Roles

Who Fills the AI Act Enforcement Officer Seats Opening Right Now?

People who have already run a case against a technical respondent: market surveillance inspectors, notified body assessors, model risk validators, security researchers and data protection case handlers. The first cohort is being hired in public. The European AI Office says it employs more than 125 staff and is recruiting around 40 contractual agents for its enforcement team across four profiles, technology specialist, legal officer, operations specialist and paralegal, with applications closing 8 September 2026 [1].

The takeHire the profile that can be wrong in public and survive it. An enforcement officer's output is a finding a well-funded provider will contest with its own engineers, so the binding constraint is not knowing the statute. It is reproducing a model's behaviour, writing down the method, and holding the conclusion under cross-examination. That rules out most commentators and most people whose technical work has never been adversarially reviewed. Split the seat if you must, pairing a lawyer with an evaluator, but do not pretend one generalist covers both halves. Nobody has ten years in this category, and asking for that is how you staff the bench wrong.

Where Olive fits

Open a role and see what the work shows

Under the automated-decision rules, "the model gave them a 74" is not an explanation. Olive produces no composite and no automated decision at all: a person writes every finding, each one carries the excerpt it rests on, and every released report exports with its rubric, scorer and bank versions attached.

Rank your shortlist

Who Is Already Hiring AI Act Enforcement Officers, and For What Work?

A provider's response lands and it is 140 pages long. It says the model was evaluated for systemic risk, cites an internal methodology nobody outside the company has read, and attaches a summary table with no seeds, no dates and no version numbers. Somebody on your side has to decide within a statutory clock whether that is compliance or a well-formatted refusal. That decision is the job, and almost nobody in the current labour pool has made it before.

The first standing bench is public. The European AI Office states that it employs more than 125 staff, including technology specialists, lawyers, policy specialists and economists, and that it is recruiting around 40 contractual agents to strengthen its enforcement team, in four profiles: technology specialist, legal officer, operations specialist and paralegal. Applications close 8 September 2026 at 12:00 Brussels time. Its powers are the shape of the work: evaluate general-purpose AI models, request information and measures from providers, investigate possible infringements, require corrective action, restrict a model's availability, and issue fines 1.

The timing is not accidental. The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026. Obligations for general-purpose AI models took effect on 2 August 2025. The rules for systems used in certain high-risk areas apply from 2 December 2027, and for AI embedded in regulated products from 2 August 2028 2. So the enforcement side is hiring roughly eighteen months ahead of the caseload it expects, which is the normal rhythm for a regulator and an unusual opportunity for anyone entering the field. This is a summary of a European regulation for orientation only; dates, scope and the split between provider and deployer duties turn on facts, and application to any specific system is a question for counsel.

Brussels is not the whole market. Every member state has to designate market surveillance authorities, and those bodies are recruiting under national budgets and national titles. Notified bodies designated for high-risk conformity assessment are staffing the mirror-image seat, which is why a notified body AI conformity assessor shows up in the same candidate pool and often against the same shortlist.

Which Tells Separate a Real Case Handler From a Policy Commentator?

The distinguishing trait is not statutory fluency, which is now cheap and widely coached. It is whether a candidate instinctively converts a claim into something checkable. Hand them a provider's model card and watch what they do in the first two minutes. Real case handlers start annotating: which version, measured when, on what data, by whom, reproducible how. Commentators summarise it.

Four tells hold up in an interview:

  • They ask for the artefact before the argument. Given a suspected infringement, the first question is what evidence exists and who holds it, not which article applies. Article selection is a later step and a cheaper one.
  • They can describe a finding they got wrong. Enforcement work produces reversals. A candidate who has never had a conclusion overturned by better evidence has either not worked cases or is not telling you about it, and both are disqualifying in different ways.
  • They know what an evaluation cannot show. Ask what a benchmark score does not tell you about a deployed system. The strong answer covers distribution shift, prompt scaffolding, unreported seeds and the gap between an evaluated checkpoint and a served endpoint.
  • They write for the respondent, not for the file. A request for information that a provider's counsel can read three ways buys a month of correspondence. Ask for a writing sample and read the questions, not the prose.

