The EU AI Act does not say who inside an organisation owns readiness work, and a 2025 survey of 2,390 data protection officers (DPOs) shows much of it landing with people who mostly work alone and part-time. Two thirds have no budget, and 85% have had no AI training. Readiness needs named owners for the AI inventory, assessments, controls, incidents, and evidence, with the DPO reviewing and monitoring.
What the Survey Measured
The study is the 2025 edition of an observatory of the DPO profession that France’s employment and vocational training directorate (DGEFP) and the CNIL have run since 2018, together with the adult vocational training agency Afpa and AFCDP, the French association of data protection officers. Afpa conducted the 2025 edition. The labour ministry, AFCDP, and the CNIL published the results on July 3, 2026, and the CNIL followed with an English summary on September 22, 2026.
According to the survey report, the online questionnaire ran from November 5 to 21, 2025. The CNIL promoted it to the 38,000 designated DPOs, and AFCDP relayed it to its members. 2,390 DPOs answered: 1,896 internal DPOs, 234 internal DPOs shared across several organisations, and 260 external DPOs working as service providers. The report states a 95% confidence level with a 2% margin of error for the full sample and describes it as representative of DPOs in France.
Every respondent works for an organisation that has designated a DPO, a group the report describes as particularly exposed to data protection issues. The figures are the DPO’s own assessment of that organisation. Apart from the adoption rates, the percentages from the section on AI use onward cover only organisations that use AI or plan to, except in the sections on training and on DPOs’ own use of AI.
AI Adoption Is Ahead of Governance
Most of the organisations already use AI or plan to: 46% use it and 24% have a project, 70% in total. The share rises with size, from 46% of organisations with fewer than 50 employees to 91% of those with 1,000 or more. Among organisations that use or plan to use AI, 81% rely on generative AI. Most systems are bought: 73% come from external providers, 16% are built in-house, and 6% are developed with a partner. More than half of DPOs (58%) say the AI systems used in their organisation process personal data.
Governance lags behind that adoption. Among organisations that use or plan to use AI, the survey report records:
| Measure | Share | Breakdown |
|---|---|---|
| Formal AI strategy or policy | 19% | 46% in preparation, 31% none. 12% under 50 employees, 26% at 1,000 or more. |
| Prepared or preparing for the AI Act | 31% | 6% very well prepared, 25% in preparation. 35% in the private sector, 25% in the public sector. |
| Not yet preparing | 55% | 28% aware without concrete action, 27% little or not informed. |
| AI ethics committee or similar body | 20% | Where one exists, 66% of DPOs take part regularly. |
| Staff awareness actions or AI usage charter | 32% | 48% planned, 14% none. |
DPOs consider a further 10% of organisations not concerned because they use no AI that the AI Act treats as risky, and 4% do not know how prepared their organisation is. Readiness also rises with size: 20% of organisations under 50 employees are prepared or preparing, against 40% of those with 1,000 or more.
The Timeline Moved After Fieldwork
The questionnaire closed in November 2025, months before the AI Omnibus was adopted. Regulation (EU) 2026/1744 entered into force on July 27, 2026 and moved the high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems. The original prohibitions have applied since February 2025, and new prohibitions apply from December 2, 2026. The Article 50 transparency duties have applied since August 2, 2026, with a transition to December 2, 2026 for the Article 50(2) marking duty on systems placed on the market before August 2, 2026. The Omnibus also rewrote Article 4: providers and deployers must take measures to support the development of AI literacy among their staff, without having to guarantee a specific level for each individual.
Apart from the Article 50(2) transition, the extra time covers high-risk systems only. An organisation that had not started preparing in late 2025 still needs an inventory to know which of its systems fall under Article 50 today and which may become high-risk later. The EU AI Act enforcement guide covers the full schedule and the authorities involved.
DPOs Are Absorbing AI Act Work
Among DPOs at organisations that use or plan to use AI, 55% say AI Act compliance already falls within their responsibilities, and 71% want the DPO role formally extended to monitoring AI Act compliance. The regulation does not assign that work to them. In her foreword to the report, CNIL president Marie-Laure Denis notes that the AI Act does not mention the DPO, one reason part of the profession sees AI Act compliance as outside its remit.
The capacity behind those answers is thin. Across all respondents, 77% work alone without a team and 66% have no budget. Among internal and shared DPOs, 85% work part-time, 60% spend a quarter of their working time or less on DPO duties, and 41% work in organisations with fewer than 250 employees.
Knowledge and training have not caught up with the scope. Among DPOs at organisations using or planning AI, 27% rate their AI Act knowledge as good or very good, 64% as limited or basic, and 9% say they have none. Across all respondents, 85% have had no AI-specific training, compared with 87% in the 2024 edition, and 16% plan to take some. Only 4% have tools or methods suited to assessing AI Act compliance, and 64% say they lack them. For the GDPR compliance of AI systems, 36% have such tools.
Who Oversees AI Today
Where an AI strategy exists or is being drafted, DPOs name the IT department or CTO as a main supervisor of AI projects in 44% of cases, the DPO or data protection team in 39%, and executive management in 29%. The figures add up to more than 100%, so some respondents named more than one function.
