Market · In-house AI counsel
AI governance and liability counsel under the EU AI Act.
In the Union the calendar is dated, the obligations are named, and a market-surveillance authority will ask for the file. A US group facing the same technology answers a patchwork. The question for a general counsel is what the European seat must already be able to do.
The same title buys two different seats.
A general counsel in Brussels who must staff the eu ai act file already owns a dated Union calendar. Sartori maps about 4,000 lawyers in this city; the coverage is a density read of who sits in-house on digital and product-regulatory work, not a count of dedicated AI Act desks.
Regulation (EU) 2024/1689 hands a company named obligations, a conformity route and a market-surveillance counterpart. A US group facing the same technology answers state statutes and enforcement discretion. Same title. Different seat.
The question for a chief legal officer in Brussels, Paris or London is capability, not a job title. The calendar below is the job description.
- 2 Aug 2026
- AI-Office and national enforcement liveTransparency duties start the same day
- European Commission, 31 July 2026
- €35m / 7%
- Article 99(3) ceiling for prohibited practicesWhichever is higher; statutory maximum, not a collected fine
- AI Act Service Desk, Article 99
- 2 Dec 2027
- Annex III high-risk Chapter III appliesAfter Regulation (EU) 2026/1744
- Commission AI Act page, 3 August 2026
- 9 Dec 2026
- Software and AI become a productDirective (EU) 2024/2853 transposition and application
- EUR-Lex; DG GROW
A dated Union file is not a patchwork, and the hire has to match the file.
The opening question is the buyer's. A general counsel in Brussels, Paris or London has to put a lawyer on the payroll who can classify systems and answer a market-surveillance authority, or decide in writing that the panel will do it.
The same job title buys two different seats. In the European Union, Regulation (EU) 2024/1689 hands a company a dated compliance calendar, named operator duties, a conformity route for high-risk systems, and a market-surveillance authority that will one day ask for the technical file. A US group facing the same technology answers a patchwork of state statutes and enforcement discretion. This page does not unpack that stack. It stays with the European statutory seat a chief legal officer actually has to staff.
We have worked the Brussels in-house market for five years, for corporate legal departments that deploy or place AI systems on the Union market. Over the last three years that desk closed fifteen in-house searches at a 93 percent completion rate, on a typical timeline of four to seven months. The work is classification, documentation, authority interface and product-liability intake — not a generic emerging-tech hiring story, which another page already owns.
Sartori’s Brussels interview cohort shows that 61 of 74 respondents sitting as general counsel, chief legal officer or head of legal at a Union deployer or provider over a 24-month window said the first enforceable file was a prohibition or HR-tool review, not an Annex III conformity pack. The same 74-person segment is the base for a second read: 48 of those 74 could not name the Belgian market-surveillance authority they would hand a technical file to. That is not a knowledge-quiz score. It is what an unfinished designation looks like from inside a legal department.
A general counsel at a Brussels-based industrial deployer, speaking inside that 24-month window, put the mistake in one line: the Digital Omnibus had been read internally as a stay, and the workplace scoring tool was already in production. The head of legal of a Paris-headquartered universal bank’s London digital-legal book told us the AI file had been bolted onto privacy without a new headcount, and that the product-liability recast was still sitting with commercial. Two roles, two organization types, no names. Both point at the same staffing error: treating a dated calendar as a 2027 project.
The European Federation of Data Protection Officers has already described the design trap a company walks into when it appoints an “AI officer” who is also the adoption champion: the person who is measured on rollout cannot be the person who is measured on a kill-decision. The AI Act does not create that office. Article 26 of Regulation (EU) 2024/1689, as displayed by the Commission service desk, places deployer duties — instructions for use, competent human oversight, input-data quality, monitoring, six-month logs, workplace information, registration for public deployers, cooperation with authorities — on the deployer as a legal person. The internal desk is a choice. The addressee is not.
A subject to followA file the company owns
- Read the alert The legal department learns the calendar from a firm bulletin. Nobody has classified the estate. The company’s position is whatever product assumed it was.
- Extend privacy A privacy counsel inherits the title. Personal-data uses get a home. The technical file, the notified body and the product-liability recast do not.
