EU AI Act Accountability: Who Owns Which Obligation? A Practitioner Q&A

Who owns which EU AI Act duty: provider versus deployer, Article 4 AI literacy, Article 14 human oversight and the evidence a regulator will expect to see.

This Q&A is for compliance leads, DPOs, CISOs and board members working out who in the organisation legally carries which duty under the EU AI Act. The Act assigns obligations by function, not by job title, so appointing an AI leader is not the same as covering your statutory duties. The answers below track the current Act text and its phased dates. They are informed guidance, not legal advice; confirm your position with qualified legal counsel. The longer argument sits in our companion post on who the Act actually holds accountable.

Does the EU AI Act require organisations to appoint a Chief AI Officer?

No. The Act names no such role and mandates no specific title. It assigns obligations to providers and deployers of AI systems, defined by what an organisation actually does rather than what it calls its people.

You can appoint a Chief AI Officer and still leave statutory functions unowned, or discharge every duty with no such title at all. The practical requirement is that each obligation has a single named owner with the authority and evidence to satisfy it. If you are working through the titles themselves, our AI leadership map covers what each one usually owns.

What is the difference between a provider and a deployer under the EU AI Act?

A provider is the organisation that builds an AI system, or has one built, and puts it on the EU market or into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional context. Most organisations are deployers.

Many become providers without realising it. Substantial modification, fine-tuning or rebadging under your own name can convert a deployer into a provider, and provider duties are considerably heavier. Establishing which role you hold for each individual system is the first step in any accountability mapping exercise, because the two statuses carry different obligations and different evidence expectations.

Who is legally accountable for AI compliance under the EU AI Act?

Accountability sits with the organisation acting as provider or deployer, not with an individual by default. Internally, though, every obligation needs a named owner who can be shown to hold it. Regulators and auditors will look for evidence that duties are assigned, resourced and actually performed.

The distinction between accountability and responsibility matters here. The organisation is accountable to regulators, while named individuals are responsible for discharging specific functions. An ownership map with no proof behind it offers little protection, because the question in an inspection is not who was nominated but what that person did and when.

Which AI Act obligations map to which leadership role?

No fixed mapping exists, because the Act does not recognise these titles. In practice a Chief AI Officer or Head of AI Strategy often owns adoption and value, a Chief AI Risk Officer or Director of AI Governance owns risk management and oversight, and a CDAO may hold data governance.

The critical rule is separation. The role driving AI adoption should not also sign off human oversight or risk acceptance, because that puts the same person in charge of the decision to proceed and the decision to stop. Map each obligation to a function first, then assign an owner to the function. Working the other way round, from the org chart towards the duties, is what leaves statutory functions uncovered.

What is the AI literacy obligation (Article 4) and who owns it?

Article 4 requires providers and deployers to ensure staff and others operating AI systems on their behalf have a sufficient level of AI literacy, taking account of their role and the context of use. It applied from 2 February 2025, so it is already in force.

It is also the most commonly unowned duty we see, because it falls between HR, security and the AI function. Assign it explicitly, usually to whoever owns AI governance, and keep dated records of the training delivered, who received it and what it covered. Without those records the obligation cannot be evidenced even where the training genuinely happened.

What does human oversight require under the EU AI Act, and who is responsible for it?

Human oversight under Article 14 requires that high-risk AI systems can be effectively overseen by people during use, so that risks to health, safety and fundamental rights are minimised. Deployers must assign oversight to competent individuals with the authority and understanding to intervene or halt a system.

Responsibility should sit with a role independent of the team that benefits from the system running. An overseer who reports to the person whose targets depend on the system staying live is not in a position to stop it. That independence is the reason oversight sign-off should not belong to whoever owns AI adoption.

Does the EU AI Act apply to UK or other non-EU organisations?

Yes, frequently. The Act has extraterritorial reach. A UK organisation is in scope if it places an AI system on the EU market, puts one into service in the EU, or the output of its AI system is used within the EU.

Being established outside the EU does not put you outside the Act. If you serve EU customers, or your AI produces output that is used in the EU, assess your exposure and assign owners as if you were established there. The practical test is where the system or its output lands, not where your registered office sits.

When do the main EU AI Act obligations take effect?

The Act entered into force on 1 August 2024, with obligations phasing in over several years. The dates worth putting in a plan:

  • 2 February 2025: prohibited-practice bans and the AI literacy obligation
  • 2 August 2025: governance rules and general-purpose AI model obligations
  • 2 August 2026: the Commission’s enforcement powers and the remaining governance provisions
  • 2 December 2027: high-risk obligations for standalone Annex III systems
  • 2 August 2028: high-risk obligations for AI embedded in already-regulated Annex I products

The last two dates moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred the high-risk deadlines from their original 2026 and 2027 positions. The prohibitions in force since February 2025 and the general-purpose AI rules from August 2025 are unaffected. Our EU AI Act preparedness guide carries the full timeline.

Can the same person own both AI adoption and AI risk sign-off under the Act?

We strongly advise against it. Combining adoption and risk sign-off in one role creates a structural conflict: the person who benefits from a system going live also decides whether it is safe to do so.

The Act’s emphasis on effective risk management and independent human oversight presumes these functions can act as a genuine check on one another. Separating them, even within a small team, protects both the organisation and the individual holding the role, and it makes the accountability story credible to a regulator who asks who could have stopped the deployment.

What evidence do we need to prove accountability under the EU AI Act?

Expect to show that each obligation has a named owner and that the function is actually performed. In practice that means:

  • Technical documentation and conformity records for high-risk systems
  • Risk management artefacts covering the full system lifecycle
  • Documented human oversight arrangements, with named overseers
  • AI literacy training records, dated and attributed
  • Post-market monitoring output and serious-incident reporting logs

A RACI that maps every statutory function to an owner, backed by dated evidence, is the practical form this takes. An aligned ISO 42001 management system can supply much of the structure, though certification alone does not discharge the statutory duties.

Map every duty to a named owner

AI Act Preparedness maps each statutory function to an accountable owner and builds the dated evidence that makes the mapping defensible.