Skip to main content
Connic
Back to BlogIndustry Insights

Who Owns EU AI Act Readiness? Evidence from 2,390 DPOs

A 2025 survey of 2,390 DPOs shows EU AI Act work landing with them; here is how product, engineering, legal, and security teams can share it.

September 28, 202610 min readAuthor: Connic Research Team

The EU AI Act does not say who inside an organisation owns readiness work, and a 2025 survey of 2,390 data protection officers (DPOs) shows much of it landing with people who mostly work alone and part-time. Two thirds have no budget, and 85% have had no AI training. Readiness needs named owners for the AI inventory, assessments, controls, incidents, and evidence, with the DPO reviewing and monitoring.

What the Survey Measured

The study is the 2025 edition of an observatory of the DPO profession that France’s employment and vocational training directorate (DGEFP) and the CNIL have run since 2018, together with the adult vocational training agency Afpa and AFCDP, the French association of data protection officers. Afpa conducted the 2025 edition. The labour ministry, AFCDP, and the CNIL published the results on July 3, 2026, and the CNIL followed with an English summary on September 22, 2026.

According to the survey report, the online questionnaire ran from November 5 to 21, 2025. The CNIL promoted it to the 38,000 designated DPOs, and AFCDP relayed it to its members. 2,390 DPOs answered: 1,896 internal DPOs, 234 internal DPOs shared across several organisations, and 260 external DPOs working as service providers. The report states a 95% confidence level with a 2% margin of error for the full sample and describes it as representative of DPOs in France.

Every respondent works for an organisation that has designated a DPO, a group the report describes as particularly exposed to data protection issues. The figures are the DPO’s own assessment of that organisation. Apart from the adoption rates, the percentages from the section on AI use onward cover only organisations that use AI or plan to, except in the sections on training and on DPOs’ own use of AI.

AI Adoption Is Ahead of Governance

Most of the organisations already use AI or plan to: 46% use it and 24% have a project, 70% in total. The share rises with size, from 46% of organisations with fewer than 50 employees to 91% of those with 1,000 or more. Among organisations that use or plan to use AI, 81% rely on generative AI. Most systems are bought: 73% come from external providers, 16% are built in-house, and 6% are developed with a partner. More than half of DPOs (58%) say the AI systems used in their organisation process personal data.

Governance lags behind that adoption. Among organisations that use or plan to use AI, the survey report records:

MeasureShareBreakdown
Formal AI strategy or policy19%46% in preparation, 31% none. 12% under 50 employees, 26% at 1,000 or more.
Prepared or preparing for the AI Act31%6% very well prepared, 25% in preparation. 35% in the private sector, 25% in the public sector.
Not yet preparing55%28% aware without concrete action, 27% little or not informed.
AI ethics committee or similar body20%Where one exists, 66% of DPOs take part regularly.
Staff awareness actions or AI usage charter32%48% planned, 14% none.

DPOs consider a further 10% of organisations not concerned because they use no AI that the AI Act treats as risky, and 4% do not know how prepared their organisation is. Readiness also rises with size: 20% of organisations under 50 employees are prepared or preparing, against 40% of those with 1,000 or more.

The Timeline Moved After Fieldwork

The questionnaire closed in November 2025, months before the AI Omnibus was adopted. Regulation (EU) 2026/1744 entered into force on July 27, 2026 and moved the high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems. The original prohibitions have applied since February 2025, and new prohibitions apply from December 2, 2026. The Article 50 transparency duties have applied since August 2, 2026, with a transition to December 2, 2026 for the Article 50(2) marking duty on systems placed on the market before August 2, 2026. The Omnibus also rewrote Article 4: providers and deployers must take measures to support the development of AI literacy among their staff, without having to guarantee a specific level for each individual.

Apart from the Article 50(2) transition, the extra time covers high-risk systems only. An organisation that had not started preparing in late 2025 still needs an inventory to know which of its systems fall under Article 50 today and which may become high-risk later. The EU AI Act enforcement guide covers the full schedule and the authorities involved.

DPOs Are Absorbing AI Act Work

Among DPOs at organisations that use or plan to use AI, 55% say AI Act compliance already falls within their responsibilities, and 71% want the DPO role formally extended to monitoring AI Act compliance. The regulation does not assign that work to them. In her foreword to the report, CNIL president Marie-Laure Denis notes that the AI Act does not mention the DPO, one reason part of the profession sees AI Act compliance as outside its remit.

The capacity behind those answers is thin. Across all respondents, 77% work alone without a team and 66% have no budget. Among internal and shared DPOs, 85% work part-time, 60% spend a quarter of their working time or less on DPO duties, and 41% work in organisations with fewer than 250 employees.

Knowledge and training have not caught up with the scope. Among DPOs at organisations using or planning AI, 27% rate their AI Act knowledge as good or very good, 64% as limited or basic, and 9% say they have none. Across all respondents, 85% have had no AI-specific training, compared with 87% in the 2024 edition, and 16% plan to take some. Only 4% have tools or methods suited to assessing AI Act compliance, and 64% say they lack them. For the GDPR compliance of AI systems, 36% have such tools.

