Skip to content
Over Unity

Does your company need an AI governance lead?

Short answer

You need someone accountable for AI governance if your systems affect people's rights, safety, or access to services, or if you must comply with rules such as the EU AI Act or UK data protection law. In a small company that role can be part time or shared with an existing compliance lead. What matters is that one named person owns the risk register and the sign-off, not the job title.

The trigger for this role is exposure, not company size on its own. Exposure comes from two directions: regulation that applies to what you build or buy, and the real-world consequences if a system gets something wrong for a person on the other end of it.

On the regulatory side, the EU AI Act can apply even if your company sits outside the EU, if your systems are placed on the EU market or used there. UK data protection law applies whenever personal data feeds a model. Sector rules add further layers in areas such as finance and health.

On the consequence side, think about what happens when the system is wrong. A recommendation engine getting a suggestion wrong is a minor annoyance. A system influencing hiring, credit, or care decisions getting something wrong is a different order of problem, and that gap is what should drive whether you formalise the role.

If your company only uses AI tools internally for productivity, with no effect on customers or regulated decisions, a dedicated governance lead is less urgent. You still need someone who owns an acceptable use policy and can say what data is allowed near which tool.

Where the role does exist, the actual work is fairly concrete. It means keeping a risk register, signing off new AI use before it goes live, keeping an audit trail of decisions, and checking vendor claims rather than accepting a sales deck at face value.

Established frameworks give the role something to hang its structure on. ISO/IEC 42001 sets out an AI management system. The NIST AI Risk Management Framework sets out categories of risk to work through. UK guidance from the Information Commissioner's Office covers the personal data side specifically.

Size still matters for how the role is staffed. A five-person company does not need a full-time governance lead, and that responsibility can sit with a founder or a fractional specialist for a few days a month. A company running AI decisions at scale over a regulated population probably does need someone dedicated to it.

This is separate from a data protection officer, even though the two roles overlap. A data protection officer covers personal data broadly. An AI governance lead covers model-specific risk, including bias, drift, and the ability to explain a decision after the fact. In a smaller company one person can hold both, but that should be reviewed as the company and its use of AI grow.

Related questions

Does the EU AI Act apply to us if we are not based in the EU?

It can apply if you place an AI system on the EU market or if its output is used within the EU, regardless of where your company is registered. Check the text of the regulation directly, or get specific legal advice, rather than assuming either way.

Is ISO/IEC 42001 mandatory?

No, it is a voluntary standard for running an AI management system. Companies use it to show customers and regulators that their governance is structured rather than improvised.

Can one person hold both the data protection and AI governance roles?

Yes, and this is common in smaller companies. Watch for it becoming a conflict of interest as the company grows and its use of AI becomes more central to what it does.

Sources

Over Unity makes introductions between hirers and independent specialists. It is not a party to any engagement, does not hold or transfer payments, and does not determine employment status. Specialists are never charged a fee.