- Own the statutory seat An in-house holder classifies, keeps the documentation chain, sits between product and the conformity body, and treats a market-surveillance request as an internal deadline.
The same job title buys two different seats.
What the eu ai act already put on the desk.
The Omnibus moved conformity. It did not move the prohibition file. A head of legal who staffs against the slipped date leaves the live work on the floor.
Regulation (EU) 2024/1689 entered into force on 1 August 2024. The Commission’s AI Act policy page, last updated on 3 August 2026, restates the staggered calendar after the Digital Omnibus: prohibitions and AI-literacy duties from 2 February 2025, GPAI and governance rules from 2 August 2025, transparency and AI-Office enforcement from 2 August 2026, Annex III high-risk rules from 2 December 2027, and Annex I embedded-product rules from 2 August 2028. Prohibition 9, on non-consensual intimate content and child-sexual-abuse generation, applies from 2 December 2026. Those dates are the job description. They are not a conference agenda.
The Omnibus is law. Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force on 27 July 2026, records in recitals (1), (2) and (40) that delayed standards and delayed national governance produced a heavier compliance burden than expected, and therefore pushed Chapter III Sections 1 to 3 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Parliament voted on 16 June 2026; the Council decided on 29 June 2026. A general counsel who had dated a notified-body surge to mid-2026 now has a late-2027 peak. That is a reason to keep the mid-senior builder on payroll through 2026 and 2027. It is not a reason to hire a surge of junior deadline contractors for an August 2026 conformity cliff the Omnibus removed.
A Commission press release dated 31 July 2026 states that from 2 August 2026 the AI Office, together with national authorities, begins enforcing the Act, and that the same date starts the transparency rules: certain systems must tell users they are interacting with AI, and AI-generated or altered content must be labeled or machine-marked. The same release records a first list of more than 180 organizations on the Code of Practice on transparency of AI-generated content. Article 50(2) marking for systems already on the market runs to 2 December 2026, on the Service Desk FAQ. Every deployer of a chatbot, a marketing generator or a deepfake tool needs a counsel who can split provider marks from deployer labels. That is mid-level in-house work, often an extension of communications legal, and the statutory addressee is still the company.
GPAI is a different desk. The Commission published guidelines on the scope of GPAI-provider obligations on 18 July 2025, ahead of application on 2 August 2025. A GPAI model is defined there as one trained with computational resources exceeding 1023 floating-point operations and capable of generating language, text-to-image or text-to-video; a systemic-risk presumption sits at 1025 FLOPs. Informal collaboration with the AI Office ran from 2 August 2025; Commission enforcement powers, including fines, arrived on 2 August 2026; models already on the market before 2 August 2025 have until 2 August 2027. The GPAI Code of Practice was received on 10 July 2025 and approved by the Commission and the AI Board on 1 August 2025, after a process the Commission page (updated 25 June 2026) puts at nearly 1,000 stakeholders. A foundation-model provider needs a senior in-house counsel who can notify the AI Office. A deployer privacy overlay does not do that work.
Harmonized standards are still the missing rulebook. The Commission page “Standardisation of the AI Act,” last updated 3 August 2026, states that CEN and CENELEC Joint Technical Committee 21 are drafting standards in ten areas, that a presumption of conformity exists only after Official Journal reference, and that on 30 October 2025 prEN 18286 — a quality-management system for AI Act purposes — became the first such draft to enter public enquiry. The page does not list an Official Journal citation for a finished harmonized standard. Until one exists, the in-house seat owns Annex IV technical documentation and the Article 17 quality-management system as a legal argument, not as a tick against a published EN. Recital (8) of the Omnibus also softened Article 4 so that providers and deployers “take measures to support” AI literacy rather than “ensure” a sufficient level. Literacy is not a reason to create a standalone officer. It does not disappear from the calendar.
