As artificial intelligence systems become deeply embedded into the operational fabric of the global economy, a quiet, high-stakes governance gap has emerged. While corporate boards scramble to address data privacy, algorithmic bias, and intellectual property theft, a more fundamental risk is being overlooked: the unmeasured, unreported, and largely unowned environmental impact of AI.
Shruti Mukherjee, a leading expert in Governance, Risk, and Compliance (GRC), argues that because external regulation is currently lagging, the burden of oversight has shifted squarely onto the shoulders of internal audit functions. For organizations deploying AI at scale, the environmental footprint is not merely a sustainability talking point—it is a live governance exposure that remains dangerously opaque.
The Core Problem: Training vs. Inference
To understand the governance failure, one must first distinguish between the two distinct phases of an AI model’s lifecycle: training and inference.
Training is the "heavy lifting" phase. It involves feeding massive datasets into neural networks to build a model’s intelligence. It is a discrete, resource-intensive event that occurs sporadically. Because training is finite and measurable, it has become the primary target of early, albeit limited, regulatory scrutiny.
Inference, however, is the "production" phase. It is the moment when a model is queried—every automated customer service response, every image generation, and every predictive analytics output. Inference happens continuously, at scale, for as long as the system remains active.
The governance gap lies here: While regulators are beginning to focus on the energy-intensive training phase, the inference phase—which consumes the vast majority of an AI system’s total energy and water resources over its lifetime—remains almost entirely unregulated. Companies can run an AI product billions of times a day with no legal requirement to report the energy it draws or the water it evaporates in data center cooling systems.
Chronology of a Regulatory Lag
The current lack of oversight is not accidental; it is a reflection of the speed at which technology has outpaced legislative processes.
- 2022–2023: The Generative AI Explosion: The release of advanced LLMs triggered a global race for AI adoption. Environmental reporting requirements remained tethered to legacy ESG (Environmental, Social, and Governance) frameworks that did not account for the massive energy density of real-time AI inference.
- 2024: Initial Regulatory Scrutiny: Early drafts of global AI frameworks, including the EU’s landmark AI Act, flirted with strict environmental transparency requirements. However, intense lobbying and technical complexities led to the dilution of these provisions.
- 2025–Present: The "Wild West" of Reporting: As of early 2026, binding inference-phase reporting requirements have failed to materialize in major jurisdictions. This has left a vacuum where disclosure is entirely voluntary and, consequently, strategically opaque.
The GRC Perspective: Why This is a Governance Failure
It is a common error to categorize AI’s environmental footprint solely as a "green" or "sustainability" issue. By doing so, organizations relegate it to corporate social responsibility (CSR) departments rather than treating it as a core business risk.
From a GRC perspective, this is a failure of transparency and accountability. In the absence of a standardized framework, companies are not necessarily acting maliciously; they are simply operating in a landscape where there is no mechanism for consequence.

"Auditors will recognize this pattern," notes Mukherjee. "It is the same dynamic that preceded mandatory, standardized reporting in financial services and product-safety disclosures. Voluntary, incomparable across organizations, and impossible to independently verify—this is sufficient to claim transparency, but entirely insufficient to be held to it."
When a company reports "carbon neutrality" or "green AI" without a verifiable, granular breakdown of inference-related energy consumption, they are creating a future liability. If and when regulators catch up, companies that have failed to build internal measurement infrastructure will face massive compliance shocks, potential litigation, and reputational damage for "greenwashing."
Supporting Data and Technical Reality
The scale of the energy demand is staggering. Estimates from the International Energy Agency (IEA) and recent technical papers indicate that a single query to a generative AI model can consume significantly more electricity than a traditional search engine request.
- Water Consumption: Data centers require millions of gallons of water for cooling. Because inference is constant, this cooling demand is a 24/7 stressor on local water grids.
- The Scalability Gap: As companies integrate AI into every software product—from email clients to accounting tools—the energy consumption per user scales linearly, while the efficiencies gained from hardware improvements are often offset by the sheer volume of usage.
- The Auditability Void: Because there is currently no "standardized carbon cost per query," internal audit teams have no benchmark against which to measure the efficacy of their organization’s AI energy consumption.
Official Responses and Global Trends
The global response to this challenge has been fragmented. While the European Union has attempted to set a tone for AI governance, the dilution of environmental clauses in the final texts of its AI Act serves as a cautionary tale.
Many corporations have adopted a "wait-and-see" approach, hoping that market-led standards will emerge. However, relying on external rules to surface this exposure is a high-risk strategy. As history shows, regulatory frameworks often arrive late, are narrowly defined, and struggle to account for the rapid evolution of technology. For global enterprises, waiting for a centralized, worldwide standard is not a risk-management strategy—it is a recipe for non-compliance.
Implications for Audit Leaders: A Roadmap
For audit leaders, the goal is not to become environmental scientists, but to apply the rigors of the profession to this new, undefined risk. To bring this exposure into view, audit functions should begin by asking the following questions:
- Ownership: Who within the organization is responsible for the energy efficiency of our AI models? Is it the IT department, the sustainability team, or the product owners? If no one claims ownership, the risk is unmanaged.
- Measurement Logic: Can we quantify the energy and water consumption of our AI inference at a per-unit or per-user level? If not, what prevents us from doing so?
- Third-Party Exposure: Most organizations rely on cloud providers (e.g., AWS, Azure, Google Cloud) for their AI compute. Do our vendor contracts require transparency regarding the carbon intensity of the specific data centers running our AI models?
- Verifiable Claims: If we have made public statements about our AI’s sustainability, what is the supporting evidence? Are these claims audit-ready, or are they aspirational marketing?
Conclusion: The New Frontier for Internal Audit
The organizations that will lead in the next decade are those that do not wait for the law to mandate transparency. By naming the environmental footprint of AI as a governance issue today, internal audit departments can provide the assurance that stakeholders and regulators will inevitably demand tomorrow.
This is the classic role of internal audit: to provide independent assurance where external frameworks are weak or nonexistent. AI’s environmental footprint is simply the newest, most complex, and perhaps most urgent place to exercise that mandate. The audit leaders who step into this void now will not only mitigate a massive future risk—they will define the standard for the next generation of corporate responsibility in an automated world.
