AI & Research

Who Is Accountable for the AI? Governance in Sustainable Finance

Oct 6, 2026 · 5 min read

Dr. Elham KheradmandCEO, Lucid Axon
Illustration of AI governance in sustainable finance: who owns, checks and answers for an AI system
In this article
  1. What AI governance means in an investment firm
  2. The rules are arriving unevenly
  3. Investors sit on both sides of the question
  4. Where to start
  5. Governance is how the promise holds

Sustainable AI needs an owner. A footprint measured once and a source cited once prove little unless someone is accountable for keeping both true as models, vendors and data change.

That accountability is AI governance. In sustainable finance it has moved from good practice to an expectation of regulators, clients and shareholders. This piece covers what it means inside an investment firm, which rules now apply, and where to start.

What AI governance means in an investment firm

AI governance is the set of answers to four plain questions. A firm that can answer all four has governance. A firm that cannot is relying on its vendors’ goodwill.

ElementThe question it answers
InventoryWhere is AI used in our research, screening, reporting and client work?
OwnershipWho signs off on each use, and who answers when it is wrong?
Validation and monitoringHow do we know it works today, and how will we notice when it stops?
Vendor oversightWhat do we know about the models we buy, and what can we ask of their providers?

The last row matters most in our field. Few investment firms train their own models. Most of their AI arrives inside tools they buy, so governing AI largely means governing suppliers.

Language models also change in ways older models did not. A provider can update a model without notice, and the same prompt can return a different answer next month. Monitoring has to be continuous, because a one-time approval goes stale.

The rules are arriving unevenly

No single AI law covers a Canadian investment firm today. The obligations come from a patchwork of financial regulation, privacy law, European rules and voluntary standards.

InstrumentWhat it asksStatus, October 2026
OSFI Guideline E-23Model risk management for AI and machine-learning models, vendor models includedFinal September 2025; effective 1 May 2027 [1][2]
Quebec Law 25Privacy duties, including transparency about automated decisionsFully in force since September 2024
EU AI ActDocumentation duties for general-purpose model providers, energy use includedApplied to those providers from 2 August 2025; high-risk duties delayed in July 2026 [3][4]
Canada’s AIDAA proposed federal AI lawLapsed in January 2025; the 2023 voluntary code on generative AI remains
ISO/IEC 42001A certifiable AI management systemPublished December 2023; appearing in procurement
NIST AI Risk Management FrameworkA voluntary risk framework with a generative AI profileActive
ISO/IEC TR 20226Metrics for the environmental side of AI systemsPublished July 2025 [5]

Two things stand out. In Canada the binding pressure comes through the financial regulator, with no AI statute behind it. And the standards now reach the environmental footprint, so governance and sustainability are converging on the same evidence.

Investors sit on both sides of the question

Investors ask portfolio companies about AI governance, and are now being asked about their own.

On the asking side, AI oversight has reached the proxy ballot. At Alphabet’s 2026 meeting, shareholder proposals on AI board oversight, AI water use and climate disclosure went to a vote. None was approved, and they are likely to return.[6]

On the receiving side, E-23 is the clearest signal. It applies to federally regulated banks and insurers, and it names risks specific to AI, such as models that re-tune themselves and models that drift. Because vendor models are in scope, the duty passes down the supply chain to every tool those institutions buy.[1]

Firms outside OSFI’s reach still feel it. An asset manager serving a bank or a pension plan will meet these questions in due diligence, whatever its own regulator requires.

A firm that votes for AI oversight at a technology company, and has no inventory of its own AI, has a stewardship position it cannot defend.

Where to start

Governance does not need a large programme to begin. Five steps cover most of the ground, and the first three need no new tools.

  1. List every AI use. Include the AI inside purchased tools, since that is where most of it sits.
  2. Rank each use by consequence. A drafting aid and a model that feeds investment decisions need different levels of control.
  3. Name an owner for each material use. One person, with authority to pause it.
  4. Write vendor requirements into contracts. Source traceability, notice of model changes, accuracy evidence and footprint data per assessment.
  5. Adopt a framework and report against it. ISO/IEC 42001 or the NIST framework gives the structure. E-23 sets the bar for anyone serving Canadian banks and insurers.

The fourth step links governance to sustainability. Footprint and traceability become durable when they are contract terms that someone checks.

Governance is how the promise holds

AI for sustainability is a claim about purpose. Sustainable AI is evidence about footprint and trust. Governance is what keeps that evidence true after the launch, the audit or the sales meeting.

We think the firms that earn trust with AI will be the ones that can say who is accountable for it. The size of the model will matter less. Read how we handle this on our Trust page.

  1. [1]OSFI, Guideline E-23: Model Risk Management, effective 1 May 2027
  2. [2]McCarthy Tétrault, OSFI E-23 Guideline and its impact on financial institutions
  3. [3]European Commission, Navigating the AI Act
  4. [4]EU Artificial Intelligence Act, Digital Omnibus on AI, 2026
  5. [5]ISO, ISO/IEC TR 20226:2025, Environmental sustainability aspects of AI systems
  6. [6]Alphabet Inc., Form 8-K, 2026 annual meeting results
  7. [7]ISO/IEC 42001:2023, NIST AI Risk Management Framework 1.0, Quebec Law 25 and Canada’s Voluntary Code of Conduct on generative AI are cited by name.

Who is accountable for your AI?

Send us your methodology and five entities. We’ll run the assessment and show you the results.