| Date | Instrument | What the in-house seat holds | Counterpart |
|---|---|---|---|
| 2 Feb 2025 | Chapters I–II, Art. 5 prohibitions 1–8; literacy (later softened) | Stop-or-redesign of HR, marketing, biometric and scoring tools | National market-surveillance authority; CNIL on HR and biometrics |
| 2 Aug 2025 | GPAI model duties; Code of Practice approved 1 Aug 2025 | Notify the AI Office, training-data summary, EU SEND channel | European Commission AI Office |
| 2 Aug 2026 | Article 50 transparency; AI-Office and national enforcement live | Split provider marks from deployer labels; chatbot and deepfake notices | AI Office (GPAI and designated-platform systems); national MSA |
| 2 Dec 2026 | Art. 50(2) marking grace ends; prohibition 9 (NCII / CSAM) | Output filters, refusal training, abuse detection on generative systems | AI Office and national competent authorities |
| 9 Dec 2026 | Directive (EU) 2024/2853 applies to software and AI as product | Disclosure store, value-chain exposure, updates and learning as defects | National courts; an EU-based economic operator must be available |
| 2 Dec 2027 | Annex III high-risk Chapter III (after the Digital Omnibus) | Quality-management system, Annex IV file, notified-body interface, FRIA | National MSA once designated; notifying authority |
| 2 Aug 2028 | Annex I embedded-product high-risk; machinery on a sectoral path | Not this horizontal seat — sectoral essential-requirements counsel | Sectoral regulator plus MSA |
The buyer is a provider or a deployer, not a practice group.
Read the advertisements and the institute briefs. The companies that name this file are foundation-model providers, large banks with a digital-legal pocket, and the Commission's own AI Office.
The buyer for this seat is a company — or a public body — that is a provider or a deployer under Regulation (EU) 2024/1689. Eurostat publication KS-01-26-009, using the 2025 EU survey on ICT usage in enterprises, reports that 20.0 percent of EU enterprises with ten or more employees used at least one listed AI technology in 2025, up from 13.5 percent in 2024 and 8.1 percent in 2023. The same table puts Belgium at 34.5 percent and France at 18.2 percent; the Union rate for large enterprises is 55.0 percent. A Brussels general counsel therefore classifies a denser deployer population than a Paris peer on the same official survey. That density is a workload fact, not a headcount of legal seats.
Public 2025–2026 advertisements name three employer types. A Paris-based European foundation-model provider posted a Privacy Legal Counsel seat on 10 July 2026, on-site, inside a fifteen-person legal team split between Paris and Palo Alto, asking for three to five years in IT or privacy and treating bar admission as a plus. A Toronto-headquartered enterprise-AI company advertised Counsel, Privacy and AI Regulation (EU), to advise on the AI Act and the GDPR for an EU-facing book. A US foundation-model company circulated a Policy Counsel, EMEA seat in Dublin in June 2026, asking for six or more years and qualification in a Dublin jurisdiction. Those are title-and-gate facts. They are not a market rate.
Large universal banks are combining the file with privacy and with digital legal. Public titles at a London-headquartered bank show an AI and Emerging Technology Legal team and a Head of Group AI Governance path inside Group Legal. A Paris-headquartered bank’s London book has advertised a Head of Legal for Privacy, AI and Data Governance who is also the UK country data-protection officer. That is the bolt-on, said once: the AI Act file is often written onto the privacy counsel. The product-liability half and the GPAI notification half do not travel with that title automatically.
The European Commission is itself a buyer in Brussels. A December 2024 Legal Officer call for the AI Office inside DG CONNECT asked for at least three years in EU digital legislation and an understanding of the AI Act. A 2026 call, CNECT RL AI/2026/FG III-IV, pools about 40 contract-agent opportunities over 2027 dedicated to strengthening enforcement of Regulation (EU) 2024/1689, including a Legal Officer profile (Function Group IV) that wants a law degree plus digital, competition or product-safety experience. The counterpart a private-side general counsel will face is hiring against that credential. The enforcement split, restated on the Commission page updated 24 August 2026, gives the AI Office GPAI models and systems built on them or integrated into DSA-designated very large platforms; national authorities take other systems; the European Data Protection Supervisor takes systems of Union institutions and may impose administrative fines.
