A Compass Is Not a Map

Investors have direction on AI governance. What they need are the questions that chart it. Forty-four percent of companies now disclose some form of AI strategy, but only 13% tie that strategy to a recognised governance framework. That distance between intention and infrastructure is the crux of the problem investors...

Table of Contents

Investors have direction on AI governance. What they need are the questions that chart it.

Forty-four percent of companies now disclose some form of AI strategy, but only 13% tie that strategy to a recognised governance framework. That distance between intention and infrastructure is the crux of the problem investors are trying to price.

Companies are embedding AI into products, operations and workforces faster than regulators, boards, or in many cases the companies themselves can build the governance to match. The question investors are asking is not whether a company has an AI policy, but whether it is deploying AI deliberately: does it know where AI is in use and why, has it thought through the consequences for workers, customers and resource use, and can it notice and correct when systems do not perform as intended. Investors tell us that most companies are still struggling to evidence this. The questions themselves are familiar ones about accountability, risk management and transparency; what is new is the pace at which companies need to answer them.

At a recent webinar convened by the PRI, investors heard the same problem from three vantage points: the Thomson Reuters Foundation on what disclosure across nearly 3,000 companies actually shows, Scottish Widows on how an asset owner builds AI governance into the stewardship of a diversified portfolio, and WBCSD on what companies themselves say is making thoughtful deployment hard in practice.

The polling of signatories on the call mapped closely onto what the corporate data shows, which is itself revealing: investors are early in this work for many of the same reasons companies are.

Sixty-eight percent of those polled ranked AI risk a high priority for their portfolios over the next three years. Yet fewer than half had any process for assessing AI-related risks, most of it at an early stage, and only around a quarter had one for managing them. Thirty-seven percent said they were actively looking for support to build a mitigation process.

The AICDI framework assesses governance and oversight, human capital, and safety and security, but across all three this gap persists between intent and execution. Governance provides the compass; implementation shows progress. While many companies disclose oversight, only 24% assess training data quality, 7% conduct human rights assessments, and just 12% provide structured AI training.

Investors like Scottish Widows, a large UK asset owner and UK Stewardship Code signatory, have started to engage with their investee companies on these key themes. In 2025, Scottish Widows published “Governing the Algorithm”, which has formed the basis of its dialogue with key investees.

Through its engagement with member companies, WBCSD is seeing a similar pattern. AI adoption is accelerating and companies are increasingly investing in responsible AI governance, with some sectors such as financial services in the lead. However, clarity and alignment are still missing on what good looks like with regards to safe, trustworthy and responsible use of AI across sectors and markets. Members are also looking for effective ways to achieve cross-functional oversight and operationalization of AI governance frameworks.

The AICDI data shows the same constraint from the outside: governance maturity tracks closely with market capitalisation, and while a small number of leading firms have built centralised responsible AI functions spanning HR, legal and compliance, that remains the exception. More often, responsible AI has been handed to existing ESG or sustainability teams without additional resource or expertise, leaving them to work out compliance and disclosure expectations as they go.

When signatories were asked where the most material AI risk would come from over the next three years, governance and accountability drew 40% and social risks 25%, with operational risk at 18%, systemic at 11% and environmental at 7%. That ranking reflects visibility more than materiality. Governance is where investors have established tools and a track record of engagement. The consequences of deployment for job quality and worker voice, for early-career pipelines, for water and energy demand pulled into sectors through procurement, and for labour markets at scale are less visible from outside a company and easier to defer.

The low prioritisation of environmental risk is also reflected in AICDI’s findings, where environmental impact assessments are among the rarest corporate disclosures. More broadly, the key challenge is the absence of a common AI framework, amid fragmented regulation and competing standards, prompting a proportionate approach.

The framework challenge is real, but not a reason to delay engagement. Effective AI stewardship relies on asking consistent questions over time, not deep technical expertise. AICDI’s investor checklist focuses on five areas: governance (strategy and accountability), controls (audits, traceability and impact assessments), workforce safeguards (reskilling and worker protections), data and vendors (privacy, security and third-party oversight), and ethics and sustainability (ethical authority and environmental impacts). These indicators support both investment decisions and  stewardship.

Where does your organisation sit against these five areas, and which would be most useful to raise with  portfolio companies first?

The Investor Checklist can be accessed here.