Procedure
Roles and approval when deploying AI
The roles are not free to allocate, because several provisions name their own addressee. Art. 26(2) AI Act requires human oversight to be assigned to persons with competence, training and authority, and Art. 38(6) GDPR rules out an approval decision by the data protection officer. The approval route has four duties to work through, all of which fall before the system is put into service.
Three introductions, no named decision
Three business units each want to introduce a tool in the same quarter. The data protection officer is to review and approve, IT is to operate, and who takes the decision appears nowhere. Two of the roles are, however, already allocated, and by legal provisions.
Three roles are allocated before anyone allocates them
How roles and responsibilities are to be allocated is not entirely a question of the organisation chart. Three provisions name their own addressee, and one forbids a particular allocation.
What is prescribed and what remains open
| Prescribed | Merkmal | Open to determine |
|---|---|---|
| Competence, training, authorityArt. 26(2) AI Act. Oversight is to be assigned to natural persons who have all three and who receive support. | Human oversight | The choice of person |
| With the controllerArt. 5(2) GDPR. The duty can be divided internally but not given away. | Demonstrating compliance | The internal division |
| Advise and monitorArt. 39(1) GDPR. Under Art. 38(6) GDPR a further task must not give rise to a conflict of interests, and an approval decision of their own does. | Role of the data protection officer | Extent of involvement |
| Not with the data protection officer | The approval decision | Otherwise openBusiness unit, IT, management or a committee. What matters is that the body is named and may decide on means. |
The third row leads to the most common change. The data protection officer reviews, documents and objects, and approval is given by a body that stands behind the project.
That separation is not a formality but the reason monitoring is worth anything later. A body monitoring its own decision can no longer object to it.
Four duties fall before the system is put into service
What the approval process has to settle follows from the points in time and not from an order the project gives itself. Four duties have a point in time fixed by law, and all four fall before the system is put into service.
Four points in time the approval route has to reflect
At the planning stage
Informing the works council
Section 90(1) no. 3 BetrVG names the deployment of artificial intelligence expressly and attaches to the planning, that is, to a point before the selection.
When the means are determined
Data protection by design
Art. 25(1) GDPR. With the choice of product the means are determined, and the effective levers are allocated after that.
Prior to the processing
The impact assessment
Art. 35(1) GDPR requires it in advance. For a high-risk system the provider's information has to be used for it under Art. 26(9) AI Act.
Before putting into service
Informing the workforce
Art. 26(7) AI Act requires, for a high-risk system at the workplace, that workers' representatives and the affected employees be informed.
Six items on which an approval can be decided
Liste zu erledigender Punkte
- The purpose of the deployment in one sentence, because the legal basis follows from it
- The classification under the AI Act, that is provider or deployer and high-risk or not
- The role taking on human oversight, with a name and an authority
- The answer to the four points in time, each with a date and a responsible body
- The retention of the logs, with a period and a storage location
- The body that decides where two participants cannot agree
How we support you in building AI governance
The approval route needs no procedural code but a form with the six items and a named body to receive it. The data protection officer gets it for review, not for decision, and their opinion is recorded. Where one of the four points in time is left without a date, approval is not yet possible, and that is precisely the effect the form is meant to have.
Frequently asked questions
Can the data protection officer own the approval process?
Not the decision. Art. 39(1) GDPR assigns them information, advice and monitoring, and Art. 38(6) GDPR requires that any further task not give rise to a conflict of interests. Anyone approving something monitors their own decision afterwards. Involvement under Art. 38(1) GDPR is by contrast mandatory and early.
How long do logs have to be kept?
For a high-risk system, under Art. 26(6) AI Act for a period appropriate to the intended purpose of at least six months, in so far as the logs are under your own control. Other Union or national law may differ, in particular data protection law with the storage limitation principle.
Does a tool that is not high-risk need an approval route?
The duties in Art. 26 AI Act do not then apply. The data protection ones do, that is Art. 25 and Art. 35 GDPR, as do co-determination and the duty under Art. 4 AI Act. That makes the approval route shorter rather than unnecessary.
Who decides where two units cannot agree?
Management, and that belongs settled in advance. An approval route without a named escalation stage regularly ends with the business unit starting without approval. Settling it is at the same time a measure under Art. 24(1) GDPR and therefore part of the demonstration.
More questions from this area
AI literacy under Art. 4 AI Act
Art. 4 AI Act requires a sufficient level of AI literacy and names five circumstances by which that level is measured.
The AI policy at work
Under the Court of Justice a legal person is liable for infringements committed by any person acting in the course of its business.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.