There is a sentence in a paper published last week that should be pinned above every ESG reporting desk. A generative tool used to draft assurance documentation should not be allowed to convert absence of evidence into confident prose.
That is the whole problem in one line. AI is good at producing text that reads as though it is supported. Sustainability assurance is the practice of checking whether text is actually supported. Those two things are on a collision course, and the collision arrives in December 2026 when ISSA 5000 takes effect.
Most ESG functions are already using AI somewhere in the reporting chain, often without a policy governing it. Here is where the audit trail breaks, what assurance providers will ask, and what a workable governance policy contains.
Where AI Is Already In The Workflow
Three use cases dominate, and they carry very different risk profiles.
Data collection and extraction. Pulling emissions figures from utility bills, extracting supplier data from questionnaires and certificates, classifying value chain evidence, reconciling figures across systems. This is where AI adds the most value and where the risk is most manageable, because outputs can be traced back to a source document.
Structured tagging. Digital submission is becoming standard. CSRD reporting requires digital tagging, Malaysia routes disclosures through a structured submission platform, and the EU's Digital Product Passport regime rests on machine-readable identifiers. Mapping narrative content to taxonomy elements is repetitive work that AI handles well, and mis-tagging is a defect that propagates silently into every downstream consumer of the data.
Narrative drafting. Producing the strategy discussion, the risk management description, the governance section. This is the highest risk use by a distance, and it is also the most common, because it is the most obviously time-saving.
The reason narrative drafting is dangerous is not that models hallucinate facts, though they can. It is that fluent prose creates an impression of substantiation that the underlying evidence may not support. A model asked to describe board oversight of climate risk will produce a competent paragraph whether or not the board did anything. The output looks the same either way.
What The AI Act Requires Of You Right Now
This is where a lot of companies have quietly stopped paying attention, and they have misread the situation.
The EU's Digital Omnibus on AI, Regulation (EU) 2026/1744, was published on 24 July 2026 and entered into force on 27 July, six days before the AI Act's high-risk deadline. It deferred the core high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in products already regulated under EU product safety law to 2 August 2028.
The headline was that the EU delayed the AI Act. That reading is imprecise in a way that matters.
Article 50 transparency obligations were not deferred. They took effect on 2 August 2026 as scheduled. Deployers must disclose when people are interacting with an AI system and when content has been artificially generated or manipulated. Providers of generative systems must mark outputs in a machine-readable form. Generative systems already on the market before 2 August 2026 have a short grace period to 2 December 2026 for the machine-readable marking requirement.
Article 4 AI literacy has applied since 2 February 2025, with its wording amended on 27 July 2026. It places a direct duty on both providers and deployers to take measures supporting AI literacy among staff dealing with AI systems on their behalf. A company using AI in its ESG function is a deployer. This obligation is live, it is not deferred, and it is the one most commonly overlooked because it does not feel like a compliance requirement.
2 December 2026 brings the Article 50 marking requirement for legacy generative systems and two new prohibited practices.
For most ESG teams, AI used in sustainability reporting will not fall within the Annex III high-risk categories, which centre on areas such as employment, credit and law enforcement. That does not leave you unregulated. Literacy and transparency obligations apply now, and the deferral of the hardest requirements is time to prepare rather than permission to stop.
Where Audit Trails Break
Four failure points recur, and each has a specific remedy.
Extraction without linkage. A model reads a utility invoice and produces a kilowatt hour figure, which flows into a spreadsheet and then into a report. If the link back to the specific invoice, page and field is not retained, an assurer cannot trace the figure to source. The remedy is that any model classifying or extracting evidence should retain links to source documents as part of its output, not as a separate manual step.
Estimation presented as measurement. Where a model infers a value rather than reading it, the output frequently arrives looking identical to a measured figure. Estimated data must carry its status, the method used and the basis. An emissions estimation model should be evaluated for methodology, data completeness, uncertainty and sensitivity, and those evaluations should be documented.
