Who should be responsible for AI in a small company?
A small company can often make people in existing roles responsible for AI, rather than creating a new position. It needs one person who owns the AI programme, a named owner for each AI use case, and a clear point at which legal, data protection and security specialists join in. Company size alone does not determine how complex or risky the AI use is: a small firm screening job applicants may need more structure than a larger one using a writing assistant.
Who is responsible for AI at each level
- The AI programme owner. One person coordinates the approach to AI: keeps the AI inventory up to date, runs the approval of new AI use cases and reports to leadership. This is often part of an existing job, for example an operations lead or a founder.
- Use case owners. Each AI use case, such as a support chatbot or a coding assistant, has an owner in the team that uses it. That person watches the quality of its output and is the first contact when something goes wrong.
- Specialists when needed. Legal counsel, the data protection officer (DPO) or whoever handles data protection, and security join when a use case calls for them: personal data, customer contracts, connections to company systems, or decisions that affect people. External advisers can fill these roles.
A title is not enough
A common failure is naming an AI lead without giving them the means to act. Recommendation: put two things in writing.
- Time. A set share of working hours, agreed with leadership. Without it, AI governance slips behind everyday work.
- Authority to pause a use case. The programme owner can suspend an AI tool when a serious problem appears, such as a data leak, harmful output or a pattern of complaints. Leadership reviews it afterwards.
Hypothetical example: a marketing agency names its operations manager as AI lead but gives her no hours and no say over client projects. When a team pastes client data into a free AI tool, she can raise the issue but cannot stop it. With written authority to pause, she could have halted it the same day.
The same authority matters for the harder call of when to stop or avoid using AI altogether.
Voluntary standards and frameworks. Both ISO/IEC 42001, the certifiable standard for AI management systems, and the NIST AI Risk Management Framework treat clearly assigned roles, responsibilities and authority as a basic part of managing AI. Appointing a responsible person is a foundation, not proof of compliance.
Next step: appoint the AI programme owner and write down, on one page, their time for the role and their authority, including the right to pause a use case.
Sources and further reading
AI Horizon Conference
The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.