The anti-tells are just as reliable. A candidate who proposes to detect whether text or code was AI-generated is offering something that does not work and would not be admissible reasoning anyway. So is anyone who treats a vendor's own assurance report as terminal evidence. And be careful with the applicant whose whole record is commentary about the Act. Publishing on a regulation and enforcing it are different muscles, and the second one is graded by an opponent.

Which Backgrounds Produce This Person, Including the Unexpected Ones?

The obvious feeders are data protection case handlers, competition and market surveillance investigators, and lawyers from technology regulatory practice. They bring procedure, which matters more than outsiders expect, because a technically correct finding assembled through a defective process does not survive appeal.

The less obvious feeders are stronger on the technical half. Model risk validators from bank supervision have spent careers taking apart statistical systems somebody else built and documenting the limits in a form a supervisor will accept. Notified body assessors from medical devices and machinery already run the exact motion the high-risk regime imports: assess against a harmonised standard, write the deviation, defend it to a manufacturer that disagrees. Applied security researchers who have run coordinated disclosure know how to write a reproducible finding against a hostile reader and a clock. Aviation and pharmaceutical inspectors know how to walk into a facility and ask for the record rather than the summary of the record. Academic evaluation researchers bring red-teaming method, and a handful of them bring the rarer thing, which is having published a negative result about a model a large company shipped.

On the legal side, the profile that transfers best is not the policy adviser but the practitioner who has done evidence-heavy technical litigation, which is the same reason an applied legal researcher reads as adjacent rather than identical to this seat.

The candidates who got good at this used AI heavily on their own work and can tell you exactly where it failed them. The useful answers are concrete: running a provider's own model against the claims in its documentation and finding the two behaviours the card did not mention; drafting an information request with an assistant, then deleting the three questions it invented obligations for; using a model to triage a thousand pages of technical annex, then hand-checking every passage it flagged as material. That habit is not a bonus qualification here. Most of the incoming caseload is judging confident technical text produced with model assistance, and an officer who has never watched an assistant overreach will not recognise it in a respondent's filing.

Source Candidates Where Technical Findings Already Get Contested

Recruit where somebody has already had to defend a technical conclusion to a party that did not want to hear it. That narrows the venues usefully and rules out most general job boards, which return people who have read about the AI Act rather than people who have argued with an engineer about a measurement.

The concrete pools, in rough order of yield: national data protection authorities and consumer or product safety market surveillance bodies, whose staff already run investigations under an administrative procedure; notified bodies designated under the medical device and machinery regimes; model risk and supervisory technology functions at central banks and financial supervisors; standards work under CEN-CENELEC JTC 21 and the ISO/IEC 42001 and NIST AI Risk Management Framework practitioner circles, where the people writing the technical specifications assemble; and applied evaluation and safety groups in academia and at AI safety institutes. Security conferences with a real review process are the fifth pool, and the most underused one.

For the European institutions specifically, the route is the published selection procedure rather than a search firm, so treat the deadline as a hard gate and brief interested candidates early 1. National authorities hire through civil service competitions with their own calendars. If you are a private organisation hiring against this profile, understand you are competing with regulators for a small pool, and that some of your best candidates will treat a public enforcement seat as more interesting than your compliance function.

Screen on artefacts throughout. Ask for a document an external party had to respond to: an investigation report, a nonconformity finding, a validation memo, a disclosure write-up, a published evaluation with its method attached. Read it before the conversation. In this discipline the writing is the work, and a redacted real finding tells you more than any certificate on the market.

How Do You Close One, and Does This Work Sit On-Site?

Close on mandate and access before pay, because the candidates worth having have all watched a technical function get overruled by a policy function. Name who signs the finding, what happens when the officer and the lawyer disagree, and what compute and tooling budget exists for independent evaluation. An enforcement officer who can only read what a provider chooses to send is doing document review with a better title, and the good ones ask about this in the first interview.

On compensation, be honest that the category has no established band. For the European AI Office the contractual agent profiles are paid on the EU institutions' published staff scales for their function group rather than at private-sector rates, which is a known quantity to any candidate and not something a hiring team sets 1. National authorities pay their own civil service grades. Private employers pulling from this pool are effectively bidding against regulated-industry benchmarks, so the sensible reference points are model risk validation and notified body assessor bands in your market, both of which sit above general corporate compliance. Broader wage data on AI-skilled roles points the same direction, with one 2026 analysis of around one billion job advertisements reporting an average wage premium of 62 percent for roles requiring AI skills 3. Do not put a point estimate in the offer conversation that you cannot source; in a category this new, an invented number is checked against nothing and believed by nobody.

