A friend of mine was appointed Head of AI Risk at a Mumbai broker last March. The Managing Director had read the SEBI Advisory of 5 May 2026 [L1-C1] on a Sunday evening and decided by Monday morning that someone needed to own this. The decision was quick. The role definition was not.
By the time my friend walked into my office six weeks later he had three contradictory job descriptions, two reporting lines (one solid to the Chief Risk Officer and one dotted to the CTO), no written authority to pull a model out of production, and a confused Board that still thought AI governance was the same thing as data protection. He had a title. He did not have a role. The programme stalled.
If you are being considered for an AI governance seat, or you are the person asked to create one, this is the first lesson you must read. The seat is not the DPO seat renamed. It is not the CISO seat extended. It is a new seat with its own authority chain, and the Indian regulators have begun to converge on what it must look like even though the MeitY Guidelines of 5 November 2025 [L1-C2] stop short of naming the role.
The role sits between four existing seats and takes authority from each
The AI Governance Officer draws from four existing roles. From the DPO comes the authority to invoke DPDP Section 10(2)(c) proviso [L1-C3], which requires a Significant Data Fiduciary to observe due diligence to verify that algorithmic software it deploys is not likely to pose a risk to Data Principal rights. This proviso is the single clearest AI-governance hook in Indian statutory law today. The AI Governance Officer runs the diligence; the DPO carries the Section 10 signature.
From the CISO comes the authority to run the SEBI AI Advisory of 5 May 2026 on an active footing. The Advisory expects a Software Bill of Materials for every critical AI application including the open-source stack, Market SOC onboarding and the long-term plan for agentic mitigation. The CISO scopes the perimeter; the AI Governance Officer owns the model-specific items.
From the Chief Risk Officer comes model risk ownership. If the organisation is a bank or NBFC in the eleven categories covered by the RBI Draft on Model Risk [L1-C4], the Board policy on model risk management will name the AI Governance Officer as the custodian for AI and ML models within the policy perimeter.
From the Compliance Head comes regulatory interface authority. When MeitY, SEBI, RBI, IRDAI, DPDP Board or the Ministry of Information and Broadcasting asks a question about an AI system, the AI Governance Officer is the person who answers in the first instance.
This four-way draw explains why the role cannot be absorbed into any one of the existing seats. The DPO cannot answer SEBI\'s SBOM question. The CISO cannot sign a DPDP Section 10 attestation on algorithmic due diligence. The CRO cannot interpret the MeitY 7 Sutras [L1-C5] as a transparency obligation. The Compliance Head cannot run a pre-deployment bias test. One role owns the integration.
What the Board resolution must say
The Board resolution appointing the AI Governance Officer is the single document a MeitY review, a SEBI inspector or a DPDP Board officer will ask for first. It must set out five things.
One, the name, designation and employee identifier of the AI Governance Officer and the reporting line. The reporting line should be a solid line to the Managing Director or an executive director, and a dotted line to the Chairman of the Audit Committee or the Risk Management Committee. Avoid a pure functional reporting line to the CTO. The AI Governance Officer must be able to escalate over the CTO when a model needs to come out of production.
Two, the authority to maintain the AI inventory and the model register. Every AI system in use by the organisation, whether built in-house, procured from a vendor or embedded in a third-party product, enters the register. The AI Governance Officer has the standing authority to inspect each entry.
Three, the authority to require a Data Protection Impact Assessment under DPDP Section 10(2)(c) [L1-C6] and Rule 13 [L1-C7] on any AI system before go-live, and to halt go-live until the DPIA is signed off.
Four, the authority to pull a model out of production on a confirmed incident. This is the kill-switch authority that the RBI FREE-AI Report of 13 August 2025 flags as a committee expectation for banks. Even if your organisation is not a bank, write the authority in. It is the single-most consequential operational power the role carries.
Five, the independence protections. The AI Governance Officer cannot be removed or his authority diluted except by a Board resolution recorded in minutes. His compensation is not linked to the deployment velocity of any business line. He has a direct right of access to the Chairman and to the Audit Committee at any time.
Personal liability exists even in a voluntary regime
The MeitY Guidelines are voluntary. There is no standalone AI penalty regime. But the forcing functions that bite the role are not voluntary. DPDP Section 10 obligations on a Significant Data Fiduciary carry penalties up to Rs 150 crore under the Schedule. SEBI penalty powers for compliance failures under the AML/CFT Framework and the CSCRF are already in force. RBI Section 13 PMLA-style powers do not apply here, but RBI directions under the Banking Regulation Act and the Payment and Settlement Systems Act do. The IT Rules 2026 amendment of 10 February 2026 creates fresh obligations on intermediaries that touch AI-generated content, and failure attracts safe-harbour loss under Section 79 of the IT Act 2000.
The practical consequence is that the AI Governance Officer must create a documented decision trail for every judgment call. Model approved for production. Model held back for bias testing. Model deployed with human-in-the-loop guardrails. Model withdrawn after post-deployment drift. Each decision gets a dated entry in the Board decision log with the specific reasoning. The due-diligence defence lives in these files.
Five failure modes practitioners repeat
Treating the role as "DPO renamed". The DPO owns personal data processing. The AI Governance Officer owns AI systems, which touch personal data in some use cases and do not touch it at all in others. If your mental model is DPO, you will miss model-risk, bias testing and the SEBI SBOM obligation entirely.
Reporting purely to the CTO. The AI Governance Officer must be able to tell the CTO that a model is coming out of production. If the reporting line runs through the CTO, that conversation becomes a negotiation. The dotted line to the Audit Committee is non-negotiable.
No written policy. The internal AI governance policy is the artifact a MeitY review will ask for before the resolution. Without a policy, every decision is undefended. Draft the policy in Week 1, approve it by Board resolution by Week 3.
No AI inventory. If you cannot list every AI system in use in the organisation on one page in under thirty minutes, you do not have a programme. You have a hope.
Hiring the role as a part-time add-on. The role requires full-time attention in the first six months. Treating it as 20 percent of someone\'s week guarantees that neither the model risk nor the DPDP obligation nor the SEBI SBOM gets done.
Your artifact from Lesson 1
Draft the Board resolution appointing the AI Governance Officer for your organisation with the five contents above. Save it in your capstone workbook under Artifact 1. If you are running on Aarti Capital Markets as the course case study, the resolution is already pre-populated. If you are running on your real organisation, write it from a blank. The exercise forces you to put the authority chain in plain English, and that discipline is the muscle every later module will build on.