It always arrives the same way. You've built the inventory. You've sorted your tools into the Act's risk categories. The room is nodding. Then someone senior leans back and asks: "Fine — so who's accountable for all this?"
It's the question every AI Act conversation ends on, and it deserves a straight answer. This page — part of our full guide to the EU AI Act for UK and Irish businesses — maps the human accountability structure the Act actually requires. The short version, and the reassurance, up front: the AI Act does not create a new statutory officer the way GDPR created (or repurposed) the DPO. Nobody in Brussels is waiting for your "AI Officer" job advert. What the Act cares about is that certain roles exist, are competent, and are written down. That's a governance exercise, not a hiring exercise.
One framing before the detail, because it unlocks everything else: the Act assigns obligations to roles, not job titles. Provider and deployer are functions you perform per system, not departments you staff. Regulators and auditors don't accept "the AI did it" — and they don't accept "the team did it" either.
First, sort the hats: provider vs deployer
Every governance duty in the Act flows from which hat you wear for a given system:
- Provider — you build, brand, or substantially modify an AI system and put it on the EU market. Article 16 duties attach: risk management, data governance, technical documentation, post-market monitoring, corrective actions.
- Deployer — you use an AI system under its instructions, in your own name, for your own purposes. Article 26 duties attach: human oversight, log retention, incident reporting, informing affected people, feeding relevant, sufficient data into the system.
Most SMEs are deployers for almost everything — the CRM add-on, the copywriting assistant, the CV-screening tool. But the line is closer than it looks: a bespoke client-facing AI tool, white-labelled or substantially modified, can flip you to provider overnight. Which is why the governance map has to say, per system, which hat you're wearing — and that column lives in the inventory, not in anyone's memory.
The provider-side roles
If any system in your inventory carries the provider hat, three roles matter:
Providers · high-risk systems
The responsible person for compliance — Article 25(5)
Providers of high-risk systems must designate a natural or legal person responsible for compliance — internal to the organisation, with the authority and resources to actually do the job. This is not a new badge from Brussels; it's the company naming its owner. If nobody is named, nobody is responsible — and that is the finding.
Providers · high-risk systems
Management accountability — Article 25(1)
Providers must have management structures and procedures that let them demonstrate compliance. Translation: governance can't be delegated below the level that owns the risk. The intern doesn't sign off the risk assessment; the level that profits from the system answers for it.
Providers established outside the EU
The authorised representative — Article 22
Non-EU providers need a representative established in the EU. If you buy from a US AI vendor, this is part of your due diligence: does your vendor's compliance structure even reach into the EU? If the answer is a shrug, the accountability chain has a hole in it — and it's on your side of the invoice.
The deployer-side roles: where most SMEs live
Five roles, none of them a job advert. Each is a named person wearing a hat they already own:
Per system · costs nothing
The AI owner
A named person accountable for each AI tool: its purpose, its risk class, its review cadence. This is the single most effective governance control an SME can introduce — it costs nothing and it catches everything. Every line of your inventory should end in a name.
High-risk systems · Article 26(5)
Human overseers
Deployers of high-risk systems must assign oversight to persons with the competence, training, authority and necessary support to do the job. Authority is the word people skip: an overseer who can't override the system isn't an overseer — they're a spectator with a job title.
Every provider and deployer · Article 4
The literacy owner
Regardless of risk class, everyone using AI must ensure staff have a sufficient level of AI literacy — and someone has to own the training plan and the records of who was trained, when, and to what depth. This one has been live since February 2025.
High-risk systems · Article 26(6)
The log keeper
Deployers keep automatically generated logs for at least six months. Someone must own where logs go and how long they're kept — before the retention question is asked by someone with a badge.
Serious incidents · Article 73
The incident reporter
Serious incidents must flow from deployer to provider — and to authorities where relevant — immediately or without undue delay. Someone needs to know the escalation path before the incident, not during it. Write the path down; incidents are a bad time for improvisation.
The board's role: where the buck actually stops
No article of the AI Act creates a "Director of AI." But don't mistake the absence of a title for the absence of a duty. Management accountability (Article 25(1)) reaches providers; certain deployers — including some banks, insurers and public-service providers — must complete a fundamental rights impact assessment before first use (Article 27); and the general direction of travel is unmistakable: the board or MD owns AI risk like any other operational risk. Approve the policy, fund the controls, review annually.
If you want one line for the minutes that would satisfy most auditors today: "AI use is inventoried, owned, and reviewed." Nine words. If it's true, you're most of the way there.
The one-page accountability map
This is the centrepiece: bookmarkable, printable, and designed to survive a leadership meeting. Six lines, top to bottom:
- Board / MD — approves the AI policy, funds the controls, reviews the picture annually.
- AI governance lead — an existing senior hire (COO, ops lead, or the DPO wearing a second hat) who owns the inventory, the risk classification, and this map.
- System owners — one per AI tool: purpose, compliance, review cadence.
- Human overseers — trained, authorised, and supported for every high-risk system (Article 26(5)).
- Procurement — vendor due diligence: Declaration of Conformity, instructions for use, EU representative, log access (Article 13).
- All staff — AI literacy to the depth their use requires (Article 4), and a duty to report incidents and shadow AI — tools nobody owns.
A note on scale: in a 20-person firm, this map is two names. In a 250-person firm, it's a diagram. The Act doesn't care which — it cares that it's written down. If you're not sure how much of this map already exists in your business, take the AI Act quiz (two minutes) — it flags which governance duties already apply to a business your size.
Timing: when governance duties bite
The calendar, post-Omnibus — pin these deliberately rather than from memory:
✅ In force since 2 February 2025
AI literacy (Article 4)
Every provider and deployer, regardless of risk class — the literacy owner role is live now.
✅ In force since 2 August 2026
Transparency (Article 50)
Disclosure and labelling duties for chatbots and synthetic content.
2 December 2027
Annex III high-risk regime
Responsible person for compliance (Art. 25(5)), human oversight and logs (Art. 26(5)/(6)), FRIA under Art. 27 for in-scope deployers.
2 August 2028
Annex I embedded high-risk
AI embedded in regulated products (machinery, medical devices and similar) follows a year later.
The point of the strip: the names-on-a-page habit starts now, because client due-diligence, tenders and audits are already asking — they don't schedule their questions around the Act's transitional dates.
The takeaway
No new statutory officer. No mandatory job title. One page, named people, per-hat clarity: provider roles if you build or brand, deployer roles for everything you use, and a board that treats AI like the operational risk it has already become. The AI Act doesn't ask who your AI officer is — it asks who signs, who oversees, and who answers when it goes wrong. Make sure the answer is a name, not a shrug.
Next step: take the AI Act quiz — two minutes, and it flags which governance duties already apply to a business your size. If you already know you want hands on deck, AI Act Readiness is the human-led route. (Practical guidance throughout — not legal advice.)