By: Johannes Fiegenbaum on 7/4/25, 3:29 PM · Last updated September 5, 2026
Regulation of artificial intelligence reaches climate work through the tools, not through the topic. If your team runs a carbon accounting engine, screens suppliers on ESG data or scores physical climate risk, the question worth answering is which of your systems the EU AI Act classifies, in which role you sit, and by when something is due. This page answers that for climate and ESG data platforms and skips the general explainer.
The AI Act sorts systems into four classes by what they are used for. The class decides the obligation, and most climate data tooling lands in the lower two.
| Risk class | What it covers | What it means for a climate or ESG data tool |
|---|---|---|
| Unacceptable risk | Prohibited practices such as social scoring or behavioural manipulation | Out of scope for normal sustainability work, but worth one screening pass |
| High risk | Safety components of regulated products, plus the Annex III uses such as creditworthiness, insurance pricing and critical infrastructure | Applies when a climate model feeds a decision about a person or steers energy or water infrastructure |
| Limited risk | Transparency duties for systems that interact with people or generate content | An ESG chatbot or a drafting assistant has to disclose that it is AI |
| Minimal risk | No additional obligations | Most analytical tooling: factor lookups, data cleaning, anomaly detection |
A separate track covers general purpose AI models. If you fine tune or prompt a hosted model, the provider carries the GPAI duties, including the extra ones attached to models with systemic risk. Conformity assessment, the formal check before market placement, only becomes your problem if something you offer is genuinely high risk.
The classification exercise is worth doing because the honest result for most sustainability teams is minimal risk. That answer is only defensible once you have written down why.
Three use cases show how the same technology lands in different classes.
Emission factor matching. A model maps spend lines or activity data to emission factors in your ESG data pipeline. No decision about a person, no infrastructure control, so minimal risk.
Supplier ESG screening. A model ranks or flags suppliers. As long as the subject is a company, this stays outside the high risk list. It moves in when the same scoring reaches natural persons, for example when it feeds employment decisions or access to essential services.
Physical climate risk scoring. An internal adaptation planning score is not high risk. The identical model becomes high risk once it is wired into insurance pricing or creditworthiness assessment for individuals. AI assisted climate risk analysis that stays advisory does not: classification follows the decision the output serves, not the model architecture.
Penalties are tiered. Prohibited practices carry fines of up to 35 million euros or 7 percent of global annual turnover, most other breaches up to 15 million euros or 3 percent. For a small team the realistic exposure is not the fine but a procurement questionnaire you cannot answer.
Almost every obligation attaches to a role, and most sustainability teams buy rather than build. Four questions settle it:
Deployer duties are lighter but not empty: ensure AI literacy among the people who operate the system (Article 4), follow the provider's instructions for use, name a human who can override the output, keep the logs under your control, and maintain a register of which systems you use for what.
| Date | What applies | What is due before it |
|---|---|---|
| 2 February 2025 | Prohibited practices and the Article 4 AI literacy duty | One screening pass, one briefing for the team |
| 2 August 2025 | GPAI model obligations, governance and penalties | Ask model and platform providers for their documentation |
| 2 August 2026 | General application, including the Article 50 transparency duties; the Annex III high risk obligations were deferred by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026 | Classification finished, transparency notices in place |
| 2 December 2027 | Standalone high risk systems under Annex III | Documentation, risk management and logging in place for anything high risk |
| 2 August 2028 | High risk systems embedded in regulated products (Annex I) | Only relevant if your tool ships inside a regulated product |
Providers outside the EU are not outside this. The Act follows market placement, so a platform sold into the EU, or whose output is used there, carries the same duties as one built in Frankfurt.
Teams already reporting under ESRS or the VSME standard own most of the governance layer the AI Act asks for, filed under a different name. A data point inventory with named owners answers the human oversight question. Documented sources and estimation methods per figure answer data governance. A versioned methodology note and a change log answer technical documentation. Quality tiering of inputs, the discipline behind data quality beating data volume, is the evidence that an input dataset was chosen deliberately.
The overlap is in substance, not in form. An ESRS data point inventory is not an AI Act technical documentation file, but it answers most of the questions inside one. Extending the reporting documentation you maintain anyway beats opening a parallel AI compliance workstream. One angle the AI governance literature skips: Article 40 pulls energy and resource performance of AI systems into the harmonised standards work, so the efficiency figures you already track will be asked for here too.
One position worth stating plainly, because the human oversight duty is easy to tick off on paper: an AI generated materiality result or emission figure is a starting point, never an audit ready result. Oversight is only real when a named reviewer can reconstruct how the number came about, which inputs went in, which method and assumptions the model applied, and what the review changed. Where that reconstruction is not possible, the figure does not belong in the report, whatever the tool says.
You are a deployer while you use the tool as delivered. You become a provider the moment you put your own name or trademark on it, change its intended purpose or modify it substantially.
Usually not. It becomes high risk when the output feeds an Annex III use such as creditworthiness or insurance pricing for individuals, or the management of critical infrastructure. Analytical tooling on company data stays minimal risk.
The model provider carries the GPAI obligations. Prompting or light fine tuning does not usually make you a model provider, but the system you build on top is yours to classify and document.
Yes, if the system is placed on the EU market or its output is used in the EU. Guidance and templates come from the European AI Office.
ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.
More aboutUnder the CSRD, climate risk is not a report of its own. It is disclosed under ESRS E1, the standard whose formal topic name is climate change, and it splits into two categories: ...
Read more →