All news
Regulation July 3, 2026 6 min

71% of DPOs want the AI Act in their remit. 27% say they know it. 85% have never had AI training

The CNIL-AFCDP survey portrays a profession taking on a responsibility no law gave it, and without the mandate that protects it

TL;DR for the DPO

Three numbers and a consequence. 71% of DPOs want the AI Act in their remit and 55% already have it; only 27% say they know the text well and 85% have never had AI training; 85% of internal DPOs do the job part-time. The AI Act does not mention the DPO anywhere: whoever takes it on does so without the Article 38 GDPR mandate that protects their independence.

Who DPOs are in 2026

The survey is the fifth edition of the Observatory, running since 2018 through the French general delegation for employment and vocational training and the CNIL, in partnership with the AFCDP. This year's research was carried out by the Afpa and published on 3 July 2026.

  • 79% of DPOs act as internal DPOs
  • 54% come from fields other than law and IT
  • 85% of internal and pooled DPOs work part-time
  • 45% have more than six years of data protection experience
  • the presence of men and women in the role is balanced

That 85% part-time figure is the one to keep in view while reading all the others: a second regulation is being placed on a function performed part-time.

The AI is already there, the governance is not

70%
of organisations use or plan to use AI

Among them, 81% use generative AI systems and two thirds buy the solution from outside suppliers, against 22% who build it in-house. Usage grows with the size of the organisation. But governance lags well behind: fewer than a quarter of organisations have a formal AI strategy or policy, fewer than a third have run staff awareness work or adopted an AI charter, and only 31% have started preparing for the AI Act.

The point nobody puts in the headline

Two thirds buy AI from outside suppliers. That means for most organisations AI compliance is not decided in-house: it is decided by reading a supplier's contract and documentation. That is exactly the territory of Article 28 and documented instructions, not new territory at all.

The 44-point gap

Here the survey gets uncomfortable. 55% of DPOs say the AI Act is already within their area of responsibility and 71% want the role formally extended to it. But only 27% say they have a good level of knowledge of the text, and 85% have not yet followed any specific AI training. More than half say they are often or systematically involved in AI projects.

44points
point gap between those who want the AI Act and those who say they know it

The CNIL puts it plainly: DPOs are broadly equipped to assess the GDPR aspects of AI, but they often lack tools and methods for the AI Act aspects. And it adds something worth more than all the percentages: the AI Act does not mention the DPO, so the role is not imposed in internal governance chains.

Taking a role without the mandate that protects it

This is where it is worth pausing. The DPO has a written mandate: Article 38 GDPR guarantees reporting to the highest level, no instructions on the exercise of the tasks, and no dismissal for performing them. That mandate covers the Article 39 tasks, that is the GDPR. It does not cover the AI Act, which does not cite the DPO.

And there is a further risk

Article 38(6) forbids the DPO tasks that create a conflict of interest. If the DPO becomes the person who designs and builds AI governance - picks the systems, writes the procedures, classifies the risks - they then end up checking their own work. It is the same reason a DPO should not be the head of IT: the role that builds cannot be the role that verifies.

What to do now, in practice

1) Put in writing, in one line, whether the AI Act is in your mandate or not: doing it in fact without it being written is the worst of both worlds. 2) Separate the two hats: advising and monitoring GDPR compliance of AI systems are your statutory tasks; AI Act compliance is an additional engagement that must be conferred, paid and recorded. 3) If the client buys AI from a supplier - and two times out of three they do - the real work is contractual: documented instructions, model information, the supplier's role. 4) Ask for training in writing: Article 38(2) obliges the controller to provide the necessary resources, and with 85% of colleagues untrained on AI you are in good company asking. 5) If you are part-time like 85% of internal DPOs, quantify the extra hours before accepting the widened remit, not after.

Official source:CNIL - The DPO profession in the age of artificial intelligence: survey results published (3 July 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min