If You Use AI for ESG Reporting, Who Is Legally Responsible?

If You Use AI for ESG Reporting, Who Is Legally Responsible?

Artificial intelligence may accelerate sustainability reporting. It does not transfer accountability.

Management signed the assertions.

The sustainability report was prepared with AI assistance. Data was aggregated, analysed and formatted by an automated system. The board approved the report. Management signed the assertions. Six months later, during an assurance engagement, one question was asked. “Who validated this output before it was disclosed?” No one had a clear answer. Not because the AI had failed. Because no one had defined who remained responsible for what the AI produced. That distinction is becoming one of the most important governance questions organisations will face.

The Question Nobody Is Asking

Organisations are adopting AI tools for ESG reporting at remarkable speed. Data aggregation. Materiality assessments. Narrative generation. Gap analysis. The efficiency gains are undeniable.

The governance gap is growing just as quickly. Poor governance around AI is no longer only a legal exposure. It is becoming a commercial one. Investors increasingly examine governance quality. Customers increasingly ask how sustainability information is produced. Assurance practitioners increasingly expect organisations to demonstrate that AI-supported outputs remained under meaningful human control. Most organisations still treat AI as a productivity tool. Increasingly, regulators expect organisations to demonstrate that AI-supported decisions remain subject to effective governance and documented human oversight. The legal question is no longer whether AI was used. It is whether its use was governed. That distinction matters. A tool may fail. A governance failure belongs to people.

Where the EU AI Act Changes the Conversation

The EU AI Act signals a broader regulatory direction. Where AI systems fall within its scope, organisations are expected to establish meaningful human oversight that is documented, operational and assigned to competent individuals. Even where a particular ESG AI application does not fall within the Act’s high-risk classification, the governance question remains remarkably similar. If AI contributes to corporate disclosures, organisations should be able to demonstrate: Who reviewed the output. Who understood its limitations. Who exercised independent professional judgement. Who accepted responsibility before relying on it. That expectation does not depend solely on whether a specific legal obligation applies. It reflects a broader governance principle that organisations increasingly cannot ignore. Sometimes, one question from an assurance practitioner, regulator or investor is enough to reveal whether that governance actually exists.

Where ESG and AI Accountability Intersect

Sustainability disclosures are not neutral documents. They are governance statements made to investors, regulators, customers and the market.
When AI contributes to those statements — whether by aggregating data, generating narratives or supporting materiality assessments — the question of accountability does not disappear. It simply changes direction. It moves toward the people who selected the technology. Toward those who reviewed the output. Toward those who approved the disclosure. Under the Corporate Sustainability Reporting Directive, sustainability reporting has become part of corporate governance rather than a purely operational reporting exercise. The EU AI Act reinforces another principle: technology does not remove human responsibility. Together, these developments expose a governance gap that many organisations have not yet recognised.

The Governance Gap Few Organisations Have Closed

Most organisations using AI in ESG reporting have not answered three fundamental questions. Who is responsible for validating AI-assisted ESG outputs before disclosure? What competence does that person require to exercise meaningful oversight? How is that review documented in a way capable of withstanding assurance, regulatory scrutiny or legal challenge? Without clear answers, AI risk has not been managed. It has merely been transferred into a process without identifiable accountability. From a legal perspective, responsibility follows the decision-maker — not the instrument used to reach the decision. AI changes the process. It does not change that principle. And when scrutiny begins, accountability always returns to the people who approved the outcome. It never remains with the technology.

The Board Dimension

Boards approving sustainability reports increasingly face a governance question rather than a technology question.
Approving a sustainability report is not simply authorising a document. It is confirming that the information within that document was generated, reviewed and preserved through a process the organisation understands — and can defend. If AI contributed to that process, but governance over its use was never clearly defined, documented or supervised, the board may struggle to demonstrate why reliance on those outputs was reasonable. The EU AI Act does not create accountability for governance. It makes existing governance expectations more visible.

Why This Is Also an Economic Issue

Weak governance around AI does not only increase legal exposure. It affects business value.

An organisation that cannot demonstrate control over AI-assisted sustainability information may face:

  • greater assurance costs
  • slower procurement processes
  • reduced investor confidence
  • increased regulatory scrutiny
  • diminished credibility with customers and business partners

Trust has become an economic asset. Governance is increasingly the mechanism through which that trust is earned.

What Accountability Actually Requires

AI can accelerate ESG reporting. It cannot replace governance. Nor can it replace evidence.

Responsible AI-assisted sustainability reporting requires:

  • documented human oversight identifying who reviews AI outputs, with what competence and under what authority
  • evidence demonstrating that AI operated within a controlled governance process rather than replacing informed human judgement
  • governance structures capable of demonstrating that every material sustainability statement was reviewed, challenged and approved before disclosure

Technology may generate information. Only governance transforms information into something organisations can responsibly disclose.

The Question Every Board Should Ask

If tomorrow an assurance practitioner, regulator or investor challenged one AI-assisted statement in your sustainability report, could your organisation demonstrate:
Who reviewed it? How it was reviewed? Why it was considered sufficiently reliable? Who accepted responsibility before it was disclosed? If the answer is uncertain, the problem is not the AI. The problem is the governance architecture surrounding it. Because in law, accountability does not follow the tool. It follows the decision to use it.

PROOFA™ Evidence Architecture™

Artificial and PROOFA™ Evidence Architecture™

Artificial intelligence does not reduce the need for evidence. It increases it.

PROOFA™ Evidence Architecture™ was developed as the first legal operational instrument integrating forensic methodology, ESG governance, Legal Design Thinking and evidence architecture into a single defensibility framework.

It is not an AI governance framework. It does not regulate artificial intelligence. It structures the human accountability, evidentiary integrity and governance architecture that must exist before AI-assisted information becomes part of a corporate sustainability disclosure.

Because organisations will not ultimately be judged by whether they used AI. They will be judged by whether they can demonstrate who remained accountable after they did.

This article discusses governance considerations arising at the intersection of AI-assisted sustainability reporting and emerging European regulatory frameworks. References to the EU AI Act reflect its broader governance direction and should not be understood as suggesting that every AI application used in ESG reporting is automatically classified as a high-risk AI system under the Act.

Other blogs

Ako koristite AI za ESG izvještavanje, ko je pravno odgovoran?

If You Use AI for ESG Reporting, Who Is Legally Responsible?

Artificial intelligence can accelerate sustainability reporting. It does not transfer responsibility...

Scope 3 podaci: Razlog zbog kojeg možete izgubiti EU kupca prije nego što shvatite zašto

Scope 3 Data: The Reason You Can Lose an EU Customer Before You Understand Why

The company has submitted Scope 3 data to its EU partner. The partner turned them on...

ENG