The AI Layer

Artificial intelligence is already inside the sustainability-data workflow, reading supplier documents, filling gaps, drafting disclosures and flagging odd figures. It is genuinely useful, and it is also a new source of risk. Once a report is audited and legally exposed, a figure an AI system made up or cannot explain becomes a liability the moment it is published. This module weaves security thinking into sustainability data: where AI helps, why its output cannot be trusted blindly, how poisoned or wrong inputs propagate, and what a sensible governance policy for using AI on ESG data contains.

  • ai-on-esg-data
  • ai-trust
  • data-poisoning
  • human-in-the-loop
  • provenance
  • ai-governance
12 min · Core

Where AI Helps with ESG Data

AI earns its place in the sustainability-data workflow by attacking the parts humans find slow and dull. It reads figures out of hundreds of supplier PDFs, estimates the gaps where no data exists, drafts the narrative around the numbers, and spots the figure that does not look right. Understanding these genuine uses is the starting point before we examine where the risk lives.

~4 min

By the end you can

  • Identify the main tasks AI genuinely helps with in sustainability data.
  • Explain why these tasks are a good fit for AI rather than people.
  • Give a concrete example of AI extracting or estimating ESG data.
  • Recognise AI as an assistant to the workflow, not a replacement for it.

The dull work AI does well

Sustainability data is built out of slow, repetitive tasks. Someone has to open a supplier's energy certificate, find the right number buried on page four, and copy it into a spreadsheet, then do the same for the next four hundred suppliers. This is exactly the kind of work modern AI handles well, and it is why the technology has arrived in the workflow so quickly. Used carefully, it takes weeks of copying and pasting down to hours and frees skilled people for judgement rather than transcription.

Reading data out of documents

The clearest win is extraction. Suppliers send their information as PDFs, scanned certificates, invoices and emails, in dozens of formats and languages. An AI system can read these documents and pull out the figures a person would otherwise hunt for by hand: the kilowatt-hours on an energy bill, the emission factor in a product declaration, the waste tonnage in a compliance certificate. For a firm gathering value-chain data from hundreds of suppliers, this is the difference between an impossible task and a manageable one.

Filling the gaps and drafting the words

AI also helps where data is missing, which in sustainability is often. When a small supplier cannot provide its emissions, an AI model can produce an estimate from what is known, the supplier's industry, size and spend, using recognised estimation methods. It can also draft the surrounding disclosure: turning a table of numbers into the readable narrative a report requires, in the structure the European standards expect. A sustainability lead who once spent days writing boilerplate can start from a draft and spend that time checking instead.

Spotting what looks wrong

The fourth genuine use is anomaly detection. Sustainability figures are easy to get wrong in ways nobody notices: a factory that reports ten times its usual energy because someone typed the wrong unit, a supplier whose emissions suddenly halve for no stated reason. An AI system that has seen the normal pattern can flag the outlier for a human to examine. It does not decide the figure is wrong; it points to the figure worth a second look, which is often what a stretched team most needs.

An assistant, not an oracle

Notice what these four uses have in common. In each case AI does the heavy lifting and a person keeps the judgement: extraction still needs someone to confirm the number, an estimate is still an estimate, a draft still needs an author, a flag still needs an investigator. That framing matters for everything that follows in this module. AI is a powerful assistant to the sustainability-data workflow. It is not, and must not become, the thing that quietly decides what your published numbers are.

AI does the heavy lifting on dull tasks while a person keeps the final judgement.
AI does the heavy lifting on dull tasks while a person keeps the final judgement.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. Which set best captures the genuine uses of AI in sustainability data?

  2. Why is reading figures out of hundreds of supplier PDFs a strong fit for AI?

  3. What do all four genuine AI uses have in common?

13 min · Core

The Trust Problem with AI

The same AI that speeds the work also invents plausible figures, cites sources that do not exist, and cannot always explain how it reached a number. On its own, that would be a manageable nuisance. In sustainability data it is not, because the number will be audited, put in front of investors and exposed to the law. An AI figure you cannot verify becomes a liability the moment you publish it.

~4 min

By the end you can

  • Explain what it means for an AI system to hallucinate a figure.
  • Describe why unexplainable AI output is dangerous in an audited context.
  • Connect the trust problem to assurance, investors and legal exposure.
  • Explain why AI output here cannot be accepted blindly.