Who Oversees AI Today

Where an AI strategy exists or is being drafted, DPOs name the IT department or CTO as a main supervisor of AI projects in 44% of cases, the DPO or data protection team in 39%, and executive management in 29%. The figures add up to more than 100%, so some respondents named more than one function.

Most DPOs (58%) are always or often involved in their organisation’s AI projects, and 42% rarely or never. Asked when, 42% say they are involved throughout the process, while others name specific stages such as the period before production deployment (26%) or operation and post-deployment monitoring (18%). Getting involved early enough is difficult for 40%, and for 48% in the public sector. On a five-point scale, 39% rate their collaboration with the teams that develop or deploy AI at one of the two lowest levels.

Where Readiness Work Stalls

On AI projects in general, 54% of DPOs cite a legal framework that is unclear or still changing, 49% a lack of time or dedicated resources, 44% a lack of clear documentation on AI systems, and 43% difficulty translating GDPR principles into technical requirements. In our assessment, most of the AI Act challenges they name depend on information that other teams hold:

AI Act challengeDPOsDepends on (our assessment)
Identifying each system’s risk level62%Intended purpose, users, and affected people
Documenting systems and obtaining provider documentation53%Vendor contracts, technical documentation, integration details
Aligning DPIAs with fundamental rights impact assessments41%Processing records and the deployment context
Detecting, preventing, and correcting bias40%Test data, evaluation results, model behavior
Ensuring reliable outputs and decisions39%Runtime logs, monitoring, incident history

Because 73% of systems are bought from providers, much of that documentation sits with vendors and with the teams that selected and integrated each system. Most DPOs also work part-time on the role, so one person is unlikely to collect it for every system. The AI Act places these obligations on providers and deployers as organisations, so the collection work can be assigned to the people closest to each system.

A Practical Responsibility Split

The split below is our proposal and goes beyond the survey data. It is meant for organisations that build or buy AI systems, including AI agents. Each task stays with the function that holds the information, and the DPO keeps the advisory and monitoring role that GDPR already defines.

TaskAccountable ownerDPO role
AI system inventoryProduct or business owner of each use caseChecks entries that involve personal data against the record of processing activities
Preliminary role and risk assessmentProduct owner with legal counselReviews personal-data aspects and flags where a DPIA is needed
Provider documentation and contractsProcurement with engineeringReviews data processing terms and transfers
Technical controls: logging, oversight gates, evaluationEngineering or platform teamReviews the evidence without configuring the controls
Human oversight for high-risk systemsBusiness team that operates the systemAdvises where oversight decisions affect data subjects
Article 50 disclosuresProduct and engineeringKeeps disclosures consistent with GDPR privacy notices
Incidents and authority notificationSecurity with legalAssesses whether an AI incident is also a personal data breach
DPIAThe controller, led by the business ownerAdvises and monitors its performance
AI literacy measuresHR or managementContributes the data protection part of staff training
Evidence pack for auditors and authoritiesLegal or compliance leadReviews and exports the record, with read access to all of it

Why the DPO Should Advise and Monitor

Article 39 of the General Data Protection Regulation sets the DPO’s minimum tasks: informing and advising the organisation and its staff, monitoring compliance, advising on DPIAs, cooperating with the supervisory authority, and acting as its contact point. Article 38(6) allows other tasks only if they do not create a conflict of interests. A DPO who decides which AI system to buy, how to configure it, and whether its risk classification is acceptable would end up monitoring those same decisions.

GDPR also places duties on the organisation. Article 38(1) requires controllers to involve the DPO properly and in a timely manner in all issues relating to the protection of personal data, and Article 38(2) requires them to provide the resources the DPO needs. Where AI systems process personal data, as 58% of DPOs report for their organisation, those duties already apply.

The 71% of DPOs who want a formal AI Act role can take one within those limits: reviewing assessments, monitoring controls, and contributing to staff training, while product and engineering own the systems themselves.

Scaling the Split by DPO Profile

The report groups respondents into three profiles based on time, team, budget, experience, expertise, and organisation size. The occasional profile (DPO Ponctuel, 32%) has little dedicated time, no team, and no budget, and works mostly in organisations under 250 employees. Only 2% of this group spend three quarters of their time or more on the role, and 9% report a formal AI strategy. The mission profile (DPO Mission, 52%) has little dedicated time but significant data protection experience, and 35% have a budget. The dedicated profile (DPO Métier, 16%) works almost full-time on the role: 93% have a budget, 53% a team, and 31% report a formal AI strategy.

In an organisation with an occasional-profile DPO, the split is likely to land on two or three people. A named product owner for each AI system and external counsel for legal review then matter more than a wider DPO remit, and the DPO can stay focused on personal-data review. An organisation with a dedicated-profile DPO can give the data protection team formal review of every assessment and a standing seat in incident review.

