The discussion about who should lead artificial intelligence governance within organizations is no longer theoretical. In Europe, the EU AI Act is already in force and is being applied in stages. In Brazil, Bill PL 2.338/2023 (the Brazilian AI Bill) was approved by the Federal Senate in December 2024 and sent to the Chamber of Deputies in March 2025. In specific sectors, concrete rules already exist, such as Resolution No. 615/2025 of the CNJ (Brazil's National Council of Justice), which sets guidelines for the development, use and governance of AI in the Judiciary. At the same time, the ANPD (Brazilian Data Protection Authority) itself has included artificial intelligence and emerging technologies among its priority enforcement topics for 2026-2027 and has kept AI on its 2025-2026 Regulatory Agenda.
In this scenario, the question “will the DPO be responsible for AI governance?” has gained practical relevance. And the most accurate answer is this: it depends on the organizational context but, as a rule, the DPO should not be the sole owner of AI governance, nor automatically its main person in charge in a broad sense. In many organizations, the DPO can and should play a central role. But turning that role into exclusive ownership of the AI agenda tends to be an oversimplification and, in certain cases, legally or operationally inappropriate.
Why this question has arisen
The question is not artificial. It stems from a real proximity between the privacy and AI agendas.
The EU AI Act works with a logic of risk classification, governance obligations, technical and organizational measures, human oversight, documentation, monitoring, record-keeping, impact assessment and adequate training of the people who operate or use AI systems. The regulation also distributes obligations among different actors, such as providers and deployers, instead of concentrating them in a single corporate function. For deployers of high-risk systems, for example, the act requires appropriate technical and organizational measures, human oversight by people with the necessary competence, training and authority, as well as monitoring and retention of the logs under their control.
The text of PL 2.338/2023 approved by the Senate also follows a governance architecture. It provides for risk classification, governance measures for high-risk systems, algorithmic impact assessment and a National System for the Regulation and Governance of Artificial Intelligence, the SIA, coordinated by the ANPD as the competent authority. The legislative report itself expressly indicates the designation of the ANPD to coordinate this system, and the approved text assigns the ANPD normative, advisory, regulatory and sanctioning functions in the proposed institutional arrangement.
In the Judiciary, CNJ Resolution No. 615/2025 adopts a similar logic. It classifies applications by risk, requires continuous auditing and monitoring for high-risk solutions, mandates governance measures before deployment to production and even allows for algorithmic impact assessment, with effective human oversight throughout the solutions' lifecycle.
The intuition makes sense. But it has limits.
What the DPO actually does and why it matters for AI
Under the Brazilian LGPD, the DPO (encarregado) acts as a communication channel between the controller, data subjects and the ANPD. ANPD regulations also reinforce that the DPO must guide employees and contractors on personal data protection practices, receive communications from the authority, handle data subjects' requests and act with technical autonomy. In addition, the processing agent must provide human, technical and administrative resources, consult the DPO on strategic decisions related to data processing and ensure direct access to the organization's decision-making bodies.
In Europe, the picture is similar. The EDPB (European Data Protection Board) summarizes that the DPO must act independently, without receiving instructions regarding the performance of their tasks, and may take on other duties only when this does not create a conflict of interests. The European board also stresses that the DPO should not hold a position in which they determine the purposes and means of the processing of personal data.
This institutional design makes the DPO especially valuable in AI agendas for five reasons.
- The first is that a large share of AI applications, especially corporate ones, involves the processing of personal data, often at scale, with potentially significant impact on people.
- The second is that the responsible AI agenda shares with privacy the logic of focusing on rights, risk mitigation and accountability.
- The third is that the DPO usually already acts as a point of healthy tension between innovation and the protection of people.
- The fourth is that the DPO often already knows the data map, internal flows, suppliers, incidents, data subject rights and impact assessments.
- The fifth is that the text of PL 2.338/2023 brings the agendas even closer by providing that, when there is also a DPIA under the LGPD, the algorithmic impact assessment may be carried out together with that document.
This point is important. It shows that, from a regulatory standpoint, there is a partial overlap between privacy and AI. But partial overlap is not the same as full identity.
The most common mistake: confusing AI governance with data governance in AI
The DPO is usually a natural figure to lead or co-lead data protection governance related to AI. This includes, for example, assessing the legal basis when personal data are processed, analyzing purpose, necessity and minimization, reviewing transparency and notices, supporting DPIAs and related assessments, interfacing with the rights of affected individuals, reviewing data sharing and transfers, and governing incidents when AI processes personal data.
