Who is responsible for AI when there is no IT department?
Without an IT department, AI still needs an owner. Which decisions genuinely require one, why an AI committee is the wrong reflex, and what belongs on a one-page AI policy.
Responsibility sits with the management, and it can be delegated to exactly one named person with decision authority. Without an IT department that role usually lands with someone already close to processes: the commercial lead, quality management, or whoever coordinates data protection. The failure is rarely the wrong person. The failure is that nobody is named, so the decisions quietly dissolve into day-to-day work.
What you’ll take away:
- The EU AI Act does not require an AI officer. It requires measures and evidence of them, and evidence needs a sender.
- Four decisions genuinely need an owner. Everything else is day-to-day work.
- An AI committee is the most common misstep in companies under 300 staff. It slows things down without clarifying responsibility.
- The AI policy that actually works in daily practice fits on one page and answers three questions.
- Missing ownership is a more likely cause of shadow AI than missing tools.
Who is responsible for AI when there is no IT department?
Management carries the responsibility and can delegate the operational side to a named person. That person needs three things: authority over tool approvals, access to management, and a fixed time budget. Technical AI expertise deliberately is not on that list, because expertise can be bought in while decision authority cannot.
In companies between 20 and 500 staff this role almost always sits with someone who already has an overview of processes. Often that is the commercial lead, in manufacturing frequently quality management, occasionally the executive assistant. Whoever coordinates data protection already brings the right reflex for data questions.
What regularly fails is assigning it to “the person who’s good with computers”. That person usually has neither authority nor time, and gets made responsible for tool questions while the actual decisions are commercial ones.
Which decisions genuinely need an owner?
Four. Everything beyond that is day-to-day work and only costs coordination.
First, tool approval. Which AI applications may be used in the business, and who carries the licence cost? Without this decision, individual subscriptions appear on private cards.
Second, the data boundary. Which information may go into an AI tool and which may not? This question is not technical. It is a question of confidentiality levels, which most companies already have.
Third, training. Which roles work with AI and therefore need qualification under Article 4 of the EU AI Act? The Digital Omnibus turned this into an obligation to act and to document, and a record needs someone who keeps it.
Fourth, labelling. Where do AI-generated contents leave the building, and who checks they are recognisable under Article 50? That obligation has been applicable and enforceable since 2 August 2026, with a transition period for legacy systems until 2 December 2026.
Do I need an AI officer?
As a legally required function, no. The EU AI Act has no AI officer comparable to a data protection officer. Article 4 requires measures to foster AI literacy and evidence of them, and Article 50 requires transparency towards the outside. Both presuppose a responsible person without prescribing a job title.
In practice the title is still useful, because it makes visible inside the company who to turn to. Whether the org chart says “AI officer”, “digital lead” or nothing at all matters less than whether the person may actually take the four decisions above.
One boundary is worth drawing: this role is not a compliance function with independence, as in data protection. It is a line responsibility. Set it up as a control body and you get a control body people work around.
Why is an AI committee usually the wrong route?
Because it distributes the responsibility question instead of answering it. In companies under roughly 300 staff, the AI working group is the most common reflex and the most common dead end: four to six people meet monthly, collect ideas, and at the end nobody has decided which tool is approved.
The reason is structural. A committee is good at evaluating options and bad at carrying responsibility. The four decisions above are approval decisions with cost and liability consequences, and those need a signature.
A group becomes useful later and in a different function: as a feedback channel from the departments, once the basic decisions are made and it is about use cases. In that role it is valuable, because the best use cases rarely come from the management floor.
What belongs in an AI policy that actually helps day to day?
One page, three questions. Which tools are approved, which data may go in, and who do I ask when in doubt? Anything beyond that goes unread and therefore changes no behaviour.
What really decides the effect is the sequence. A policy without an approved tool is a ban, and bans move usage into private accounts rather than ending it. First the official route that is at least as convenient as the unofficial one, then the rule about it.
The second factor is the contact person. “When in doubt, ask X” is the line most often needed in daily work, and it is missing from most policies. Without it everyone decides for themselves, which is exactly what the policy set out to prevent.
Is missing ownership really the cause of shadow AI?
More often than missing tools. Shadow AI appears when someone can finish a task faster and the official route is unclear. Unclear rarely means “there is no tool”. It usually means “I don’t know whether I’m allowed, and I don’t know who to ask”.
This is where the ownership question becomes concrete. As soon as there is a named person and an approved tool list, the grey zone in which shadow AI grows disappears. The competence to recognise the boundary at all comes with qualification: the PASSION4IT Academy covers this in role-specific learning paths without classroom dates, with a certificate per module for the documentation.
What this role does not have to deliver is a substantive evaluation of every tool. That is what the AI workshop is for, at a fixed price of 3,900 euros, prioritising use cases and producing the roadmap in six hours. The internal role decides afterwards, it does not research beforehand.
Frequently asked questions (FAQ)
Who is responsible for AI when there is no IT department?
Management, with the operational side delegated to a named person who has decision authority, access to management and a fixed time budget. In companies between 20 and 500 staff the role usually sits with the commercial lead, quality management or data protection coordination.
Does the EU AI Act require an AI officer?
No. There is no mandatory function comparable to a data protection officer. Article 4 has required measures to foster AI literacy and evidence of them since 2 February 2025, Article 50 has required outward transparency since 2 August 2026. Both presuppose a responsible person without prescribing a title.
Which decisions must this person be allowed to take?
Four: approval of AI tools including licence costs, the boundary for confidential data, the training need per role, and the labelling of AI content that leaves the company. Without authority over these four points the role has no effect.
Does this person need AI expertise?
Not necessarily. Expertise can be bought in, whereas decision authority and knowledge of your own processes cannot. More important than technical understanding is that the person has an overview of workflows and access to management.
Should I set up an AI working group?
In companies under roughly 300 staff, rarely as a starting point. A committee distributes responsibility instead of clarifying it, and approval decisions with cost and liability consequences need a signature. Such a group becomes valuable as a feedback channel for use cases once the basic decisions are made.
What has to be in an AI policy?
Three things on one page: the approved tools, the data boundary, and the contact person for doubtful cases. The sequence matters, because a policy without an approved tool acts as a ban and moves usage into private accounts.
How does ownership relate to shadow AI?
Shadow AI grows in the grey zone between “maybe I’m not allowed” and “I don’t know who to ask”. A named person plus an approved tool list closes that grey zone. Bans alone relocate usage rather than ending it.
When is external support worth it?
For prioritising use cases and building the roadmap, which is exactly where internal role holders otherwise research for months. The PASSION4IT AI workshop costs 3,900 euros net at a fixed price for six hours and is eligible for BAFA funding; PASSION4IT is registered with BAFA, consultant number 222542.
Further reading
- AI adoption in mid-sized companies without an IT department: what’s realistic? for technical feasibility, before the ownership question.
- How do I meet the EU AI Act training obligation for my business? for the record this role has to keep.
- How does an SME use AI in accounting without having its own IT department? for the first concrete use case.
Nobody named yet, but the tools are already in the building? Book a conversation.
Sources: AI Regulation Art. 4 and Art. 50 · Regulation (EU) 2026/1744 (Digital Omnibus Regulation on AI), in force since 27 July 2026 · BAFA, funding for management consulting for SMEs. Practical guidance, not legal advice. As of 11 August 2026.