Recording Ownership in Connic

If your agents run on Connic, the Enterprise AI Governance feature keeps most of that split in one record. Each AI system records its intended purpose, owner, geographies, and affected people, and links to the environments, deployments, and agents that implement it. Controls, monitoring plans, and incident corrective actions carry their own owners, and each control is marked as provided by Connic, owned by your organisation, shared, or handled outside the platform.

Assessments are versioned and never edited in place. Each version records who created it, its rationale, and who reviewed it, and only the latest version can be approved. When your DPO or counsel records that review, it stays visible next to the assessment.

Access for each role
AI Governance has separate permissions to view the record, manage it, export evidence, and manage incidents, and custom permission groups let you combine them. A DPO with view and export access can read every system and export evidence without changing anything. Recording a formal assessment review needs the manage permission, which also allows editing systems and controls and creating new assessment versions. Incident access can be granted to security separately. Every change is written to the project audit log.

The AI Governance documentation describes the full workflow, and the feature overview shows the record, controls, and evidence exports.

Legal boundaries
AI Governance is a documentation and evidence workflow. Assessment results are preliminary, and final classification, reporting deadlines, and the legal sufficiency of any evidence remain with your organisation and its counsel.
Assign AI Act owners in one record

We walk through your AI systems with you, map owners and controls in AI Governance, and set up review and export access for your DPO and counsel.

Discuss AI governance

Frequently Asked Questions

No. The AI Act does not mention the DPO or create a comparable role; its obligations fall mainly on providers and deployers as organisations. GDPR still requires a DPO in the cases set out in its Article 37, and the organisation must involve that DPO properly and in a timely manner when AI systems process personal data.

The DPO can take on AI Act tasks, provided they do not create a conflict of interests under GDPR Article 38(6). In the 2025 survey, 55% of DPOs at organisations using or planning AI said AI Act compliance already falls within their responsibilities. Advising, reviewing assessments, and monitoring controls fit the role. Deciding which systems to deploy and how to configure them is harder to reconcile with independent monitoring.

It covers 2,390 DPOs in France who answered an online questionnaire from November 5 to 21, 2025, promoted to 38,000 designated DPOs. The report states a 95% confidence level and a 2% margin of error for the full sample and calls it representative of DPOs in France. Most AI results cover only organisations using or planning AI, reflect each DPO's view of their organisation, and were collected months before the AI Omnibus changed the high-risk timeline.

15%. In the 2025 survey, 85% of DPOs had no AI-specific training, compared with 87% in the 2024 edition. DPOs at organisations with 1,000 or more employees were more likely to be trained (23%) than those at organisations with fewer than 50 employees (8%).

The product or business owner of each use case, because they know its purpose, users, vendor, and deployment, with the DPO reviewing entries that involve personal data. In the 2025 survey, DPOs at organisations with an AI strategy in place or in progress named IT or the CTO as a main supervisor of AI projects in 44% of cases and the DPO in 39%.

More from the Blog

Industry Insights

AI Agent Platform SLA Checklist: What Enterprise Buyers Should Verify

Evaluate an AI agent platform SLA across uptime scope, dependencies, incident response, recovery, security evidence, remedies, and exit terms.

August 29, 202612 min read
Industry Insights

EU-Hosted AI Models in 2026: Providers, Dependence & Options

EU-hosted AI models compared by location, retention, operator, portability, legal exposure, and deployment model, using a 2026 Commission-requested study.

August 18, 202611 min read
Industry Insights

EU AI Gigafactories: What the €30B Plan Means for Enterprise AI

The EU's €30B Gigafactory plan could expand compute, while eligible AI SMEs can apply for AI Factory access through Playground, Fast Lane or Large Scale.

August 14, 202615 min read
Industry Insights

AI Agent Platforms With EU Data Residency: 2026 Shortlist

AI agent platforms compared by EU data residency, including where traces, storage, model calls, backups, subprocessors, and support access are processed.

July 6, 202612 min read
Industry Insights

Webhook vs Kafka vs SQS vs Postgres for AI Agent Triggers

Webhook, Kafka, SQS, and Postgres LISTEN/NOTIFY compared as AI agent triggers by delivery guarantees, ordering, replay, latency, and failure behavior.

June 29, 20269 min read
Industry Insights

Pre-built AI Agent Connectors: Platforms Compared (2026)

Pre-built AI agent connectors compared by platform, supported modes, documented recovery behavior, official sources, and production trade-offs.

June 16, 202615 min read
Industry Insights

The Real Cost of Assembling an AI Agent Stack

The real cost of assembling an AI agent stack comes from the integration and maintenance tax between tools. The comparison explains when an integrated platform makes sense.

June 9, 202610 min read
Industry Insights

Managed vs Self-Hosted AI Agents: TCO at 50K LLM-Agent Runs

Managed vs self-hosted AI agents at 50,000 monthly LLM-agent runs: compare Connic, custom-build, and service-stack costs in a transparent three-year model.

May 16, 202614 min read
Industry Insights

EU AI Act Enforcement: Who Investigates and What Evidence to Keep

The AI Office, national authorities, and EDPS divide EU AI Act enforcement by system and provider; teams should keep scoped governance and runtime evidence.

April 13, 202614 min read