But AI governance is broader than that.
It may involve model security, technical documentation, robustness, accuracy, operational human oversight, testing, post-deployment monitoring, input data validation, logs, supplier governance, regulatory risk classification, proportionate explainability, user training, sector-specific compliance, labor, consumer and competition issues, copyright, intellectual property, product management and civil liability. The EU AI Act itself distributes obligations among different agents and requires technical and organizational competences for the human oversight of systems, not merely legal or privacy awareness.
So can the DPO be the one responsible?
Yes, but not automatically, and not under just any design.
In smaller organizations, with low technological complexity, few use cases and strong centralization of governance functions, the DPO may be a good candidate to lead the initial implementation of the responsible AI agenda, provided they receive technical support, resources, participation from the business areas and a clear delimitation of scope. In these environments, speed of implementation and the reuse of existing LGPD structures can be real advantages. The Brazilian regime for the DPO itself allows the accumulation of functions, as long as there is no conflict of interest and the duties can be fully performed.
But there is an important regulatory point. Neither under the LGPD nor under ANPD regulations is the DPO legally responsible for the controller's governance. Resolution CD/ANPD No. 18/2024 expressly states that the processing agent is responsible for the compliance of personal data processing and that performing the DPO's activities does not make the DPO responsible, before the ANPD, for the compliance of the processing carried out by the controller.
This logic helps answer the question about AI. Even when the DPO leads, advises on or coordinates an important part of the program, organizational responsibility is not transferred to them as an individual or as an isolated function. In terms of good governance, the most appropriate approach is to view AI governance as a distributed institutional responsibility, sponsored by senior management and with clearly defined roles among legal, privacy, security, technology, product, compliance, risk, audit and the business.
The advantages of placing the DPO at the center of the AI agenda
Even so, there are good arguments for placing the DPO in a central position, especially in the early stages.
- The first is familiarity with people-oriented governance. Regulated AI, in the EU AI Act, in PL 2.338/2023 and in CNJ Resolution 615, is treated not only as a matter of efficiency but as a matter of risks to fundamental rights, fairness, privacy, non-discrimination and human oversight. The DPO already works with this grammar.
- The second is the culture of accountability. The DPO usually already works with inventories, processes, records, controls, legal bases, incidents, responses to data subjects, traceability and accountability. This creates a useful foundation for structuring AI policies, usage criteria, review workflows and risk assessment.
- The third is proximity to the impact on people. The EU AI Act requires, in certain cases, a fundamental rights impact assessment for deployers of high-risk systems. PL 2.338/2023 refers to algorithmic impact assessment and allows integration with the DPIA. The conceptual convergence is evident.
- The fourth is relative independence. Both the European regime and the Brazilian regulations on the DPO are concerned with technical autonomy, access to senior management and the prevention of conflicts of interest. This can be useful for challenging high-impact AI projects without being subject to purely commercial or delivery pressure.
- The fifth is pragmatic. In companies that have already reached some LGPD maturity, the existing structure can be expanded more quickly to cover AI, at least in its governance, policy, inventory and risk layer.
The disadvantages and why they are serious
The risks of centralizing everything in the DPO are also real.
- The first is overload. The DPO usually already concentrates data subject requests, incidents, contracts, training, internal consultations, product reviews, suppliers, international data transfers and regulatory dialogue. Adding the entire AI agenda can produce superficial coverage precisely where the organization would most need depth.
- The second is the technical gap. AI governance requires understanding architecture, training, testing, model drift, performance, limitations, operational human oversight, technical documentation and the specific risks of the use case. No serious regulatory framework assumes that this can be handled solely by a legal or privacy function. The EU AI Act, for example, expressly refers to people with the competence, training and authority to carry out human oversight.
- The third is conflict of interest. The ANPD defines a conflict of interest as a situation capable of compromising the DPO's objectivity and technical judgment. The regulation also states that a conflict may arise when the DPO accumulates activities involving strategic decision-making on the processing of personal data. The EDPB takes the same direction in indicating that the DPO should not hold a position that determines the purposes and means of processing.
