As AI becomes embedded in business operations, Data Protection Officers (DPOs) are taking on expanded roles beyond GDPR compliance. The EU AI Act introduces new obligations around risk classification, transparency, human oversight, and lifecycle management that complement existing data protection duties. DPOs bring expertise in privacy risk assessments, data mapping, and accountability documentation that directly supports AI governance. Key elements of an effective AI governance framework include maintaining an AI inventory, classifying systems by risk level, establishing governance policies, and fostering cross-functional collaboration. GDPR principles like lawfulness, data minimization, transparency, and accountability align closely with responsible AI practices. Privacy by Design should be embedded from the start of AI development rather than added retroactively. Compliance alone is insufficient — trustworthy AI also requires fairness, explainability, and ethical consideration of impacts on individuals.