Silent version drift. A model, prompt or configuration changes between reporting periods and prior year figures become non-reproducible. Financial reporting solved this with version control and change logs decades ago. ESG functions using AI tools frequently have neither.
Judgement quietly delegated. A system used to compare disclosures against a reporting standard is a useful checking tool. It should not be treated as determining materiality. The distinction sounds obvious and is routinely lost in practice, because a tool that outputs a materiality assessment looks like it made one.
The underlying insight from the research is worth stating plainly: AI redistributes judgement rather than eliminating it. The judgement moves from the person writing the disclosure to the people choosing the tool, designing the prompt, setting the thresholds and reviewing the output. If nobody has been told they own those decisions, nobody does.
What Assurance Providers Will Ask
ISSA 5000 became the global baseline standard for sustainability assurance, published in November 2024 and effective for periods beginning on or after 15 December 2026. It is framework-neutral, it applies to both limited and reasonable assurance, and it explicitly recognises growing reliance on technology for evidence gathering.
Practitioners preparing for engagements should expect questions along these lines.
Which parts of the reported information involved AI, and how. Not whether you used AI, but where in the chain and for what purpose. Extraction, calculation, tagging and drafting attract different levels of scrutiny.
Can every reported figure be traced to a source? This is the question that decides the engagement. Traceability is not weakened by AI involvement, but it is frequently lost in AI-assisted workflows that were designed for speed.
How was the tool validated? What testing established that the model performs acceptably on your data? Accuracy on a vendor's benchmark is not evidence of accuracy on your invoices.
Who reviewed the output, with what competence, and what did they change? Human oversight has to be evidenced, not asserted. A review that never results in a correction is indistinguishable from no review at all.
How are estimates distinguished from actuals? And where estimates were generated by a model, what is the basis and the uncertainty.
What changed since last period? Model, prompt, configuration, data source. Restatement is normal in sustainability reporting; unexplained restatement is not.
Assurance providers are also under their own pressure here. The profession is adopting AI in its engagements while simultaneously being expected to assure AI-assisted client data, and firms are working through their own governance of that. Expect the questions to sharpen rather than soften.
Building An AI Governance Policy For The ESG Function
Seven components cover the ground, drawn from the categories emerging in the research literature and consistent with the Govern, Map, Measure and Manage structure of the NIST AI Risk Management Framework.
Use-case governance. Define which uses are permitted, which require approval and which are prohibited. The most useful policies name specific prohibited uses rather than stating general principles. Drafting narrative that asserts facts not evidenced elsewhere in the reporting pack is a good candidate for the prohibited list.
Evidence boundaries. For each permitted use, define what the tool may and may not determine. Classification, yes. Materiality, no. Extraction with source linkage, yes. Estimation without documented method, no.
Validation. Establish how tools are tested before deployment and re-tested after changes, on your own data rather than vendor benchmarks, with results documented.
Data controls. Cover input data quality, confidentiality of commercially sensitive supplier information, and where data goes when it enters a third party tool. Supplier data provided under commercial confidentiality is a particular exposure.
Human oversight. Name the reviewer for each use case, define what review means in practice, and require evidence of it. Oversight that cannot be demonstrated does not exist for assurance purposes.
Documentation and change logging. Record tool, version, prompt or configuration, date and reviewer for anything that touches reported figures. This is the single highest value control and the one most often missing.
Competence and incident monitoring. Train the people using the tools, which also discharges the AI Act literacy obligation, and establish how errors are identified, escalated and corrected.
Two further points on ownership. The policy should sit with whoever owns the reported numbers, usually finance or the sustainability controller, rather than with IT. And it should be written before the tooling is procured, because retrofitting governance onto a deployed system is considerably harder than specifying it in advance.
The Line That Matters Most
Return to where this started. The distinctive risk of AI in sustainability reporting is not fabrication. It is fluency without foundation.