Location is genuinely mixed and worth stating in the posting. Document analysis, model evaluation and drafting travel well and much of the cohort will expect hybrid. Three parts do not travel. Inspections and any on-premise access to a provider's systems happen where the systems are. Confidential technical material, including trade secrets disclosed under statutory powers, is often handled only in a controlled environment. And case coordination across authorities is still built on people who have met, which is why the European seats are Brussels-based and the national ones sit in their capitals. Write the on-site expectation into the offer with the number of days named. Candidates from inspection backgrounds will not be surprised by it, and candidates who would be are telling you something.

Read the evidence

Common questions

How do I become an AI Act enforcement officer?

Build the evidence half first, because the statute is learnable and the technical judgement is not. Get into a role where you have to defend a measurement: model validation, conformity assessment, security research with coordinated disclosure, or a market surveillance investigation function. Then publish one reproducible evaluation of a real deployed system, with method, versions and limits stated. Read the Act and the relevant harmonised standards alongside the work rather than instead of it. When the public selection procedures open, apply through them directly; the European AI Office and national authorities recruit on published calendars rather than through search firms.

Is this a lawyer's job or a technologist's job?

Both, and current hiring splits it rather than merging it. The European AI Office is recruiting technology specialists, legal officers, operations specialists and paralegals as separate profiles for its enforcement team, which is the honest answer to whether one person covers the whole seat. In smaller authorities a single officer may carry more of the range, but the pairing is still the working unit: someone who can reproduce a behaviour and someone who can turn that into a defensible act. Hiring one and hoping the other half appears is the common failure.

How is this different from an AI compliance officer inside a company?

Direction of travel. A compliance officer builds and holds the evidence a company will be asked for. An enforcement officer decides whether the evidence somebody else produced supports the claim attached to it, with statutory powers and a contested audience. The skills overlap in documentation and standards fluency and diverge in procedure, since enforcement work carries administrative process, disclosure rules and appeal risk that an internal function never touches. People move both ways, and the crossing is easier from enforcement into industry than back.

When should an organisation start hiring against this profile?

Follow the deadlines rather than the news. Obligations for general-purpose AI models took effect on 2 August 2025, the Act became applicable on 2 August 2026, high-risk rules for certain listed areas apply from 2 December 2027, and rules for AI in regulated products from 2 August 2028. Authorities are staffing roughly eighteen months ahead of each wave. If your organisation is a provider or a notified body, hire against the same clock, because the people who can answer an enforcement request are the same people who can anticipate one, and they are being absorbed now.

What does the first ninety days look like in this seat?

Mostly inventory and method, not cases. Expect to learn the authority's administrative procedure in detail, since a finding that skips a procedural step is worthless regardless of its technical quality. Expect to map which providers fall in scope and what documentation each has already filed. Expect to build or inherit an evaluation environment and to argue about what it can and cannot demonstrate. Candidates who assume they will open an investigation in week two have misread the work, and hiring managers who promise that are setting up a resignation.

References

  1. 1. European AI Office European Commission, Shaping Europe's digital future, 2026. digital-strategy.ec.europa.eu States the AI Office employs more than 125 staff and is recruiting around 40 contractual agents for its enforcement team in four profiles, technology specialist, legal officer, operations specialist and paralegal, with applications closing 8 September 2026 at 12:00 Brussels time; also lists its GPAI evaluation, information-request, corrective-measure and sanction powers.
  2. 2. AI Act regulatory framework and application timeline European Commission, Shaping Europe's digital future, 2026. digital-strategy.ec.europa.eu Entry into force 1 August 2024, applicable 2 August 2026, GPAI obligations from 2 August 2025, high-risk rules for certain listed areas from 2 December 2027 and for AI in regulated products from 2 August 2028.
  3. 3. PwC AI Jobs Barometer 2026 PwC, 2026. pwc.com Reports an average 62 percent wage premium for roles requiring AI skills across an analysis of around one billion job advertisements. Used here only as a directional macro reference, not as a band for this title.

3 sources, numbered by first appearance. How Olive sources claims

General guidance for hiring teams. What works at one company and one volume may not transfer to yours.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.