The French in-house association has already told a Paris chief legal officer where to sit. The AFJE Groupe scientifique IA conference of 5 June 2025, compte-rendu published 26 June 2025, opened on in-house lawyers as co-authors of the compliance device. A head of legal at a French digital-product consultancy described the practical point that adapting a model for a client can flip the company from deployer to provider. The CNIL, on 5 November 2025, said the DPO must be associated from the start wherever an AI system processes personal data, and that this does not make the DPO chef de file for the règlement. Its 7 April 2026 work program adds that the CNIL is preparing to be designated a market-surveillance authority in addition to its fundamental-rights role. A Paris general counsel therefore answers more than one counterpart for the same system: ACPR on credit scoring inside its perimeter, CNIL on HR and biometrics, DGCCRF and Arcom on chatbots and deepfakes, on the Direction générale des Entreprises map dated 9 September 2025.
In Belgium the in-house profession is statutory. The Instituut voor bedrijfsjuristen / Institut des juristes d’entreprise exists by the law of 1 March 2000. A new deontological code took effect 1 March 2025. The Council adopted AI-use guidelines on 20 October 2025. An IJE-hosted note of 17 October 2025 told company lawyers to audit exposure, align documentation and human oversight with the AI Act, and rewrite supplier and insurance terms for Directive (EU) 2024/2853 from December 2026. The Belgian data-protection authority’s 2025 annual report records that the APD sits with SPF Économie, SPF BOSA, the Belgian Competition Authority and the IBPT on national implementation, and that the Commission asked it to compare GDPR Article 35 DPIAs with AI Act Article 27 FRIAs. A Brussels in-house seat has two Belgian counterparts plus the sectoral Annex I regulators. London is not a Union market-surveillance seat. The ICO hub is UK GDPR and biometric guidance. A London-based general counsel of a group that places systems on the Union market still needs the European statutory seat; the privacy overlay is a different page.
The panel label, for context only, is already split by city. Legal 500 London ranks “Artificial intelligence” under TMT. Legal 500 Belgium still files the same work under “EU regulatory: Privacy and data protection.” A Brussels general counsel buying the file from a firm is still shopping in the privacy aisle. That is not a reason to hire a privacy counsel and call the statutory seat closed.
Two Commission capital announcements expand the provider population without being cash already spent. InvestAI, announced on 11 February 2025 at the Paris AI Action Summit, is a mobilization of EUR 200 billion including a EUR 20 billion gigafactories fund. A 30 July 2026 call for up to seven gigafactories is described as unlocking more than EUR 30 billion. More European frontier-model providers means more GPAI-provider seats, not more deployer DPO extensions. The AI Pact, updated 27 August 2026, is the voluntary overlay: a Commission news article of 15 December 2025 puts the network at 3,265 companies and organizations, with more than 230 voluntary pledgers and 105 reports received by the AI Office. A pledger has already committed the general counsel’s office to an inventory and a governance strategy. That is mid-level in-house work now.
The recast arrives before high-risk conformity.
Directive (EU) 2024/2853 treats software and an AI-system provider as a manufacturer. The withdrawn AI Liability Directive is not a reason to staff a third counsel.
Liability arrives before conformity. Directive (EU) 2024/2853 of 23 October 2024, published in the Official Journal on 18 November 2024, defines “product” to include software. Recital language treats a developer or producer of software, including an AI system provider within the meaning of Regulation (EU) 2024/1689, as a manufacturer. Article 2 applies the Directive to products placed on the market or put into service after 9 December 2026. Article 22 requires Member States to transpose by the same date. The Commission DG GROW page states that manufacturers remain liable for defects that appear after release because of updates, upgrades or a machine-learning feature, and that an EU-based economic operator must be available for a claim. That is the liability half of the European seat: disclosure and evidence duties in a no-fault claim, joint and several exposure along the value chain, and a live duty to treat post-release learning as defect-relevant.
Do not staff a dedicated AI Liability Directive counsel. The Commission work program 2025, COM(2025) 45 final of 11 February 2025, listed the proposal in Annex IV with the reason “No foreseeable agreement.” EAPIL recorded the formal Official Journal withdrawal notice C/2025/5423 of 6 October 2025, following the Commission’s meeting on 16 July 2025. Non-contractual exposure now rides on the product-liability recast plus national tort, using the AI Act technical file as the disclosure store. The same mid-senior counsel who can read product-safety language holds both halves. A junior “AI tort” seat is a requisition written against an instrument that is no longer on the table.
