Skip to main content
Deliberate AcademyProfessional AI Education
~13 min left
Lesson 8 of 9
13 min read10 XP

Escalation and Ownership: Who Owns What, and When to Escalate

Deliberate Academy Editorial Team

Reviewed for accuracy and professional relevance

You're 8 lessons in — don't lose your progress.

Sign up free
What you'll learn
  • Map the compliance-function roles most commonly involved in AI governance work and the piece of the work each typically owns
  • Identify the handoff points between roles where gaps most often appear
  • Recognize three specific situations from this course that should trigger escalation to specialist expertise, rather than being handled at a foundational level
  • Apply this course's foundation to recognize the boundary of your own current expertise honestly, as a professional strength rather than a weakness

A newly hired compliance analyst is asked to "handle the AI governance question" for a new marketing tool that processes customer purchase history to generate personalized offers. Handled well, this is a two-minute conversation: recognize that this touches personal data, flag it to the data protection function whose existing remit covers exactly this kind of question, and confirm the handoff happened. Handled poorly, the analyst either tries to resolve the data protection question alone without the relevant expertise, or assumes someone else has already covered it and never follows up. This lesson is about getting that handoff right.

Who Typically Owns What

The compliance officer typically owns the overall program: maintaining the AI system inventory, tracking regulatory obligations against it, and reporting status upward. The AI governance lead — sometimes a dedicated role, sometimes layered onto an existing model risk or data governance function — typically owns the classification methodology and technical documentation standard. Legal and risk teams interpret how a specific regulatory obligation applies to an ambiguous or novel use case and advise on vendor contract exposure. Enterprise IT risk functions typically own the technical controls layer — access logging, system security, and infrastructure. The data protection officer, where one exists, extends their remit to cover the data governance dimension of AI systems specifically — training data provenance and personal data use in AI processing.

Tip

You do not need to personally hold the expertise every one of these roles carries. You need to recognize, from the foundation this course has built, which category a given question falls into and who is positioned to answer it — and to make sure the handoff to that person actually happens, rather than assuming it will.

Knowledge check

A compliance analyst discovers that a new marketing AI tool processes customer purchase history to generate personalized offers. Whose responsibility is it to assess whether this specific use of customer data is compatible with the organization's data protection obligations?

Select one answer.

Three Moments From This Course That Should Trigger Escalation

Looking back across this course, three specific situations should reliably prompt escalation to deeper specialist expertise rather than a foundational-level resolution: when an AI system's orientation-level EU AI Act classification suggests it is plausibly high-risk (Lesson 5) — this needs the formal classification methodology and conformity gap analysis a dedicated governance course covers, not a first-pass orientation judgment treated as final; when a GDPR Article 22 analysis is genuinely ambiguous, particularly around whether a human review step is substantive (Lesson 4) — legal counsel should confirm a borderline case; and when a vendor relationship touches a consequential, individual-level decision and the vendor's own due-diligence answers are incomplete or evasive (Lesson 6) — this warrants full legal and risk team involvement before contract signature, not just a compliance analyst's initial screen.

A Clean Handoff That Prevented a Delay — Enterprise SaaS Company

Compliance Analyst, enterprise SaaS company

Context

A compliance analyst, three months into the role, was asked to review a new AI-powered candidate-ranking feature the company's own product team was building for an HR-tech product line.

Action

Applying the orientation framework from this course, she recognized the feature plausibly fell into the EU AI Act's high-risk employment domain and that its automated ranking output likely raised a GDPR Article 22 question given how thin the proposed human review step was. Rather than attempting to resolve either question herself, she escalated both specifically — the risk classification to the company's AI governance lead, and the Article 22 human-review-adequacy question to legal counsel — with a clear, written summary of what she had found and why each question needed their expertise.

Outcome

Both specialists were able to move quickly because her summary was specific and well-scoped rather than a vague 'can someone look at this AI thing.' The AI governance lead confirmed the high-risk classification and began the formal conformity process; legal counsel identified that the proposed review step needed to be redesigned before launch. The analyst's manager specifically credited the clarity of the escalation — not just the fact that she escalated — for how quickly both issues moved to resolution.

Quick check

What does this lesson identify as the key skill this course has built, with respect to situations beyond a foundational level of expertise?

Select one answer.

Exercise

~10 min

Your Task

Think of an AI-related question currently open in your organization (or a plausible one). Identify which of the roles from this lesson — compliance officer, AI governance lead, legal/risk, IT risk, or DPO — is best positioned to resolve it, and draft the two- or three-sentence escalation summary you would send them, specific enough that they could act on it without needing to ask you clarifying questions first.

Your reflection

Did you complete this exercise? What did you find? (Saved locally in your browser)

Key takeaways
  • AI governance work typically splits across five roles — compliance officer, AI governance lead, legal/risk, IT risk, and DPO — each owning a distinct piece, with gaps most often appearing at the handoffs between them.
  • Recognizing which category a question falls into, and making sure the right person actually receives it, is more valuable at a foundational level than attempting to resolve every question personally.
  • Three specific moments from this course should reliably trigger escalation: a plausibly high-risk EU AI Act classification, a genuinely ambiguous Article 22 human-review question, and an incomplete or evasive vendor due-diligence answer on a consequential use case.
  • A clear, specific escalation summary — not just the fact of escalating — is what lets a specialist move quickly on a handed-off question.
  • Recognizing the boundary of your own current expertise honestly is a professional strength this course is specifically designed to build, not a gap to be embarrassed about.