Confident, fluent and sometimes wrong

An AI language model does not look up facts the way a database does. It produces the most plausible-sounding text, and most of the time that text is right. But when it does not know, it does not stop; it fills the gap with something that reads perfectly and is simply invented. This is called a hallucination. The model might report an emission factor that sounds exactly like a real one but appears in no standard, or cite a source document that does not exist. The danger is not that the output looks wrong. The danger is that it looks completely right.

The number you cannot explain

Alongside invented figures sits a quieter problem: even when the output is correct, an AI system often cannot show its working. Ask why it produced a particular emissions estimate and you may get no traceable path from a source to the answer. In an earlier module we called traceability the ability to follow a figure back to its origin. AI, used carelessly, produces the opposite: a number with no explainable lineage. For most casual uses that is tolerable. For a figure heading into an audited report, it is a hole where the evidence should be.

Why this bites in sustainability data

In many settings a wrong AI answer costs little. Sustainability data is not one of those settings, because of the three pressures this course keeps returning to. The figure faces assurance: an external auditor will ask for the evidence behind it, and "the AI produced it" is not evidence. It is investor-grade: a bank may lend against it, so an invented number becomes a false statement in a financial decision. And it carries legal exposure: an overstated green claim, even one an AI generated, is grounds for regulatory action. A hallucinated figure is harmless in a chat window and a liability in a published report.

The moment of publication changes everything

Consider the arc. An AI-drafted estimate sitting in a working file is a helpful starting point. The same estimate, unchecked, printed in an assured report and filed with a regulator, is now a claim the company must defend and cannot. Nothing about the number changed; what changed is that others now depend on it. This is why AI output in this domain cannot be accepted blindly. It is not that the tool is bad, but that the cost of an unverified figure jumps the instant it crosses from draft to disclosure.

Trust is earned, not assumed

The lesson is not to ban AI. It is to treat every AI-produced figure as a claim that has not yet earned trust. In a chat, output is innocent until proven guilty; in an audited disclosure, it must be guilty until proven innocent. That reversal, from assume-correct to prove-correct, is the whole of the trust problem, and the remaining lessons are about how a sensible organisation manages it.

A hallucinated figure is harmless in a chat window and a liability in a published report.
A hallucinated figure is harmless in a chat window and a liability in a published report.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. What is an AI hallucination in the context of sustainability data?

  2. Why is an AI figure that cannot be explained especially dangerous in sustainability data?

  3. What changes when an AI-drafted estimate moves from a working file into a published, assured report?

14 min · Core

Data Poisoning and Why Provenance Matters More

AI does not only invent figures; it also faithfully processes whatever it is fed. If an input is wrong, whether by accident or because someone tampered with it, the error flows straight through into the report, often amplified. This is why knowing where your data came from, its provenance, matters more once AI is in the loop, not less. It connects sustainability data directly to security thinking.

~4 min

By the end you can

  • Explain how wrong or poisoned inputs propagate through an AI pipeline.
  • Define data poisoning in plain terms and give a realistic example.
  • Explain why provenance matters more, not less, with AI in the loop.
  • Connect ESG data risk to the broader field of AI security.

Garbage in, garbage out, at scale

An AI system is only as good as what it reads. Feed it a supplier certificate with a mistyped figure and it will not question the number; it will extract it, feed it into a calculation, and present the result as if it were sound. The old rule of "rubbish in, rubbish out" still holds, but AI raises the stakes, because it processes so much so fast that a single bad input can spread across a whole report before anyone notices. A wrong emission factor applied by hand affects one line. The same factor picked up by an automated pipeline can quietly reshape a hundred figures.

What data poisoning means

Data poisoningDeliberately feeding bad or manipulated data into a system so its output is skewed, for example a supplier submitting a doctored certificate that an automated pipeline extracts without question. is the deliberate version of this: someone feeds bad data into a system on purpose to bend its output. It sounds exotic, but the sustainability world offers easy openings. A supplier under pressure to look greener could submit a doctored certificate showing lower emissions, knowing an automated pipeline will accept it without a second glance. A tampered public dataset that a model draws on for estimates could nudge a whole industry's figures. The attacker does not need to break into your systems; they only need to get a wrong number into the front of your pipeline, and trust does the rest.