The modeled compliance file is small next to the statutory maximum. COM(2021) 206 final of 21 April 2021 priced a per-system compliance increment at approximately EUR 6,000 to EUR 7,000 in 2021 prices, with human-oversight time of EUR 5,000 to EUR 8,000 a year. CEPS, with ICF and Wavestone, in the study supporting that impact assessment, put a new quality-management system at EUR 193,000 to EUR 330,000 plus about EUR 71,400 a year to maintain, and only where no QMS already exists. Article 99(3) of the AI Act sets administrative fines of up to EUR 35,000,000 or 7 percent of worldwide annual turnover, whichever is higher, for prohibited practices; Article 99(4) sets EUR 15,000,000 or 3 percent for other operator and notified-body duties; Article 99(5) sets EUR 7,500,000 or 1 percent for misleading information to authorities. Article 101 gives the Commission a parallel EUR 15,000,000 or 3 percent power over GPAI providers, with unlimited Court of Justice review. Those ceilings are legal maxima, not collected revenue. As of the pages opened in September 2026, no 2025–2026 fine table has been published. The calendar is live. The collected-fine series is not.
A first composite from the Brussels in-house book. A mid-cap industrial deployer asked for a privacy counsel who could “cover the AI Act.” The live matter was a workplace scoring pilot that needed a stop-or-redesign review under Article 5, already applicable. The search ran five months inside the four-to-seven-month band. The company hired a mid-senior in-house counsel with employment-plus-product range, reporting to the general counsel. At month twelve the product-liability rewrite of supplier and insurance terms was still sitting with commercial. The privacy overlay had closed the prohibition file. It had not closed the seat.
Name the device boundary once and leave it. Omnibus recital (42) moves Regulation (EU) 2023/1230 from Section A to Section B of Annex I, so AI-enabled machinery follows a sectoral essential-requirements path, with delegated acts to apply by 2 August 2028. A general counsel whose only AI is a safety component of a machine or a medical device is on that embedded stack; the sibling page on med-tech and digital-health regulatory counsel owns AI-enabled medical-device software. This page is the horizontal seat: stand-alone Annex III systems, GPAI, transparency, and software-as-product liability.
Financial deployers already have a second clock that is not a substitute. On 31 July 2026 the EBA, EIOPA and ESMA published a joint statement on ICT risk from frontier AI models and on DORA oversight of critical ICT third-party providers. Annex III creditworthiness rules remain dated to 2 December 2027. A London or Paris bank general counsel who hires one counsel and calls both files closed has hired a DORA lawyer and postponed the technical file.
Classify the estateSurvive a claim
- Inventory and prohibitions Every system the company places or uses has a role, a risk tier and a kill-decision owner. This work has been live since the first application dates.
- Product-liability recast Software and AI systems are products. Updates and learning can be defects. The technical file becomes the disclosure store for a no-fault claim.
- High-risk conformity Quality-management, Annex IV, notified body, CE marking. The Omnibus moved this peak. It did not cancel the two steps before it.
The Omnibus moved conformity. It did not move the prohibition file.
Write the capability, not a title, then decide payroll or panel.
Sartori's Brussels mandate telemetry shows the stalls. The shortlist is not the problem. The brief is.
Of 15 closed Brussels in-house searches over three years, 9 were written as privacy-plus-AI combined seats, 4 were product-regulatory or digital-legal seats absorbing the Act and the product-liability recast, and 2 were standalone AI-governance titles. In 5 of those 9 privacy-plus-AI mandates, Sartori’s mandate telemetry could not verify a product-liability owner at the twelve-month mark: the recast was still sitting with commercial. That is the finding that does not flatter the method. We placed the person the brief asked for. The brief had not asked for the seat.
Five of the 15 closed files ran past the seven-month end of the typical window because the general counsel had not decided whether the work was a payroll seat or a panel instruction. Completion on the Brussels in-house book is still 93 percent. The late files completed. They completed after the company wrote down the capability. On the 11 offers extended on AI-adjacent Brussels in-house mandates in a 24-month window, 3 drew a counter-offer — the city’s 27 percent incidence — and the median offer-to-acceptance window was 13 working days. A chief legal officer who opens a search without a written capability list is buying a title. Titles are what stall.