Most DPOs (58%) are always or often involved in their organisation’s AI projects, and 42% rarely or never. Asked when, 42% say they are involved throughout the process, while others name specific stages such as the period before production deployment (26%) or operation and post-deployment monitoring (18%). Getting involved early enough is difficult for 40%, and for 48% in the public sector. On a five-point scale, 39% rate their collaboration with the teams that develop or deploy AI at one of the two lowest levels.
Where Readiness Work Stalls
On AI projects in general, 54% of DPOs cite a legal framework that is unclear or still changing, 49% a lack of time or dedicated resources, 44% a lack of clear documentation on AI systems, and 43% difficulty translating GDPR principles into technical requirements. In our assessment, most of the AI Act challenges they name depend on information that other teams hold:
| AI Act challenge | DPOs | Depends on (our assessment) |
|---|---|---|
| Identifying each system’s risk level | 62% | Intended purpose, users, and affected people |
| Documenting systems and obtaining provider documentation | 53% | Vendor contracts, technical documentation, integration details |
| Aligning DPIAs with fundamental rights impact assessments | 41% | Processing records and the deployment context |
| Detecting, preventing, and correcting bias | 40% | Test data, evaluation results, model behavior |
| Ensuring reliable outputs and decisions | 39% | Runtime logs, monitoring, incident history |
Because 73% of systems are bought from providers, much of that documentation sits with vendors and with the teams that selected and integrated each system. Most DPOs also work part-time on the role, so one person is unlikely to collect it for every system. The AI Act places these obligations on providers and deployers as organisations, so the collection work can be assigned to the people closest to each system.
A Practical Responsibility Split
The split below is our proposal and goes beyond the survey data. It is meant for organisations that build or buy AI systems, including AI agents. Each task stays with the function that holds the information, and the DPO keeps the advisory and monitoring role that GDPR already defines.
| Task | Accountable owner | DPO role |
|---|---|---|
| AI system inventory | Product or business owner of each use case | Checks entries that involve personal data against the record of processing activities |
| Preliminary role and risk assessment | Product owner with legal counsel | Reviews personal-data aspects and flags where a DPIA is needed |
| Provider documentation and contracts | Procurement with engineering | Reviews data processing terms and transfers |
| Technical controls: logging, oversight gates, evaluation | Engineering or platform team | Reviews the evidence without configuring the controls |
| Human oversight for high-risk systems | Business team that operates the system | Advises where oversight decisions affect data subjects |
| Article 50 disclosures | Product and engineering | Keeps disclosures consistent with GDPR privacy notices |
| Incidents and authority notification | Security with legal | Assesses whether an AI incident is also a personal data breach |
| DPIA | The controller, led by the business owner | Advises and monitors its performance |
| AI literacy measures | HR or management | Contributes the data protection part of staff training |
| Evidence pack for auditors and authorities | Legal or compliance lead | Reviews and exports the record, with read access to all of it |
Why the DPO Should Advise and Monitor
Article 39 of the General Data Protection Regulation sets the DPO’s minimum tasks: informing and advising the organisation and its staff, monitoring compliance, advising on DPIAs, cooperating with the supervisory authority, and acting as its contact point. Article 38(6) allows other tasks only if they do not create a conflict of interests. A DPO who decides which AI system to buy, how to configure it, and whether its risk classification is acceptable would end up monitoring those same decisions.
GDPR also places duties on the organisation. Article 38(1) requires controllers to involve the DPO properly and in a timely manner in all issues relating to the protection of personal data, and Article 38(2) requires them to provide the resources the DPO needs. Where AI systems process personal data, as 58% of DPOs report for their organisation, those duties already apply.
The 71% of DPOs who want a formal AI Act role can take one within those limits: reviewing assessments, monitoring controls, and contributing to staff training, while product and engineering own the systems themselves.
Scaling the Split by DPO Profile
The report groups respondents into three profiles based on time, team, budget, experience, expertise, and organisation size. The occasional profile (DPO Ponctuel, 32%) has little dedicated time, no team, and no budget, and works mostly in organisations under 250 employees. Only 2% of this group spend three quarters of their time or more on the role, and 9% report a formal AI strategy. The mission profile (DPO Mission, 52%) has little dedicated time but significant data protection experience, and 35% have a budget. The dedicated profile (DPO Métier, 16%) works almost full-time on the role: 93% have a budget, 53% a team, and 31% report a formal AI strategy.
In an organisation with an occasional-profile DPO, the split is likely to land on two or three people. A named product owner for each AI system and external counsel for legal review then matter more than a wider DPO remit, and the DPO can stay focused on personal-data review. An organisation with a dedicated-profile DPO can give the data protection team formal review of every assessment and a standing seat in incident review.
Recording Ownership in Connic
If your agents run on Connic, the Enterprise AI Governance feature keeps most of that split in one record. Each AI system records its intended purpose, owner, geographies, and affected people, and links to the environments, deployments, and agents that implement it. Controls, monitoring plans, and incident corrective actions carry their own owners, and each control is marked as provided by Connic, owned by your organisation, shared, or handled outside the platform.
Assessments are versioned and never edited in place. Each version records who created it, its rationale, and who reviewed it, and only the latest version can be approved. When your DPO or counsel records that review, it stays visible next to the assessment.
The AI Governance documentation describes the full workflow, and the feature overview shows the record, controls, and evidence exports.
We walk through your AI systems with you, map owners and controls in AI Governance, and set up review and export access for your DPO and counsel.
Discuss AI governance