A company can post a strong ESG score and still be blind to its fastest-growing material exposure. Not because anyone gamed the rating, but because the thing creating the exposure — artificial intelligence — does not yet have a home on the scorecard. It is treated as an IT decision, when it has quietly become an environmental, social and governance one all at once.
ESG, as a language, was assembled for an industrial-era set of risks: carbon in the supply chain, safety on the factory floor, independence in the boardroom. It is good at those. But the defining corporate technology of the decade arrived after the frameworks were written, and it does not sit neatly under any single letter. AI draws heavily on the E, reshapes the S, and tests the G — simultaneously.
This essay makes a simple claim: AI has become one of the most material ESG issues a board faces, and the frameworks have not caught up. The task is not to invent a fourth letter. It is to stop filing the algorithm under 'technology' and start weighing it where it actually lands.
AI is now material across E, S and G — but ESG frameworks still treat it as a technology story, not a sustainability one. The gap between the two is where the next governance failure sits.
What follows: why the frameworks predate the machine, the 'E' nobody costed, the 'S' in the training data, the 'G' that hasn't caught up, and five moves for boards and investors.
A taxonomy with no home for AI
ESG earns its keep by making diffuse risks comparable — a shared vocabulary an investor can price and a board can govern to. That vocabulary was set before generative AI was a line in anyone's strategy. So when AI arrived, it did not slot into a category; it spread across all of them, and mostly went unrecorded.
The result is a blind spot with a paper trail. A firm can report diligently on Scope 1 and 2 emissions while the compute behind its new AI products drives a Scope 2 and 3 surge that never gets named as such. It can publish a thoughtful human-rights policy while an automated hiring or credit model quietly makes decisions the policy never anticipated. Each letter is being tested by the same technology, and the scorecard has no cell for it.
AI did not slot into a category. It spread across all of them, and mostly went unrecorded.
The footprint nobody costed
Start with the letter that feels least likely. AI is marketed as weightless — the "cloud" — but every model runs on a data centre with an electricity bill and, increasingly, a water meter. The numbers have stopped being trivial. The International Energy Agency puts data-centre electricity at around 415 terawatt-hours in 2024, about 1.5% of the world's total, and expects it to more than double to roughly 945 TWh by 2030 — more than the entire electricity consumption of Japan. Data-centre demand has grown about 12% a year since 2017, over four times faster than electricity demand as a whole.
For any organisation with a net-zero commitment, that is not a background detail; it is a material line item that most transition plans have not costed. The "clean tech" framing hides a heavy-industry energy draw — by 2030 the IEA expects US data centres alone to use more power than the production of aluminium, steel, cement and chemicals combined. An AI strategy is now, unavoidably, an environmental strategy.
The society in the training data
The social letter is where AI is most obviously consequential and least well measured. When a model screens a job application, prices a loan, triages a benefits claim or moderates a platform, it is making decisions with direct human stakes — and it makes them at a scale and speed no committee reviews case by case. Bias in the training data becomes bias in the outcome, quietly and repeatably. That is a social risk in the truest ESG sense: it touches the organisation's licence to operate.
It runs deeper than outputs. The AI supply chain has its own labour question — the data-labelling and content-moderation workforce, often low-paid and exposed to harmful material, on whom the "automated" system quietly depends. A firm can hold an impeccable modern-slavery statement for its physical supply chain and know almost nothing about the human one behind its models. The 'S' was written for factories and franchises. It now has to account for the people inside the machine, too.
The governance that hasn't caught up
Governance is meant to be the letter that ties the other two together — and here the lag is starkest. The 'G' has mature machinery for board independence, executive pay and audit. It has almost none for algorithmic accountability: who signs off a model, who can halt it, who answers when it errs. As the earlier essays in this series argued, an AI system can hold operational authority but cannot bear responsibility; that gap is precisely a governance risk, and it belongs on the ESG ledger, not just the risk register.
Regulation is closing the gap faster than reporting is. The EU AI Act makes prohibited AI use punishable by fines up to €35 million or 7% of global annual turnover — a figure that turns "AI ethics" from a values statement into a hard, financially material exposure. And the disclosure regimes are pulling in the same direction: the EU's CSRD asks for double materiality — both how the business affects the world and how the world affects the business — while the ISSB's global baseline focuses on what is financially material to the firm. On either test, a technology that reshapes a company's energy, its people decisions and its liability is not a footnote. It is a reportable, material matter that most ESG statements still pass over in silence.
A 7%-of-turnover fine turns "AI ethics" from a values statement into a material exposure.
Five moves to close the gap
None of this requires a new framework. It requires using the one we have as if AI were the material issue it has become.
Put AI in the materiality assessment
Name AI explicitly in the double-materiality exercise — across E, S and G — rather than leaving it implicit under "technology". If it isn't on the map, it won't be governed or disclosed.
Cost the compute
Bring the energy and water of AI workloads into the transition plan and the Scope 2/3 account. A net-zero commitment that ignores its own AI footprint is not credible.
Audit the social supply chain
Extend human-rights and bias due diligence to the models: the decisions they make about people, and the labour behind their training data. Treat both as licence-to-operate risks.
Extend the 'G' to the algorithm
Give AI the governance furniture the rest of the business already has — named accountability, decision rights, escalation, and the human authority to halt a system. Ethics without a control is a slogan.
Report against both materialities
Disclose AI where it is financially material (the investor's lens) and where it is material to the world (the double-materiality lens). Silence now reads as either ignorance or avoidance.
The letters were never the point; the discipline behind them was — making the diffuse comparable, and the comparable governable. AI is the first technology in a generation that is material to all three at once. An ESG report that cannot say where the algorithm sits is not describing the company as it now is.
AI is the first technology in a generation material to all three letters at once. ESG has to be able to say where it sits.
- International Energy Agency — Energy and AI (2025): data-centre electricity ≈ 415 TWh in 2024 (~1.5% of world total), projected to more than double to ~945 TWh by 2030 (exceeding Japan's total consumption) and ~1,200 TWh by 2035; ~12% annual growth since 2017; by 2030 US data centres to use more electricity than aluminium, steel, cement and chemicals combined.
- EU Artificial Intelligence Act (Regulation 2024/1689), Article 99 — penalties for prohibited AI practices up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
- EU Corporate Sustainability Reporting Directive (CSRD) / ESRS — the "double materiality" principle (impact materiality and financial materiality); and the ISSB IFRS S1/S2 global baseline, focused on financial materiality.
- Note: the framing of AI as material across E, S and G, and the five-move response, are the author's synthesis; the empirical and regulatory claims above are drawn from the cited IEA and EU sources. Argument connects to earlier essays in this series on AI accountability ("Who answers for the machine?") and algorithmic hiring.