The DPO profession in the age of artificial intelligence: publication of the survey results

· Source: RSS - Actualités CNIL · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, short

Summary

A 2025 survey, published on July 3, 2026, by the Ministry of Labour and Social Affairs, AFCDP, and CNIL, reveals the evolving role of Data Protection Officers (DPOs) amidst increasing AI integration and the new AI Act (RIA). The study found that 70% of organizations use or plan to use AI, with 81% specifically employing generative AI systems. While 2/3 purchase solutions externally, AI governance remains largely unstructured; less than a quarter of organizations have a formal AI strategy, and only 31% are preparing for the AI Act. DPO profiles are diverse, with 79% internal and 85% part-time. Significantly, 55% of DPOs already consider RIA compliance within their scope, and 71% desire this expansion, despite only 27% reporting good RIA knowledge and 85% lacking specific AI training. The CNIL plans to continue supporting DPOs with practical tools.

Key takeaway

For Data Protection Officers navigating the new AI Act, your role is expanding rapidly, even if not explicitly mandated. You should proactively seek specific training on the AI Act's requirements and advocate for formalizing AI governance within your organization. This will enable you to effectively manage the compliance risks associated with the 70% of organizations adopting AI, particularly generative AI, and position yourself as a critical asset in this evolving regulatory landscape.

Key insights

The AI Act and widespread AI adoption are rapidly transforming the DPO role, creating new compliance challenges and a strong desire for expanded responsibilities.

Principles

In practice

Topics

Best for: Executive, CTO, VP of Engineering/Data, Legal Professional, Consultant, Policy Maker

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by RSS - Actualités CNIL.