Why provenance now matters more

Here is the point that turns AI from a worry into a discipline. Before AI, a slow human process had natural friction: a person handling each figure might notice something odd. An automated pipeline removes that friction and moves faster, so the safeguard has to move to the front. That safeguard is provenance: a clear record of where each figure came from, who supplied it, and how trustworthy that source is. When a machine will act on data without hesitation, knowing you can trust the source becomes more important, not less. ProvenanceA clear record of where a figure came from, who supplied it, and how trustworthy that source is. It becomes the key safeguard once a machine acts on data without human friction. is how you stop a poisoned or mistaken input before it is amplified.

This is a security problem

Framed this way, sustainability data has quietly become a security concern. The questions are the ones a security team has always asked: can I trust this input, where did it come from, could someone tamper with it, and what happens downstream if they do. DSI's course on Securing AI Agents makes the same argument for autonomous systems, and its central line applies squarely here: in an AI system, data is not just data, it behaves like instructions the machine will act on. A poisoned figure is not a passive error sitting in a cell; it is an input that steers the output.

The practical stance

None of this argues against using AI. It argues for treating the inputs with the seriousness the outputs deserve. The strongest sustainability-data operations do not just check the final number; they know and grade the source of every figure that entered the pipeline, and they treat a figure from an unverified supplier differently from one from a trusted, audited source. Provenance is the difference between a system that can be steered by whoever feeds it and one that cannot.

In an AI system, a poisoned figure behaves like an instruction the machine acts on.
In an AI system, a poisoned figure behaves like an instruction the machine acts on.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. Why does a single wrong input become more dangerous once AI is in the pipeline?

  2. What is data poisoning?

  3. Why does provenance matter more once AI is in the loop?

12 min · Core

Humans and Evidence in the Loop

If AI output cannot be trusted blindly, the answer is not to abandon AI but to keep a person and a source between the machine and the published number. Human review catches what the model gets wrong, and citation-to-source keeps every AI-assisted figure traceable. Together they let a company gain AI's speed while keeping numbers that stay defensible under audit.

~4 min

By the end you can

  • Explain what keeping a human in the loop means in practice.
  • Describe citation-to-source and why it keeps a figure defensible.
  • Explain how review and citation preserve auditability with AI in use.
  • Judge where human review matters most across the workflow.

The person between the machine and the report

Keeping a human in the loop means no AI-produced figure reaches a published report without a person having checked and accepted it. This is not a token sign-off. The reviewer's job is to catch the invented emission factor, question the estimate that looks too clean, and confirm that an extracted number matches the document it came from. The model proposes; a competent person disposes. Done well, this preserves almost all of AI's speed, because checking a drafted number is far faster than producing it from scratch, while removing the risk of an unchecked figure slipping through.

Every figure carries its source

Review alone is not enough, because a reviewer who approves a number today may not be able to explain it to an auditor a year later. The second discipline is citation-to-source: every figure, whether extracted, estimated or drafted by AI, is stored with a link to the exact document or dataset it came from and a note of how it was derived. When AI reads a kilowatt-hour figure off a supplier's certificate, the figure and the certificate travel together. This is traceability applied to AI output. It turns a bare number into a defensible one, because the evidence is attached rather than lost.

Why the two together preserve auditability

Recall that assurance means an external auditor will ask for the evidence behind a figure. If AI produced the number and nobody can show where it came from, the audit stalls. But a figure that a named person reviewed and that carries a link to its source answers the auditor's question directly: here is the number, here is who checked it, here is the document it came from. The AI did the work; the human and the citation make it stand up. This is how a company gets speed and trust at the same time, rather than trading one for the other.

Where to spend the scrutiny

Not every figure needs the same weight of review, and pretending otherwise wastes the effort. A sensible team concentrates human attention where the risk is highest: figures that are large, that materially affect the headline results, that came from an estimate rather than a hard source, or that a supplier of unknown reliability provided. A routine energy reading from a trusted, metered source needs a lighter touch than a value-chain estimate feeding the group's total. Matching the depth of review to the stakes is what keeps human-in-the-loop practical rather than a bottleneck that tempts people to skip it.

The defensible AI-assisted number

Put the two disciplines together and you get the goal of this whole module: an AI-assisted figure that is also a defensible figure. It was produced quickly by a machine, checked by a person who understood the stakes, and stored with the evidence that lets anyone, an auditor, a lender, a regulator, follow it back to its origin. That is not AI replacing the workflow. It is AI inside a workflow built to keep trust as the binding constraint.

