Scroll through any privacy careers pages right now and you'll likely spot a title that barely existed a few years ago: AI Governance Officer. Sometimes it's Head of Responsible AI, sometimes Director of AI Risk, sometimes AI Compliance Lead. The variety of names is itself a clue that the market hasn't quite settled on what this person actually does!
And it raises a question we hear constantly from clients building out their compliance functions: is this a genuinely new role, or is it simply a Data Protection Officer with a fresh coat of paint?
The honest answer is that it's some of both; and understanding the overlap is the key to hiring well.
Why the role is appearing now
The obvious driver is regulation. The EU AI Act, which entered into force in 2024, is rolling out in phases: bans on certain practices came first, obligations for general-purpose AI models followed, and the heavier requirements for high-risk systems continue to phase in through 2026 and beyond. Add the patchwork of US state privacy and AI laws, sector-specific guidance from financial and health regulators, and voluntary frameworks like the NIST AI Risk Management Framework and ISO 42001, and you have a compliance surface that simply didn't exist when the DPO role was codified under GDPR.
But regulation is only half the story. The other half is that AI now touches revenue, product, and risk in ways that make boards nervous. A model that discriminates, hallucinates, or leaks training data is a business problem long before it's a legal one.
Companies want someone whose full-time job is to see those problems coming.
Where it overlaps with the DPO
The similarities are real, which is why the "rebranded DPO" theory has legs. Both roles sit at the intersection of law, technology, and ethics. Both require translating dense regulation into practical controls that engineers and product teams will actually follow. Both depend on independence and the authority to say no. And critically, both deal heavily with data - because most AI risk is, at root, data risk. Training data provenance, consent, purpose limitation, and automated decision-making are all GDPR concerns that map directly onto AI governance.
For many mid-sized organisations, this overlap is decisive: the existing DPO simply absorbs AI governance as an extension of the privacy mandate. That's a reasonable and often cost-effective choice.
Where it genuinely diverges
The differences, though, are more than cosmetic.
A DPO's remit is defined and bounded by data protection law. AI governance is broader and messier. It covers model performance, bias and fairness testing, explainability, robustness, human oversight, third-party model procurement, and the ethical questions that don't have a clean legal answer yet. Much of this is technical in a way privacy law rarely demanded: you cannot meaningfully govern a model you don't understand at least conceptually.
There's also a structural tension. Under GDPR, the DPO must remain independent and cannot be instructed on how to perform the role. AI governance, by contrast, is often expected to enable the business: to help ship AI products faster and more safely; not just to police them. Bolting an enablement mandate onto a legally independent watchdog role can create real conflicts. That's one reason sophisticated organisations are increasingly separating the two.
What this means for hiring
For employers, the practical takeaway is to resist defaulting to a title and instead define the mandate first. If the need is fundamentally about data protection compliance for AI systems, extending the DPO function may be the right, leaner answer. If the need spans model risk, technical assurance, and cross-functional enablement, you're hiring for a distinctly different profile: one that pairs regulatory literacy with genuine technical fluency and the stakeholder skills to influence product decisions.
That profile is scarce today, which is exactly why compensation and titles are all over the map. The strongest candidates tend to come from three directions: privacy and legal professionals who have upskilled technically, machine learning practitioners who have moved into risk, and risk-and-audit specialists who have specialized in AI. Few tick every box, so the more valuable question in an interview is which gaps you can afford and which you can't.
Our verdict
The AI Governance Officer is neither purely new nor merely a rebranded DPO. It's an evolution; one that grew out of the privacy function, but has outgrown its boundaries.
Treating the two as interchangeable is the mistake we see most often, and it leads companies to either overpay for a privacy hire or underequip an AI mandate.
Get the mandate right first, and the right title, profile and compensation tend to follow.