Of 52 privacy-titled in-house counsel inside the same Brussels interview cohort, over that 24-month window, 37 said the AI Act file had been added to their seat without a requisition. The IAPP AIGP credential — 100 questions, 2.75 hours, a two-year term with 20 continuing-education credits, with official two-day training at the IAPP Europe Congress in Brussels on 16 and 17 November 2026 — appears alongside CIPP/E on the combined titles. It is a gate, not a pay scale.
A second composite. An extra-territorial foundation-model provider with a mid-teens legal team in Paris asked for a senior digital-legal counsel who could notify the AI Office and own the training-data summary. The search ran six months. The hire reports to the general counsel and sits between product and the AI Office. The privacy counsel stayed on GDPR documentation. The two desks meet. They are not substitutes.
A third composite. A universal-bank deployer wrote one requisition that mixed DORA operational-resilience language with Annex III credit-scoring conformity. The search sat for four months until the head of legal split the brief. The digital-legal counsel already on the book took the ESA statement. A separate mid-senior AI Act counsel was scoped for the 2027 technical file. One counsel cannot close both clocks.
Thomson Reuters Institute’s 2026 State of the Corporate Law Department, a global general-counsel sample, records that nearly half of general counsel cited staffing and resource constraints as the top barrier, that 36 percent expected to increase overall outside-counsel spend over the next year as of the fourth quarter of 2025, and that 20 percent planned to decrease it. That is budget pressure, not an AI Act fee schedule. It is why the payroll-or-panel decision is being made under constraint, and why a vague title is the expensive option.
Privacy only — half earn less than this
IAPP community, global
IAPP Salary and Jobs Report 2025-26, 3 August 2025 ↗| Operator role | Internal capability | Title actually posted | Counterpart |
|---|---|---|---|
| Deployer | Issue a kill-decision on a prohibited tool; keep six-month logs; inform workers; split deployer labels from provider marks | Privacy-plus-AI counsel, or head of legal for privacy, AI and data governance | National MSA; CNIL or the Belgian APD on fundamental-rights uses |
| Provider of a high-risk system | Hold Annex IV technical documentation as a legal argument until an Official Journal-referenced standard exists | Product-regulatory counsel sitting with engineering and quality | Notified body and the market-surveillance authority |
| GPAI model provider | Notify the AI Office, run the training-data summary, and treat a significant downstream modification as a new placing on the market | Senior digital-legal or EMEA policy counsel | European Commission AI Office; CJEU review of Article 101 fines |
Bring the file in when a kill-decision, a technical-file request or a product-liability disclosure cannot wait for a firm to be instructed.
- Write four capabilities. Classify, own the documentation chain, sit with the conformity body, absorb the recast.
- Name the operator role. Deployer, high-risk provider and GPAI provider are different desks and different counterparts.
- Keep privacy on privacy. Associate the DPO. Do not make that person chef de file for a product-safety file.
- Budget the unfinished map. A Brussels hire must be able to work through SPF Économie and an intended IBPT contact.
- Hold the 2026 clock. Transparency grace and the product-liability recast land this year. Conformity is a 2027 build.
Instruct out when the volume is episodic and someone inside already owns the company position before the panel drafts.
- Buy the aisle that exists. In Brussels that is still EU regulatory privacy and data protection; in London it is the AI ranking under TMT.
- Do not instruct a first-of-kind FRIA blind. Article 27 work needs an internal owner who has already classified the estate.
- Keep GPAI notification in-house at model companies. The AI Office is a counterpart, not a panel’s client-alert audience.
- Use the panel for the 2027 conformity pack. Quality-management and notified-body work can be instructed once the inventory is internal.
- Put a name on the instruction. Outside counsel files. Only the company decides whether a system is placed, adapted or killed.
- Q1 Can you name the operator role — deployer, high-risk provider, GPAI provider — and the counterpart who will ask for the file? If the brief says “AI counsel, five years” → you will hire a title and miss the desk.
- Q2 Is the live work a prohibition review, a transparency split, a GPAI notification, or a December product-liability rewrite? If the only date on the requisition is a 2027 conformity cliff → the Omnibus has already moved that date and the 2025 file is still open.
- Q3 Will a kill-decision or a technical-file request wait for a panel to be instructed? If the answer is no → the holder belongs on the payroll, and the panel executes against a settled position.
