Companies exempting artificial intelligence (AI) from their existing governance system take a great and unnecessary risk in doing so.
As companies race to integrate AI across their operations, they do so with the twin goals of efficiency and productivity, but many leave out what should be equally pursued: responsibility.
Leaders act as if AI moves too fast to take that into account.
Any company that considers itself to be responsible already has a plethora of governance in place to comply with laws and regulations and manage the factors that create risk or opportunity for their business. Policies on business ethics, environmental impact, labour standards and responsible sourcing are standard.
Boards review them. Investors rely on them. Employees and customers demand them. Governments enforce them.
Existing governance answers the same types of questions that AI use inspires. Does AI’s energy and water demand work against environmental commitments? Does AI’s use in hiring or performance management introduce discrimination or reinforce bias? Does incorporating AI increase the risk of deceptive business practices?
AI keeps getting treated as a special case, with the excuse that it’s too soon to have a Responsible AI Policy to address these risks.
Nonsense.
Companies should not wait on adopting a standalone Responsible AI Policy before addressing the business and societal risks AI brings now.
Leaders should instead map their AI practices onto their existing governance framework, protecting business operations and their legal and social licenses to operate in the process.
“
There’s no need to invent new categories for disclosure from AI adoption – just a need to map AI’s risks onto the ones that already exist, and to be honest, where current disclosures fall short.
The frameworks for Responsible AI already exist
Every major technology shift produces a similar reflex – commission a study, draft a new policy, appoint a committee.
The Sustainability Accounting Standards Board’s (SASB) sustainability framework spans five dimensions against which companies already report and investors already assess: environment, social capital, human capital, leadership and governance, and business model and innovation.
Every consequence of AI adoption – strained energy and water systems, workforce disruption, widening inequality, and new questions of board oversight – fits neatly inside one of these dimensions.
A company running AI models at scale consumes meaningfully more electricity and water than it did before. This cost belongs in the same environmental disclosure the company already files.
When a retailer deploys AI across its operations and headcount falls, that’s a labor practices disclosure that belongs in human capital reporting. In a working paper based on a survey of 750 chief financial officers, the United States National Bureau of Economic Research projects roughly 502,000 AI-related job cuts in 2026, close to a nine-fold jump from the year before.
Oracle became the first major company to say so in a binding regulatory filing, telling the US Securities and Exchange Commission in June 2026 that AI adoption has led, and may continue to lead, to workforce reductions – alongside a fiscal-year headcount drop from 162,000 to 141,000.
When a bank uses AI to screen loan applications, the risk of biased or opaque decisions isn’t a new frontier – it’s a customer-fairness and data-privacy issue that maps straight to SASB’s Social Capital dimension, in the same disclosure where the bank already reports on fair lending and data security.
There’s no need to invent new categories for disclosure from AI adoption – just a need to map AI’s risks onto the ones that already exist, and to be honest, where current disclosures fall short.
Demonstrating operational maturity
Incorporating AI risk into existing policies and disclosures tests a business’ operational maturity and commitment to responsibility, and companies should be doing it whether a regulator, investor or activist asks them to or not.
Mature organisations build governance systems designed to absorb new material risks as they emerge, not spin up a parallel structure every time technology moves.
A risk mapped into the framework your board already reviews, your legal team already advises on, and your investors already use to assess performance gets properly managed.
Even though 88 per cent of organisations now use AI regularly, governance fails to keep pace.
Nearly three-quarters of companies plan to deploy AI agents within the next two years, yet only 21 per cent of them report having a mature governance model.
Mature means clear ownership, oversight, and controls embedded in the risk processes a company already runs. When companies treat a familiar type of risk as an unfamiliar problem and wait for a “new” requirement from their stakeholders, they increase their risk.
When the climate crisis first became a boardroom issue, most companies handed it to the sustainability team and kept it out of financial planning altogether. The Task Force on Climate-related Financial Disclosures changed that by requiring companies to integrate climate risk into the financial reporting frameworks they already had.
That integration took years. Given how fast AI moves, companies that wait for a dedicated AI governance regime to emerge will spend years catching up to those who stayed ahead of it.
The path forward
The path forward requires the discipline to update existing policies and frameworks, not invent new ones.
Start with your responsible investment or Environmental, Social, and Governance (ESG) policy already on the books, rather than drafting a parallel AI charter from scratch.
Map AI risk against the SASB dimensions the company reports on today, matching each new AI-driven exposure to the disclosure category it belongs in, whether that’s environmental footprint, human capital or business risk.
Then address the material changes AI brings to that risk profile – the added energy and water draw, the workforce shifts, the new bias or privacy exposure – rather than treating AI as a threat to be considered down the road.
Finally, update disclosures to reflect what’s changed, so investors and regulators aren’t reading an incomplete version of the business.
More than 5,000 private capital firms signed the Principles for Responsible Investment before AI became central to how businesses operate. The mandate has not changed, but what it takes to honor the mandate has.
Companies that adapt AI into their existing governance adapts will be the ones ready for an AI-driven world and beyond. Those which use the lack of a dedicated Responsible AI Policy as an excuse to avoid addressing the risks AI brings will be the most likely to fall behind.
Steven Okun is CEO, Megan Willis a Senior Advisor and Noemie Viterale a Manager at APAC Advisors, a Singapore-headquartered consultancy focused on geopolitics and responsible investing.