Sustainability disclosure has a long-standing weakness that this technology could make much worse. The first wave of voluntary California SB 261 climate risk reports showed 92 per cent of companies claiming board-level oversight while only 12 per cent referenced a formal transition plan and only 12 per cent quantified financial impacts. The governance language was already outrunning the governance substance before generative tools entered the picture.
A model asked to write that governance section will produce something plausible in seconds. It will not know whether the board met, what it reviewed or what it decided. The organisation has to know that, and has to be able to show it.
Used well, AI genuinely helps. Extraction with retained source links, anomaly detection across large datasets, consistency checking against a taxonomy and first-draft structuring all reduce cost without weakening evidence. The research on early SB 261 disclosures was itself produced using an AI extraction tool with manual verification of every extraction against the source, which is a reasonable model for how this should work.
The test is simple. If the AI produces something an assurer can trace, it is helping. If it produces something that merely reads well, it is manufacturing risk. Build the policy around that distinction and most of the rest follows.
Governance Checklist
-
Inventory where AI already sits in your reporting chain, covering extraction, calculation, tagging and narrative drafting.
-
Note that Article 4 AI literacy obligations under the EU AI Act have applied since 2 February 2025 and were not deferred.
-
Note that Article 50 transparency obligations took effect on 2 August 2026, with a marking grace period to 2 December 2026 for legacy generative systems.
-
Understand that high-risk obligations were deferred to 2 December 2027 for Annex III and 2 August 2028 for Annex I, which is preparation time rather than a stand down.
-
Require any extraction or classification tool to retain links to source documents as part of its output.
-
Prohibit tools from determining materiality, which remains a human judgement.
-
Evaluate emissions estimation models for methodology, data completeness, uncertainty and sensitivity, and document the evaluation.
-
Distinguish estimates from actuals in every output, with basis recorded.
-
Log tool, version, prompt or configuration, date and reviewer for anything touching reported figures.
-
Validate tools on your own data before deployment and after any change, not on vendor benchmarks.
-
Name a human reviewer per use case and require evidence that review occurred and what changed.
-
Address confidentiality of supplier data entering third party tools.
-
Train users, which also discharges the AI literacy obligation, and establish an incident escalation route.
-
Prepare for ISSA 5000 assurance from periods beginning on or after 15 December 2026, and expect direct questions about AI involvement.
-
Place ownership of the policy with whoever owns the reported numbers rather than with IT.
Position as of September 2026. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and amended the AI Act timeline. Whether particular AI uses fall within high-risk categories depends on the specific system and context, and this article does not assess that for any organisation. Confirm current obligations with counsel and take professional advice for your circumstances.
Sources
Regulation (EU), International Auditing and Assurance Standards Board, IAASB, National Institute of Standards and Technology, Professional Judgment and AI Disclosure Governance in Audit and Sustainability Assurance, AI and Data Analytics in Sustainable Financial Reporting and ESG Disclosure, Governance and Accountability Institute and Ceres, European Sustainability Reporting Standards digital tagging requirements, Gibson Dunn, DLA Piper, Pinsent Masons, Protiviti, Coolset, CPA Australia
This article is intended for general professional information and does not constitute legal, financial, or investment advice.
Subscribe to our newsletter for more insights, case studies, and ESG intelligence.
Keep abreast of the top ESG Events on OneStop ESG Events.
OneStop ESG Educate: Your go-to source for top ESG courses and training programs tailored to your needs.
Stay informed with the latest insights on OneStop ESG News.
Discover meaningful career opportunities on OneStop ESG Jobs.
.png%3Falt%3Dmedia%26token%3Df424d82f-cf72-4aec-a5ee-a1263006bd81&w=3840&q=100)




.png%3Falt%3Dmedia%26token%3D910a4ea1-9886-4e46-a5c9-0b48aa7b96bf&w=1920&q=90)