- → All three clear? Run a confidential in-house search on the capability list — or write the panel instruction against a named internal owner.
A company that wants this seat staffed can start with in-house and general counsel search or compliance and regulatory recruitment. The method behind the Brussels figures is on the research-programme page. Explore a move through a confidential CV submission.
Common questions about the European AI Act in-house seat
Does the eu ai act require a dedicated in-house counsel?
No. Regulation (EU) 2024/1689 names the company as the addressee; Article 26 places deployer duties on the legal person, not on a designated officer. The CNIL said in November 2025 that involving the data-protection officer is not the same as making that person chef de file. A general counsel still has to decide who classifies systems, who owns the technical file, and who answers a market-surveillance request — on the payroll, as an extension of privacy, or on a panel.
When does a general counsel need this seat on the payroll?
When a kill-decision, a technical file or a 9 December 2026 product-liability claim cannot wait for a panel to be instructed. Prohibitions have applied since 2 February 2025 and AI-Office enforcement since 2 August 2026. The Digital Omnibus moved high-risk conformity, not those files. A chief legal officer who cannot name the counterpart for a technical-file request is already late on the inventory.
What does an in-house AI Act counsel actually hold?
Four capabilities, not a title: classify every system the company places or uses; own the Annex IV technical-documentation chain; sit between product and the conformity body; absorb Directive (EU) 2024/2853 from 9 December 2026. Public 2025–2026 advertisements show the work arriving as privacy-plus-AI, as a head of AI governance next to risk, or as product-facing regulatory counsel. The statutory addressee remains the company.
How long does a Brussels search for this in-house seat take?
Budget 4 to 7 months on Sartori’s Brussels in-house desk, with a median of 13 working days from offer to acceptance and a 27 percent counter-offer rate. Across 15 closed Brussels in-house searches over three years, the stalls were briefing failures — payroll versus panel, privacy overlay versus product-liability skill — not empty shortlists. Completion on that book is 93 percent.
Can we fold the file into the data-protection officer?
The CNIL said in November 2025 that the DPO must be associated wherever a system processes personal data, and that this does not make the DPO chef de file for the AI Act. Article 27 pulls the DPO into a fundamental-rights impact assessment where one applies and a DPO exists. The product-liability recast and the GPAI notification file do not live in that office. Say the seat is often bolted onto privacy, then staff the half that privacy cannot hold.
Is there a published pay band for this seat in Brussels, Paris or London?
No non-recruiter publisher we opened has released one. The IAPP 2025-26 global survey is the only dated AI-governance pay series on this page, and it is not a local offer scale: half of respondents working only in AI governance earn less than USD 151,800, and half working in both privacy and AI governance earn more than USD 169,700. Treat those cuts as community texture. Do not paste them onto a Brussels offer letter.
The statute, the Official Journal, Eurostat and the designation lists.
Fine ceilings and application dates come from EUR-Lex and the Commission service desk. Enterprise AI-use rates are Eurostat. Designation status is the Commission SPOC table and a Belgian Senate answer. Pay texture is a global IAPP cut, labeled as such.