Applying this logic to AI, there is an evident risk. If the DPO also becomes the owner of the AI product, or the final decision-maker on its deployment, budget, commercial strategy or functional design, they may move from a position of control, advice and challenge to a position of operational decision-making that weakens their independence. This does not mean that the DPO cannot take part in AI governance. It simply means that there are limits, so that the reviewing function does not become an executing function.
- The fourth is the broader regulatory scope of AI. Even when there are no personal data, there may still be significant regulatory or ethical risks in AI. Copyright, discrimination not based on identifiable personal data, system security, information integrity, consumer protection, labor relations and sector-specific compliance may go beyond the typical mandate of the DPO.
- The fifth is excessive dependence on one person. Mature programs cannot rely on the individual heroism of the DPO. They need structure, a committee, roles, decision trails and repeatable processes.
The most robust model: the DPO as a pillar, not as a sole owner
In most organizations, the most robust design tends to be this: the DPO is a central piece of AI governance, but not the only one responsible for it.
In practical terms, this usually means that senior management acts as sponsor and institutionally responsible party; that there is a formal governance body, committee or AI forum; that technology and product are responsible for architecture, testing, monitoring and operational controls; that legal and compliance support regulatory interpretation, contracts, liability and corporate governance; that information security assesses technical risks, incidents, access and resilience; that risk and audit contribute methodology and verification; and that the DPO leads or co-leads the layer of data protection, individuals' rights, impact, accountability and regulatory interface whenever personal data are processed.
This design fits better with the current regulatory reality. The EU AI Act does not create an AI DPO. It distributes obligations by role and requires concrete governance from the deployer and the provider. PL 2.338/2023 likewise does not turn the DPO into the universal person responsible for AI. It structures a regulatory system and imposes duties on AI agents according to risk and function. CNJ Resolution 615/2025 also refers to governance mechanisms, internal persons or committees in charge, auditing, monitoring and impact assessment, not to full delegation to a single function.
When it makes sense for the DPO to lead
There are situations in which it makes sense to place the DPO as the executive leader of the responsible AI agenda, at least temporarily.
This occurs when the organization does not yet have a broader digital compliance structure, when AI use cases are few and heavily based on personal data, when AI is being adopted more as an internal tool than as a core product, when the DPO has solid seniority, a cross-functional view and effective access to senior management, and when there is real technical support from the technology, product, security and business areas.
In these cases, the DPO can be the catalyst for implementation, including the usage policy, systems inventory, risk classification, questionnaires, impact assessment triggers, approval trail, criteria for the use of generative AI, contract review and the setting up of a committee.
But even in this scenario, the best design remains coordinating leadership, not exclusive ownership of the agenda.
When it does not make sense
There are scenarios in which it is not advisable for the DPO to be the main person responsible.
This happens in companies with many AI-based models and products, in environments where AI is a core part of the commercial strategy, in organizations subject to strong sector-specific regulation, in high-risk contexts, including biometrics, employment, credit, health, education or decisions with significant effects, in structures where the DPO is already working at full capacity, and in environments where the function would end up accumulating decision-making power incompatible with its independence.
In these cases, the ideal is a dedicated AI governance structure, with a specific executive owner, a multidisciplinary committee and the formal participation of the DPO as guardian of the data dimension and of the impact on people.
What, then, is the best answer?
The best answer is this: the DPO should not be presumed to be solely responsible for AI governance, but can be one of the main leaders of this agenda, especially in matters concerning individuals' rights, governance, accountability and data protection.
In small companies or those at an early stage of maturity, the DPO may even take on a broader coordinating role, provided there is technical support and no conflict of interest. In larger organizations or those where AI is more strategic, the most mature solution tends to be a distributed model, with multidisciplinary governance, clear ownership and strong participation of the DPO, without reducing all of AI governance to data protection governance.
Conclusion
The question “will the DPO be responsible for AI governance?” is relevant precisely because regulated AI resembles, in several respects, the data protection agenda: a focus on people, inventory, risk, impact, governance, transparency, controls and demonstrability. The EU AI Act, PL 2.338/2023 and CNJ Resolution No. 615/2025 confirm this convergence, while the ANPD itself already lists AI among its priority enforcement topics.
But the mature answer is not to transfer the entire AI agenda to the DPO. It is to recognize that the DPO has a central and often indispensable role, without ignoring that AI governance is broader than privacy and requires distributed technical, organizational and sector-specific competences.


