Skip to content
7 min read

EU AI Act for ESG and Carbon Accounting Software: Risk Class, Deployer Duties, Deadlines

Featured Image

Regulation of artificial intelligence reaches climate work through the tools, not through the topic. If your team runs a carbon accounting engine, screens suppliers on ESG data or scores physical climate risk, the question worth answering is which of your systems the EU AI Act classifies, in which role you sit, and by when something is due. This page answers that for climate and ESG data platforms and skips the general explainer.

What the AI Act Requires and Which Risk Class Climate Data Tools Fall Into

The AI Act sorts systems into four classes by what they are used for. The class decides the obligation, and most climate data tooling lands in the lower two.

Risk classWhat it coversWhat it means for a climate or ESG data tool
Unacceptable riskProhibited practices such as social scoring or behavioural manipulationOut of scope for normal sustainability work, but worth one screening pass
High riskSafety components of regulated products, plus the Annex III uses such as creditworthiness, insurance pricing and critical infrastructureApplies when a climate model feeds a decision about a person or steers energy or water infrastructure
Limited riskTransparency duties for systems that interact with people or generate contentAn ESG chatbot or a drafting assistant has to disclose that it is AI
Minimal riskNo additional obligationsMost analytical tooling: factor lookups, data cleaning, anomaly detection

A separate track covers general purpose AI models. If you fine tune or prompt a hosted model, the provider carries the GPAI duties, including the extra ones attached to models with systemic risk. Conformity assessment, the formal check before market placement, only becomes your problem if something you offer is genuinely high risk.

The classification exercise is worth doing because the honest result for most sustainability teams is minimal risk. That answer is only defensible once you have written down why.

AI in Climate and ESG Data Platforms: Where the Obligations Actually Bite

Three use cases show how the same technology lands in different classes.

Emission factor matching. A model maps spend lines or activity data to emission factors in your ESG data pipeline. No decision about a person, no infrastructure control, so minimal risk.

Supplier ESG screening. A model ranks or flags suppliers. As long as the subject is a company, this stays outside the high risk list. It moves in when the same scoring reaches natural persons, for example when it feeds employment decisions or access to essential services.

Physical climate risk scoring. An internal adaptation planning score is not high risk. The identical model becomes high risk once it is wired into insurance pricing or creditworthiness assessment for individuals. AI assisted climate risk analysis that stays advisory does not: classification follows the decision the output serves, not the model architecture.

Penalties are tiered. Prohibited practices carry fines of up to 35 million euros or 7 percent of global annual turnover, most other breaches up to 15 million euros or 3 percent. For a small team the realistic exposure is not the fine but a procurement questionnaire you cannot answer.

Provider or Deployer: What a Small Team Must Do and by When

Almost every obligation attaches to a role, and most sustainability teams buy rather than build. Four questions settle it:

  • Do you place the system on the market under your own name or trademark? Then you are a provider.
  • Have you changed its intended purpose or modified it substantially? Then you are a provider, even if someone else built it.
  • Do you use it under your own authority in your own processes? Then you are a deployer.
  • Do you pass a third party tool on unchanged? Then distributor duties apply, and provider duties as soon as you rebrand it.

Deployer duties are lighter but not empty: ensure AI literacy among the people who operate the system (Article 4), follow the provider's instructions for use, name a human who can override the output, keep the logs under your control, and maintain a register of which systems you use for what.

DateWhat appliesWhat is due before it
2 February 2025Prohibited practices and the Article 4 AI literacy dutyOne screening pass, one briefing for the team
2 August 2025GPAI model obligations, governance and penaltiesAsk model and platform providers for their documentation
2 August 2026General application, including the Article 50 transparency duties; the Annex III high risk obligations were deferred by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026Classification finished, transparency notices in place
2 December 2027Standalone high risk systems under Annex IIIDocumentation, risk management and logging in place for anything high risk
2 August 2028High risk systems embedded in regulated products (Annex I)Only relevant if your tool ships inside a regulated product

Providers outside the EU are not outside this. The Act follows market placement, so a platform sold into the EU, or whose output is used there, carries the same duties as one built in Frankfurt.

Where AI Act Documentation Overlaps CSRD and VSME Data Duties

Teams already reporting under ESRS or the VSME standard own most of the governance layer the AI Act asks for, filed under a different name. A data point inventory with named owners answers the human oversight question. Documented sources and estimation methods per figure answer data governance. A versioned methodology note and a change log answer technical documentation. Quality tiering of inputs, the discipline behind data quality beating data volume, is the evidence that an input dataset was chosen deliberately.

The overlap is in substance, not in form. An ESRS data point inventory is not an AI Act technical documentation file, but it answers most of the questions inside one. Extending the reporting documentation you maintain anyway beats opening a parallel AI compliance workstream. One angle the AI governance literature skips: Article 40 pulls energy and resource performance of AI systems into the harmonised standards work, so the efficiency figures you already track will be asked for here too.

One position worth stating plainly, because the human oversight duty is easy to tick off on paper: an AI generated materiality result or emission figure is a starting point, never an audit ready result. Oversight is only real when a named reviewer can reconstruct how the number came about, which inputs went in, which method and assumptions the model applied, and what the review changed. Where that reconstruction is not possible, the figure does not belong in the report, whatever the tool says.

FAQs

Am I a provider or a deployer if I embed a third party ESG model?

You are a deployer while you use the tool as delivered. You become a provider the moment you put your own name or trademark on it, change its intended purpose or modify it substantially.

Is a carbon accounting or ESG model high risk?

Usually not. It becomes high risk when the output feeds an Annex III use such as creditworthiness or insurance pricing for individuals, or the management of critical infrastructure. Analytical tooling on company data stays minimal risk.

Do GPAI rules apply if you only fine tune or prompt a model?

The model provider carries the GPAI obligations. Prompting or light fine tuning does not usually make you a model provider, but the system you build on top is yours to classify and document.

Does the AI Act apply to a provider outside the EU?

Yes, if the system is placed on the EU market or its output is used in the EU. Guidance and templates come from the European AI Office.

Johannes Fiegenbaum

Johannes Fiegenbaum

ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.

More about