Business ethics news: flood risk, ESG ratings rules and a deferred AI deadline

Three regulatory moves in the past fortnight point in different directions. A UK regulator has started asking firms about physical climate risk rather than disclosure; the EU has filled in the detail of a new supervisory regime for ESG rating providers; and the bloc's headline AI compliance deadline has been pushed back by more than a year. Here is what changed and what it means for governance and compliance teams.
The FCA turns to climate adaptation, not just disclosure
On 4 August the Financial Conduct Authority published a new web page on climate adaptation and resilience, setting out how physical risks such as flooding are already affecting the property insurance and mortgage markets, and how the regulator intends to engage with firms on it. The shift is notable: most of the last decade of climate work in UK financial regulation has been about reporting, and this is about whether firms can absorb the risk.
The themes the FCA flags for mortgage lenders are practical ones. How flood risk feeds into lending decisions, property valuations and customer outcomes; and how the availability and affordability of property insurance could constrain future lending, with Flood Re due to expire in 2039 and the growing stock of homes built since 1 January 2009 falling outside the scheme entirely. For scale, the Environment Agency puts 6.3 million properties in England at risk of flooding, potentially 8 million by 2050, and the Climate Change Committee estimates annual flood damage at £3.3 billion, rising towards £4.5 billion by 2050.
The EU's ESG ratings rulebook fills in
Four European Commission delegated regulations were published on 28 and 30 July covering ESG rating providers: disclosure requirements, safeguards on separating rating activities from other business lines, enforcement procedures, and the fee structures supervisors may charge. They sit under the ESG Ratings Regulation, which has applied since 2 July 2026.
The practical consequence is that ESG ratings move from a lightly-governed information market into a supervised one. For any firm whose financing costs, index inclusion or procurement scoring depends on a third-party ESG rating, the separation and disclosure rules are the ones to read: they determine what you can find out about how you were scored, and who may sell you advice on improving it.
High-risk AI obligations slip to December 2027
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July and entered into force on 27 July, six days before the AI Act's original high-risk deadline. It defers the main compliance obligations for stand-alone high-risk AI systems listed in Annex III to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028.
Annex III is the list that touches ordinary corporate use: recruitment and worker management, creditworthiness assessment, certain life and health insurance underwriting, education and access to essential services. The transparency obligations under Article 50 were not moved and applied from 2 August 2026 as planned. The honest reading is a deferral, not a reprieve, and firms that paused their conformity work in July will have to restart it against a longer runway rather than a shorter list.
Source: White & Case
What it means for governance teams
The common thread is that supervisory attention is moving from what firms say to what they can withstand and to who supplies the numbers behind their claims. Physical climate risk, third-party ESG ratings and AI system inventories all sit outside the traditional disclosure cycle, and all three now have a named regulator attached. Boards that treat the AI deferral as breathing room rather than as a cancellation are reading it correctly.