Review catches what the model gets wrong; citation keeps every figure traceable.
Review catches what the model gets wrong; citation keeps every figure traceable.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. What does keeping a human in the loop mean in practice?

  2. What is citation-to-source and why does it matter?

  3. Where should a sensible team concentrate its human review of AI-assisted figures?

13 min · Core

Governing AI on Sustainability Data

Ad hoc AI use, one analyst quietly pasting supplier data into a chatbot, is how a company ends up with figures it cannot defend and data it should not have shared. A sensible governance policy makes AI use deliberate: it says where AI may and may not be used, what must always be checked, how figures are traced, and who is accountable. This lesson lays out what such a policy contains.

~4 min

By the end you can

  • Explain why AI on ESG data needs an explicit policy, not ad hoc use.
  • List the core elements a sensible AI-on-ESG policy contains.
  • Explain the confidentiality risk of pasting supplier data into public tools.
  • Describe how accountability keeps AI use defensible.

Why a policy, not a free-for-all

Left ungoverned, AI enters an organisation through the side door. A busy analyst pastes a supplier's data into a free public chatbot to save an hour, an estimate the model produced ends up in the report with no check, and nobody can later say which figures were AI-touched. Each shortcut is understandable and each creates exposure. A governance policy exists to make AI use a deliberate choice rather than a scatter of private habits. It is not there to slow people down; it is there so the speed AI offers does not quietly cost the company its ability to defend its numbers.

What the policy should say about where AI is used

A sensible policy starts by naming the permitted uses. It states clearly where AI may help, extraction, estimation, drafting, anomaly-flagging, and where it may not, such as producing a final published figure with no human check. It draws a line around high-stakes numbers, requiring that any figure material to the headline results be reviewed by a named person before it is used. And it insists that every AI-assisted figure carry its source, so the traceability discipline is a rule, not a good intention.

Approved toolsThe specific, vetted AI services a policy permits for sustainability work, chosen so sensitive supplier and workforce data stays private and contractually contained rather than exposed to public services. and the confidentiality trap

The policy must also govern which AI tools may be used, and this is where confidentiality bites. Supplier data, workforce figures and unpublished results are sensitive. Pasting them into a free consumer chatbot can send that information to a third party and, in some cases, feed it into the tool's future training. For a European business this raises real data-protection questions, and it can breach the confidentiality a supplier expected. A sound policy therefore restricts sustainability work to approved tools that keep data private and contractually contained, and forbids pasting sensitive data into unvetted public services.

AccountabilityThe principle that a named person owns and answers for each figure even when the work was machine-assisted, so responsibility for a published number always stays human.: who owns the number

Guardrails only hold if someone owns them. The policy names who is accountable for AI-assisted figures, the same person who would answer to the auditor, so that "the AI did it" can never be an excuse. Responsibility for a number stays human even when the work was machine-assisted. This mirrors how finance already treats its figures: a tool may calculate, but a named officer signs. Extending that principle to AI-touched sustainability data is what keeps the whole arrangement defensible when the auditor, the lender or the regulator comes asking.

A policy that fits the trust argument

Read the elements together and they are simply the trust argument made operational: permitted uses so AI assists rather than decides, mandatory review and citation so figures stay defensible, approved tools so sensitive data stays protected, and clear accountability so a person always stands behind the number. A policy like this does not treat AI as a threat to be banned or a miracle to be waved through. It treats AI as a powerful tool used under discipline, which is exactly what a domain governed by assurance, investors and the law requires.

A policy makes AI use deliberate so speed never costs the ability to defend a number.
A policy makes AI use deliberate so speed never costs the ability to defend a number.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. Why does using AI on sustainability data need an explicit policy rather than ad hoc use?

  2. What is the confidentiality risk of pasting supplier data into a free public chatbot?

  3. How does accountability keep AI-assisted figures defensible?

Flashcards

Recall-first review of the load-bearing facts.

0 reviewed · 8 left

Ready to test yourself?

12 graded questions with real explanations. You commit a confidence before each reveal — that is how you find what you only think you know.

Start practice quiz →
The AI Layer — Sustainability Data as Infrastructure | Contested Futures Academy · The Contested Futures Institute