Why "one person owns AI" isn't a role, it's a bottleneck

The AI Act doesn't require a job titled "AI Governance Officer." It requires a risk management system (Art. 9), effective human oversight (Art. 14), and maintained technical documentation (Art. 11). These are three obligations with different rhythms and different skill profiles: managing risk is ongoing coordination work; overseeing a system in production requires being close to daily operations; maintaining technical documentation requires direct access to the ML team. Folding all three into one person isn't efficiency — it's a single point of failure with a name attached.

The four roles that hold up a real program

1. AI Governance Officer (or equivalent)

Doesn't execute every control — makes sure they exist. Sets the acceptable AI use policy, keeps the systems inventory, convenes the committee, and is the person a market surveillance authority would look for first if they ask "who's accountable for this at your company?" Usually reports into Legal, Compliance, or directly to leadership depending on company size. Doesn't need to know how to train a model, but does need real authority to block deployment if risk isn't managed.

2. AI governance committee

This is where decisions get made that no single role can or should make alone: approving the use of a high-risk system, deciding budget to remediate a gap, or resolving a disagreement between Legal and Product about whether a system needs reclassifying. Without this body, every risk decision becomes an informal negotiation between two people with no formal authority to settle it — which is exactly how "temporary" systems that never get reviewed pile up.

3. Per-system risk owner (not company-wide)

Every high-risk AI system needs one specific person accountable for it — usually whoever runs it at the product or business level, not the technical team. This is different from the AI Governance Officer: the latter coordinates the whole program; the risk owner answers for one specific system, knows when it was last retrained, and should be the one raising the alarm if the system's intended use changes.

4. Human overseer (human oversight, Art. 14)

Article 14 is specific: whoever oversees needs competence, training, and above all real authority to intervene or stop the system. An analyst with no ability to pause a deployment doesn't satisfy Article 14, no matter how carefully they "review" outputs. This role usually lives inside the team operating the system day to day, not in a central function — effective oversight requires operational proximity, not a quarterly committee.

RoleAccountable forCadence
AI Governance OfficerThe whole program, policy and coordinationOngoing
Governance committeeDecisions that require collective authorityMonthly / quarterly
Per-system risk ownerOne specific AI systemPer system, when something changes
Human overseerDay-to-day operation of a system in productionOngoing, real-time
The most common mistake: naming an AI Governance Officer and assuming that covers Article 14 human oversight too. These are different roles with different requirements — the first doesn't replace the second, and an authority auditing a system in production will ask specifically who oversees it day to day, not just who runs the program.

How to start if none of the four exist today

You don't need new hires to get going. The most practical sequence: first, someone takes on the AI Governance Officer role, even part-time, with a clear written mandate. Second, the committee's first meeting gets convened — it doesn't need new people, just the people already making AI decisions without a formal structure, now with an agenda and minutes. Third, a risk owner gets assigned for each high-risk system already in production. Article 14 human oversight usually already exists de facto within the operating team; what's typically missing is documenting who holds that authority and verifying they can actually pause the system.

What to check this week

  1. Is there a written mandate for whoever coordinates AI Governance, or has it become an informal responsibility that "fell to" someone?
  2. Has the governance committee ever met with minutes, or are risk decisions made in hallway conversations?
  3. For each high-risk system, is there one specific name accountable for it, or just "the team" in the abstract?
  4. Does the human overseer of each production system have real authority to pause it, or do they just review outputs with no decision-making power?

No AI Governance program survives on a single owner. The four roles don't need to be four different people from day one, but they do need to be four explicit responsibilities with a written mandate — the alternative is that everything depends on one person never taking a vacation.

Data/AI Governance Committee Charter Defines the committee's mandate, composition and cadence in a signable document, ready for the first meeting. €39.
View template →
First Committee Meeting Kit Agenda, minutes template and decision checklist so the first meeting doesn't end as just a conversation with no outcome. €39.
View kit →