Why "one person owns AI" isn't a role, it's a bottleneck
The AI Act doesn't require a job titled "AI Governance Officer." It requires a risk management system (Art. 9), effective human oversight (Art. 14), and maintained technical documentation (Art. 11). These are three obligations with different rhythms and different skill profiles: managing risk is ongoing coordination work; overseeing a system in production requires being close to daily operations; maintaining technical documentation requires direct access to the ML team. Folding all three into one person isn't efficiency — it's a single point of failure with a name attached.
The four roles that hold up a real program
1. AI Governance Officer (or equivalent)
Doesn't execute every control — makes sure they exist. Sets the acceptable AI use policy, keeps the systems inventory, convenes the committee, and is the person a market surveillance authority would look for first if they ask "who's accountable for this at your company?" Usually reports into Legal, Compliance, or directly to leadership depending on company size. Doesn't need to know how to train a model, but does need real authority to block deployment if risk isn't managed.
2. AI governance committee
This is where decisions get made that no single role can or should make alone: approving the use of a high-risk system, deciding budget to remediate a gap, or resolving a disagreement between Legal and Product about whether a system needs reclassifying. Without this body, every risk decision becomes an informal negotiation between two people with no formal authority to settle it — which is exactly how "temporary" systems that never get reviewed pile up.
3. Per-system risk owner (not company-wide)
Every high-risk AI system needs one specific person accountable for it — usually whoever runs it at the product or business level, not the technical team. This is different from the AI Governance Officer: the latter coordinates the whole program; the risk owner answers for one specific system, knows when it was last retrained, and should be the one raising the alarm if the system's intended use changes.
4. Human overseer (human oversight, Art. 14)
Article 14 is specific: whoever oversees needs competence, training, and above all real authority to intervene or stop the system. An analyst with no ability to pause a deployment doesn't satisfy Article 14, no matter how carefully they "review" outputs. This role usually lives inside the team operating the system day to day, not in a central function — effective oversight requires operational proximity, not a quarterly committee.
| Role | Accountable for | Cadence |
|---|---|---|
| AI Governance Officer | The whole program, policy and coordination | Ongoing |
| Governance committee | Decisions that require collective authority | Monthly / quarterly |
| Per-system risk owner | One specific AI system | Per system, when something changes |
| Human overseer | Day-to-day operation of a system in production | Ongoing, real-time |
How to start if none of the four exist today
You don't need new hires to get going. The most practical sequence: first, someone takes on the AI Governance Officer role, even part-time, with a clear written mandate. Second, the committee's first meeting gets convened — it doesn't need new people, just the people already making AI decisions without a formal structure, now with an agenda and minutes. Third, a risk owner gets assigned for each high-risk system already in production. Article 14 human oversight usually already exists de facto within the operating team; what's typically missing is documenting who holds that authority and verifying they can actually pause the system.
What to check this week
- Is there a written mandate for whoever coordinates AI Governance, or has it become an informal responsibility that "fell to" someone?
- Has the governance committee ever met with minutes, or are risk decisions made in hallway conversations?
- For each high-risk system, is there one specific name accountable for it, or just "the team" in the abstract?
- Does the human overseer of each production system have real authority to pause it, or do they just review outputs with no decision-making power?
No AI Governance program survives on a single owner. The four roles don't need to be four different people from day one, but they do need to be four explicit responsibilities with a written mandate — the alternative is that everything depends on one person never taking a vacation.