EU AI Act · AI Act · AI governance

AI Officer as a Service: Your External AI Officer

You assign responsibility for AI in a demonstrable way and reduce liability and organizational risks, without a dedicated full-time position. We handle the ongoing operational steering of your AI governance under mandate: inventory, risk classification under the EU AI Act, AI literacy (Art. 4) and reporting to executive management. Ultimate legal responsibility remains with executive management and the board of directors.

from CHF 500 / month Mandate instead of permanent hire Attorney-client privilege (Art. 321 SCC)

15 min · no obligation · free of charge · directly with Dr. Dominic Staiger

External AI Officer steering the AI governance of a Swiss company
The AI counterpart to the external Data Protection Officer, law and technology from a single mandate.

Working for regulated industries and SMEs

CIPP/E · Dr. iur. · LL.M. Certified data-protection and legal expertise
Art. 321 SCC Swiss professional secrecy
ISO/IEC 42001:2023 AI governance aligned with standards
AI Act expertise Specialist articles on the EU AI Act
CH · EU · UK · US Mandates across jurisdictions
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M. (Bond), Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Dr Dominic Staiger handles the operational management of your AI governance as your external AI Officer. He combines data protection and AI law with technical understanding, has published on the EU AI Act and the AI Act (see Insights) and handles mandates in Switzerland, the EU, the UK and the USA, in line with the extraterritorial reach of the EU AI Act (Art. 2 EU AI Act).

LinkedIn profile

What is an AI Officer as a service?

Brief definition

An AI Officer as a service is an external, permanently staffed function that, under mandate, handles the operational management of your AI governance; ultimate legal responsibility remains with executive management and the board of directors (Art. 717/754 CO). We build up your AI inventory, classify every system under the EU AI Act (Regulation (EU) 2024/1689), and manage AI literacy (Art. 4 EU AI Act), policies, the coordination of FRIA and DPIA, and reporting to your executive management. The model follows the proven principle of the external Data Protection Officer: a designated, competent point of contact without a dedicated full-time position.

An AI Officer is not a legally mandatory role, but rather governance- and market-driven; in practice it is nevertheless the most effective way to demonstrably consolidate AI literacy and oversight responsibility. ISO/IEC 42001:2023 requires clear assignment of roles, responsibilities and oversight across the entire AI lifecycle; for executive management and the board of directors, the documented assignment of this responsibility is part of a diligent organisation. This does not guarantee compliance, but it does deliver demonstrable risk reduction and accountability. (Why the EU AI Act itself does not prescribe an "AI Officer" is explained in the frequently asked questions.)

Do you need an external AI Officer?

Many Swiss companies already make broad use of ChatGPT, Microsoft Copilot, Claude and similar tools, without anyone being responsible for them. These four triggers indicate that an AI Officer is warranted:

1

In your executive management or your board of directors, the question arises "Who is actually responsible for AI here?", and there is no clear, designated answer.

2

Your employees use GPAI tools (general-purpose AI models, e.g. ChatGPT, Copilot, Claude) productively, but a binding usage policy is lacking, and shadow AI is spreading uncontrolled.

3

EU customers or procurement questionnaires request information about your AI governance, or the output of your AI systems is used in the EU (Art. 2(1)(c) EU AI Act, output clause).

4

You make, with AI, automated individual decisions or carry out profiling (e.g. scoring, HR pre-selection, creditworthiness) and are thereby directly affected by Art. 21 revised FADP and, depending on the application, by the Annex III obligations of the EU AI Act.

What makes us unique

Law, software engineering and in-house AI development, in a single team

At our firm, these three disciplines interlock within a single team. Neither a pure law firm nor a conventional consultancy can deliver this combination. This is how we manage your AI governance substantively rather than merely formally: legally, technically and with genuine AI understanding.

Deep legal expertise

Lawyers with doctorates holding CIPP/E, Attorney at Law (NY) and Solicitor (UK) qualifications. We classify AI with legal certainty under the EU AI Act, the FADP and the GDPR, drawing on ongoing mandates rather than textbooks.

Our own software engineers

Our own development centre and the Priverion Platform. We know how AI systems are built today, and we examine what a system technically really does instead of relying on self-declarations.

In-house AI development

We develop and operate our own LLM and AI systems. As a result, we know the best practices and pitfalls firsthand, from RAG to prompt security.

What do we take care of?

