ensuring sufficient AI literacy among those involved in AI (since 2.2.2025), and
  • the labeling of AI-generated or AI-manipulated content (from 2.8.2026).

The role of the AI Officer

One way to coordinate the use of AI in the company is to appoint an AI officer or AI manager. This person bundles the organizational and legal requirements surrounding the use of AI and serves as a central point of contact for management, departments, and employees.

His typical duties include, in particular:

  • the recording and documentation of deployed AI systems (AI register),
  • the assessment of risks and regulatory requirements,
  • the establishment of release and control processes,
  • the creation of internal AI policies as well as
  • the coordination of training and awareness-raising measures.

Furthermore, the AI officer has a key coordinating function within the company.

The AI Officer as the central interface in the company

The use of AI regularly involves several business areas and different professional disciplines. Considerations include data protection issues, requirements for information security, and other legal aspects, such as copyright. In addition, depending on the area of deployment, the involvement of the works council may be required.

Therefore, it is not possible to assess whether and under what conditions an AI application can be used by a single person on a regular basis. Rather, the professional assessments of the involved departments must be combined and coordinated with one another.

This is where the AI officer comes in. He coordinates the coordination process between the relevant departments – especially IT, data protection, information security, legal affairs and compliance – and, where necessary, also involves the works council early on. In this way, he ensures that all relevant requirements are taken into account, responsibilities are clarified and decisions are documented in a comprehensible manner.

Principle: No statutory designation requirement

It should be clarified that the AI Act does not provide for mandatory appointment of an AI officer. Unlike the General Data Protection Regulation (GDPR), which requires the appointment of a data protection officer under certain conditions, the AI Act does not contain any corresponding provision. Therefore, companies can generally decide for themselves how to ensure the compliance with the requirements of the AI Act in the future, organizationally.

Conclusion

Anyone who wants to maintain control over the use of AI needs clear structures and responsibilities. Even if the AI Act does not require companies to appoint an AI officer, it is advisable to entrust a responsible person or department with the coordination of AI deployment at an early stage.

Especially for small and medium-sized companies, an external AI consultant can be an efficient and practical solution. This way, responsibilities can be streamlined, internal processes can be unified, and the requirements of the AI Act can be permanently integrated into the company's practices.

 Practical tips

  • AI systems capture: Check which AI applications are currently being used in the company and document them in an AI register.
  • Defining responsibilities: Name an AI officer or AI manager as the central point of contact for questions regarding the use of AI.
  • Establish internal rules: Create an AI policy and determine which AI applications are allowed to be used and which requirements must be met when using them.
  • Training of employees: Regularly train your employees on how to use the AI systems used in the company.
  • Involve affected parties: Involve all relevant departments, as well as your data protection and information security officer and – if necessary – the works council, in the introduction of new AI applications in a timely manner.
  • Documenting processes: Keep the disclosures, risk assessments, and organizational measures clear and understandable.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

What does the AI regulation regulate for companies?


What obligations can arise from the AI Regulation?


What are the duties of an AI officer?

Why is central coordination useful when using AI?


Do companies have to appoint an AI officer?


What organizational measures should companies take when using AI?