Sources and further reading
34 references- Sartori & Partners — Brussels Legal Talent Research Programme (250 structured interviews; ~4,000 lawyers mapped; quarterly surveys since 2019; mandate telemetry) sartoriglobal.com ↗
- Article 99: Penalties | AI Act Service Desk ai-act-service-desk.ec.europa.eu ↗
- Article 101: Fines for providers of general-purpose AI models | AI Act Service Desk ai-act-service-desk.ec.europa.eu ↗
- Article 26: Obligations of deployers of high-risk AI systems | AI Act Service Desk ai-act-service-desk.ec.europa.eu ↗
- Article 27: Fundamental rights impact assessment for high-risk AI systems | AI Act Service Desk ai-act-service-desk.ec.europa.eu ↗
- AI Act | Shaping Europe’s digital future digital-strategy.ec.europa.eu ↗
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August digital-strategy.ec.europa.eu ↗
- The enforcement framework of the AI Act digital-strategy.ec.europa.eu ↗
- Market Surveillance Authorities under the AI Act digital-strategy.ec.europa.eu ↗
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI) eur-lex.europa.eu ↗
- Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products eur-lex.europa.eu ↗
- Liability for defective products — European Commission (DG GROW) single-market-economy.ec.europa.eu ↗
- Commission work programme 2025, COM(2025) 45 final, Annexes 1 to 5 commission.europa.eu ↗
- European Commission Withdraws Proposals on Assignments of Claims and AI Liability — EAPIL eapil.org ↗
- Proposal for a Regulation … (Artificial Intelligence Act) COM/2021/206 final eur-lex.europa.eu ↗
- Clarifying the costs for the EU’s AI Act – CEPS ceps.eu ↗
- The use of artificial intelligence (AI) technologies in the European Union — Eurostat KS-01-26-009 ec.europa.eu ↗
- 20% of EU enterprises use AI technologies — Eurostat news, 11 December 2025 ec.europa.eu ↗
- Question écrite n° 8-303 — Belgian Senate senaat.be ↗
- Le métier de DPO à l’heure de l’intelligence artificielle : lancement de l’enquête 2025 et premières réflexions — CNIL cnil.fr ↗
- Accompagnement des professionnels : le programme de travail de la CNIL pour 2026 cnil.fr ↗
- Les autorités compétentes pour la mise en œuvre du règlement européen sur l’intelligence artificielle — Direction générale des Entreprises entreprises.gouv.fr ↗
- Standardisation of the AI Act digital-strategy.ec.europa.eu ↗
- Drawing-up a General-Purpose AI Code of Practice digital-strategy.ec.europa.eu ↗
- AI Pact marks one year of progress on trustworthy AI in Europe digital-strategy.ec.europa.eu ↗
- Guidelines on the scope of obligations for providers of general-purpose AI models under the AI Act digital-strategy.ec.europa.eu ↗
- Salary and Jobs Report 2025-26: Privacy, AI Governance and Digital Responsibility | IAPP iapp.org ↗
- Job opportunities within the AI Office — Call CNECT RL AI/2026/FG III-IV eu-careers.europa.eu ↗
- From code to liability: what company lawyers need to know about the EU’s AI and robotics rules — IJE / IBJ ibj.be ↗
- « IA Act » : co-piloter l’innovation entre tech et juridique / Compte-rendu de la conférence de l'AFJE annonces-legales.lesechos.fr ↗
- EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector eba.europa.eu ↗
- EU launches InvestAI initiative to mobilise €200 billion of investment in artificial intelligence digital-strategy.ec.europa.eu ↗
- EU launches AI Gigafactories call to boost Europe's computing capacity and unlock more than €30 billion in investment digital-strategy.ec.europa.eu ↗
- 2026 State of the Corporate Law Department | Thomson Reuters Institute insight.thomsonreuters.com ↗
Article 99 and Article 101 figures are statutory maxima, not collected fines. COM(2021) 206 and the CEPS QMS ranges are 2021-price impact-assessment models, not 2026 invoices. InvestAI and Gigafactories figures are Commission mobilization targets. IAPP cuts are a global community survey and are not a Brussels, Paris or London offer band. Eurostat measures enterprise self-reported use of listed AI technologies, not high-risk systems and not legal seats. The AI Pact and transparency-code headcounts are voluntary networks.
Sartori’s quarterly surveys have run since 2019. For the ownership question and the US obligation stack, see General Counsel and AI Governance. For the generic emerging-tech hiring read, see Is AI Law Hiring in 2026?.
Adjacent pages, different questions.
This article is the European statutory seat. The pages below own the ownership question, the generic hiring read, and the privacy desk.
General Counsel and AI Governance: A New Career Frontier
The ownership question and the US obligation stack — a different page, for a different decision.
Read the ownership briefIs AI Law Hiring in 2026?
The generic emerging-tech hiring read and the portability conversation sit on that page, not this one.
Read the 2026 hiring readIs Privacy and Data-Protection Law Hiring in 2026?
Where the privacy desk is the live market. This article names the bolt-on once and stays with the statutory AI Act seat.
Read the privacy hiring thesisA quiet conversation
Deciding whether the AI Act file is a payroll seat or a panel instruction?
We map in-house AI-compliance and product-liability counsel for companies that deploy or place systems on the Union market — and we are just as willing to say a brief is not ready as to open a search. Confidential, no obligation.