When external regulation lags, internal audit becomes the only line of defense. AIโ€™s environmental footprint is a live governance exposure, and right now, almost no one is auditing it.

A company can run an AI product billions of times a day with no obligation to measure what it consumes: No requirement to report the energy it draws or the water it evaporates doing so. That is the current state of regulation worldwide.

Shrutiheadshot
Shruti Mukherjee

For internal audit, the interesting question isnโ€™t whether thatโ€™s fair to the environment. Itโ€™s this: Any organization deploying AI at scale is carrying an exposure that is unmeasured, unreported, and in most organizations, unowned. No one is accountable for it because no external framework forces the question, and internal functions rarely raise it on their own.

This article offers audit leaders a way to see and assess that exposure before regulation forces the issue: The technical distinction behind the gap, why itโ€™s a governance failure rather than an environmental one, and the questions an audit function can ask now to bring the risk into view.

Training versus inference

Two phases define an AI systemโ€™s life, and the gap lives in the difference between them.

Training is when a model is built: A discrete, resource-intensive event using large data and compute, happening once or a handful of times before release. Because it is finite and measurable, it is relatively easy to document.

Inference is when the model runs: every query, every generated image, every automated decision. It happens continuously, at scale, for as long as the system is deployed, and it is the phase that touches users every day.

The governance problem reduces to one line: The measurable phase is the one regulators are beginning to address, while the phase that scales without limit carries no equivalent obligation. The smaller, bounded problem is on the books. The larger, open-ended one is not.

Why this is a GRC problem, not an environmental one

The instinct is to file this under sustainability. That is a mistake, and it matters for how the profession responds.

Absent an obligation to disclose, disclosure defaults to whatever is strategically convenient. Companies are not withholding inference data because they are uniquely irresponsible. They are withholding it because no framework compels them to surface it, no standard makes it comparable, and no mechanism creates a consequence for opacity.

Auditors will recognize the pattern. Itโ€™s the same dynamic that preceded mandatory, standardized reporting in financial services and product-safety disclosure: Voluntary, incomparable across organizations, and impossible to independently verify. Sufficient to claim transparency, insufficient to be held to it.

That is a governance gap, not a green issue. And governance gaps are exactly what internal audit exists to surface.

What audit leaders should look for

This is not a call to develop new environmental measurement science. It is a call to apply existing audit logic to a risk most assurance functions have not yet named.

  • Is AI environmental consumption owned by anyone? Identify whether any role, function, or risk register entry accounts for the energy and water footprint of the organizationโ€™s AI use. In most organizations the honest answer is no, which is itself the finding. An unowned risk is an ungoverned one.
  • Can the organization measure inference, or only training? Many organizations that can describe the footprint of building or procuring a model cannot describe the footprint of running it day-to-day. A measurement capability that stops at training has captured the bounded problem and missed the one that scales.
  • What environmental disclosures exist in third-party AI contracts, and are they comparable or verifiable? Most organizations consume AI through vendors rather than building their own models, which makes this a vendor-risk question. Test whether contracts require any environmental disclosure at all, and whether whatโ€™s disclosed is standardized enough to be audited, or simply a vendorโ€™s self-designed figure taken on faith.
  • Can internal audit substantiate the organizationโ€™s own environmental claims? If the organization makes external statements about efficiency gains or sustainability targets touching AI, test whether those claims can be independently substantiated. An unverifiable claim is a greenwashing exposure waiting to surface, and it sits with the organization, not the vendor that supplied the number.

None of this requires the auditor to become an environmental scientist. Each question is about ownership, measurement, third-party risk, and verifiable claims: the core territory of the profession.

The global dimension

The temptation is to treat this as a European problem, since Europe has moved first. The lesson is the opposite.

The EUโ€™s AI framework illustrates the gap rather than defines it: Environmental provisions in early drafts were diluted through negotiation, and binding inference-phase reporting didnโ€™t survive into the final text.

Treat that as a case study, not the subject. Environmental disclosure obligations for AI are immature, fragmented, and trailing the technology everywhere, shifting as commercial and political pressure is applied. No global audit function can outsource this risk to its regulator. Relying on external rules to surface the exposure means waiting for a framework that, as the trajectory shows, may arrive late, narrow, or not at all.

The first line that sees it

Governance gaps left open by regulation are precisely where internal auditโ€™s independent assurance role earns its keep. When no external framework compels an organization to measure a risk, the function that names it first is doing the job the profession exists to do.

The organizations that get ahead of this wonโ€™t be the ones that waited for a standard. Theyโ€™ll be the ones whose audit functions asked, early and plainly: Who owns this, what can we measure, and what have we claimed that we cannot prove. Those arenโ€™t environmental questions. Theyโ€™re the questions internal audit was built to ask, and AIโ€™s environmental footprint is simply the newest place to ask them.


Shruti Mukherjee is a GRC thought leader specializing in cybersecurity, privacy, and AI governance. She works at the intersection of technology, regulation, and operational risk, advising organizations on building practical, scalable governance programs in increasingly automated environments. She is a frequent speaker on topics including AI risk, security governance, and modern compliance challenges.