As your external AI Officer, we manage AI governance on an ongoing basis, not as a one-off project but as a permanent mandate. Here is what you get:

  • Overview and control over every AI system in use: a maintained AI inventory / use-case register including shadow AI, kept on our Priverion Platform.
  • Clarity about your risk: risk classification of every system under the EU AI Act, prohibited (Art. 5), high-risk (Art. 6 et seq., Annex III), limited risk (transparency, Art. 50) or minimal risk, with prioritised action needs.
  • Capable employees: an AI literacy programme under Art. 4 EU AI Act with role-specific training and awareness measures.
  • Binding rules of the game: an internal AI policy / acceptable-use rules for GPAI tools that move shadow AI into regulated, approved use.
  • No duplication of effort: AI governance under shared responsibility with your existing roles, including coordination of FRIA and DPIA as well as an interface to the DPO und CISO.
  • Demonstrable diligence towards leadership: regular reporting to executive management, documented escalation processes, supplier and provider management (provider obligations, contracts, instructions for use, Art. 26 EU AI Act) as well as preparation for the high-risk obligations (Annex III).

Effort and impact at a glance

Building up a dedicated AI governance role in-house is expensive and inflexible; a mandate scales with your actual use of AI. Dedicated AI governance roles are moreover increasing significantly in the market (IAPP AI Governance Profession Report 2025).

CHF 120k–180k+

Full cost of an internal AI Officer position per year; a mandate starts at CHF 6'000/year.

since 02.02.2025

Art. 5 (prohibitions) and Art. 4 (AI literacy) of the EU AI Act apply directly.

EUR 35 million

maximum fine range (7% of global turnover) for prohibited practices, Art. 99 EU AI Act.

Under Art. 99 EU AI Act, prohibited practices (Art. 5) carry fines of up to EUR 35 million / 7% of worldwide annual turnover, and breaches of deployer obligations (Art. 26) up to EUR 15 million / 3%. These are statutory upper limits for the most serious categories, not a typical deployer case. A mandate reduces this risk through demonstrable allocation and documentation, but it is not a guarantee.

Mandate models

We offer three mandate levels, all on an ongoing retainer basis, with usage-based escalation when needs increase. The specific scope (number of AI systems, locations, response times) is agreed in the mandate.

Readiness

from CHF 500 / month

The designated point of contact for SMEs with a manageable use of AI.

  • Designated AI Officer function as a point of contact
  • Annual AI status assessment (AI Governance Check)
  • Ad-hoc questions from the organisation
  • Access to the Priverion Platform for the AI inventory
  • Information on relevant legal changes (EU AI Act, revised FADP)

Full mandate

on request

Complete AI governance for groups and regulated industries.

  • All services from "Governance"
  • Coordination of FRIA (Art. 27 EU AI Act) and DPIA (Art. 35 GDPR)
  • Supplier/provider management and contract review
  • Interface with the DPO, CISO and supervisory authority (e.g. FINMA)
  • Preparation for the Annex III high-risk obligations

How we work

An AI Officer delivers value over time. Our approach is based on ISO/IEC 42001:2023 and structured into a clear sequence of phases:

Status assessment

At the outset, we capture your use of AI, your roles (provider/deployer) and any EU output nexus, on request as AI Governance Check.

Build-up phase (weeks 1–6)

We build the AI inventory and carry out the initial risk classification in order to prioritise the need for action.

Embedding

We adopt the AI policy and launch the literacy programme.

Ongoing operation

We keep the inventory and classification up to date, manage shadow AI and coordinate FRIA/DPIA as needed.

Reporting and review

We report regularly to executive management and make adjustments whenever the legal or technical landscape changes.

Why SIDD?

What the three disciplines above mean for you in concrete terms within the mandate:

The AI counterpart to the external DPO

The same proven mandate model as for the external Data Protection Officer (DPO), applied to AI, in shared responsibility with your DPO und CISO role.

Swiss professional secrecy

Communications and assessments are covered by Swiss professional secrecy (Art. 321 SCC), a level of confidentiality that pure consulting or InfoSec firms cannot offer.

Demonstrable, not PowerPoint

AI inventory, risk classification and reporting as maintained, auditable tooling on the Priverion Platform, not as one-off slides.

Ready to start quickly, without a permanent hire

Assessment and a robust AI inventory in four to six weeks, without the recruiting, training and backup an internal position would require.

CH · EU · UK · US from a single source

Mandates spanning jurisdictions, aligned with the extraterritorial reach of the EU AI Act (Art. 2) and with group structures.

Advisory and audit kept separate

We keep advisory and independent audit strictly separate, which makes our assessments credible to supervisory authorities and auditors.

Related mandates

The following mandates are data-protection and governance engagements whose role, inventory and evidence structures translate directly to responsible AI governance. Both clients are named with their consent.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the AI Officer mandate, concretely: when we classify your AI inventory under the EU AI Act, LexCommand traces every rating to the exact article in the version valid on the chosen date and surfaces overlapping duties from the AI Act, ISO/IEC 42001 and the FADP together.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

What does an external AI Officer cost?

