Companies Already Have the Tools to Govern AI,They're Just Not Using Them
Companies don't need to wait for new AI governance rules to emerge; they can integrate artificial intelligence risks into the existing policies and disclosure frameworks they already use for environmental, social, and labor issues. Rather than creating separate AI charters, organizations should map AI-related risks onto established governance dimensions like environmental impact, workforce management, and customer fairness, according to governance experts.
Why Are Companies Treating AI as a Special Case?
As businesses race to deploy AI across their operations, many executives treat the technology as too fast-moving to fit into traditional governance structures. This creates a dangerous gap. Even though 88 percent of organizations now use AI regularly, nearly three-quarters of companies plan to deploy AI agents within the next two years, yet only 21 percent report having a mature governance model. The disconnect stems from a common misconception: that AI requires entirely new policy frameworks rather than updates to existing ones.
This approach leaves companies exposed to significant risks. When AI systems consume more electricity and water, those environmental costs should appear in the same sustainability disclosures companies already file. When AI-driven hiring tools introduce bias, that's a customer-fairness issue that belongs in existing data-privacy and fair-lending disclosures. When workforce reductions occur due to AI adoption, those labor impacts should be reported through human-capital frameworks already in place.
What Real-World Costs Are Companies Missing?
The financial stakes are substantial. A working paper based on a survey of 750 chief financial officers projects roughly 502,000 AI-related job cuts in 2026, close to a nine-fold jump from the year before. Oracle became the first major company to publicly acknowledge this trend in a binding regulatory filing, telling the U.S. Securities and Exchange Commission in June 2026 that AI adoption has led, and may continue to lead, to workforce reductions, alongside a fiscal-year headcount drop from 162,000 to 141,000.
These aren't hypothetical concerns. They're material business risks that should already be tracked through existing governance systems. The Sustainability Accounting Standards Board (SASB) framework, which companies already report against, spans five dimensions: environment, social capital, human capital, leadership and governance, and business model and innovation. Every consequence of AI adoption fits neatly into one of these categories.
How to Map AI Risks Into Existing Governance Frameworks
- Environmental Disclosure: Companies running AI models at scale consume meaningfully more electricity and water than before. These costs belong in the same environmental disclosure the company already files, not in a separate AI report.
- Human Capital Reporting: When a retailer deploys AI across its operations and headcount falls, that's a labor practices disclosure that belongs in human capital reporting alongside existing workforce metrics and compensation data.
- Social Capital and Fairness: When a bank uses AI to screen loan applications, the risk of biased or opaque decisions isn't a new frontier; it's a customer-fairness and data-privacy issue that maps to existing fair-lending and data-security disclosures.
- Business Model Innovation: Changes to how the company operates due to AI adoption should be reflected in existing business-model disclosures, not treated as a separate category.
The path forward requires discipline and integration rather than invention. Organizations should start with their responsible investment or Environmental, Social, and Governance (ESG) policy already on the books, rather than drafting a parallel AI charter from scratch. Then they should map AI risk against the SASB dimensions they report on today, matching each new AI-driven exposure to the disclosure category it belongs in. Finally, they should update disclosures to reflect what's changed, so investors and regulators aren't reading an incomplete version of the business.
"There's no need to invent new categories for disclosure from AI adoption; just a need to map AI's risks onto the ones that already exist, and to be honest, where current disclosures fall short," stated Steven Okun, CEO at APAC Advisors.
Steven Okun, CEO at APAC Advisors
Why Did Climate Risk Governance Take So Long?
History offers a cautionary lesson. When the climate crisis first became a boardroom issue, most companies handed it to the sustainability team and kept it out of financial planning altogether. The Task Force on Climate-related Financial Disclosures later required companies to integrate climate risk into the financial reporting frameworks they already had. That integration took years. Given how fast AI moves, companies that wait for a dedicated AI governance regime to emerge will spend years catching up to those who stayed ahead of it.
Mature organizations build governance systems designed to absorb new material risks as they emerge, not spin up a parallel structure every time technology moves. A risk mapped into the framework your board already reviews, your legal team already advises on, and your investors already use to assess performance gets properly managed. When companies treat a familiar type of risk as an unfamiliar problem and wait for a "new" requirement from their stakeholders, they increase their risk rather than reduce it.
More than 5,000 private capital firms signed the Principles for Responsible Investment before AI became central to how businesses operate. The mandate has not changed, but what it takes to honor the mandate has. Companies that adapt AI into their existing governance will be the ones ready for an AI-driven world and beyond. Those which use the lack of a dedicated Responsible AI Policy as an excuse to avoid addressing the risks AI brings will be the most likely to fall behind.