The mandate starts at CHF 500/month for the readiness tier (named point of contact, annual assessment, ad-hoc questions). The governance tier typically ranges between CHF 1'500 and CHF 3'500/month. As AI use and steering needs grow, the mandate scales on a usage-based model; the specific scope, such as the number of AI systems covered, is agreed in advance.

Does the EU AI Act mandate an AI officer?

No. Unlike the GDPR with the Data Protection Officer (Art. 37 GDPR), the EU AI Act does not provide for a corresponding mandatory role. Art. 4 EU AI Act merely requires a sufficient level of AI literacy within the organisation. The AI Officer is therefore not legally compelled but governance- and market-driven, yet in practice the most effective way to demonstrably consolidate this competence and the oversight responsibility.

How do we govern ChatGPT and Microsoft Copilot in the workplace?

Through a binding internal AI policy (acceptable-use rules) for GPAI tools such as ChatGPT, Copilot and Claude: which tools are approved, what data may go into them, who bears responsibility. We identify existing shadow AI, assess it and transition it into governed, approved use. For more, see our guide to the EU AI Act for Switzerland and the AI policy template for SMEs.

Are we even affected as a Swiss SME?

Possibly yes. The EU AI Act has extraterritorial effect: it captures Swiss companies as providers (Art. 2(1)(a)) and via the output clause (Art. 2(1)(c)) when the output of an AI system is used in the EU. Independently of this, Swiss law already applies today, in particular Art. 21 revised FADP for automated individual decisions, as well as the liability and organisational obligations under the Swiss Code of Obligations.

From when do the high-risk obligations of the EU AI Act apply?

Art. 5 (prohibitions) and Art. 4 (AI literacy) have applied since 02.02.2025. The GPAI obligations (Art. 53, 55) have applied since 02.08.2025 for models newly placed on the market; for existing models there is a transition period until 02.08.2027. Most high-risk obligations (Annex III) were originally scheduled to apply from 02.08.2026. Following the provisional agreement on the "Digital AI Omnibus", they are expected to be postponed to 02.12.2027 (Annex III) and 02.08.2028 (Annex I) respectively. As of 18.06.2026 this agreement had not yet been published in the EU Official Journal and is therefore not final; until formal adoption, the original deadlines formally apply. As a precaution, we plan against both scenarios. The longer lead time is an advantage, not an all-clear.

How long do we commit for, and how do we terminate?

The mandate runs as a monthly retainer with a three-month notice period, with no annual lock-in. The specific terms are agreed in the mandate contract.

How quickly are we ready to start, and how much internal effort does it require?

The initial assessment and a robust AI inventory are typically available within four to six weeks. The internal effort is essentially limited to providing access to your system and tool lists and to one or two workshops.

Where is our data stored on the Priverion Platform?

The Priverion Platform is hosted in Switzerland or the EU; the standard configuration for Swiss mandates is hosting in Switzerland. Your inventory and governance data is additionally covered by attorney professional secrecy (Art. 321 SCC). We set out the specific storage location in the mandate.

How does the AI Officer relate to our DPO and CISO?

Complementary. The AI Officer works in shared responsibility with your existing DPO und CISO role: He coordinates the FRIA (fundamental rights impact assessment, Art. 27 EU AI Act) alongside the DPIA (data protection impact assessment, Art. 35 GDPR) and steers AI-specific governance without duplicating existing responsibilities. We can also provide both roles from a single source.

Does this reduce the liability of executive management?

A designated, documented AI responsibility is a demonstrable building block of the duty of care and organisation (Art. 717/754 CO); it reduces organisational and liability risk but does not replace a case-by-case assessment of liability. Ultimate legal responsibility remains with executive management and the board of directors and cannot be transferred to an external mandate. We cannot promise guaranteed compliance or an exclusion of liability; the aim is demonstrable risk reduction and accountability.

Is this legal advice for a specific case?

This page does not constitute legal advice for a specific case. Within the mandate, we provide concrete advice tailored to your organisation, under Swiss professional secrecy (Art. 321 SCC).

This page as of: 18.06.2026, last reviewed by Dr. Dominic Staiger. This page does not replace legal advice for a specific case.

Clarify who is responsible for AI in your organisation

In a 15-minute, non-binding initial consultation with Dr. Dominic Staiger, we assess your use of AI and tell you the appropriate mandate level and the effort involved straight afterwards, under attorney secrecy (Art. 321 SCC).