Those executives weren't describing fraud. They were describing something more structural: a gap between what marketing, investor relations, and sustainability communications teams said publicly, and what the internal data systems could actually support. The claims were made in good faith. The data architecture to back them up hadn't been built.
That gap is now the primary focus of an expanding enforcement landscape. In Europe, the Empowering Consumers for the Green Transition Directive takes full effect in September 2026. The European Commission's guidance makes clear that claims published on corporate websites — including those not specifically aimed at consumers — can be subject to national enforcement scrutiny if they're capable of influencing buying decisions.
In the UK, the Competition and Markets Authority published new supply chain liability guidance in January 2026. In the U.S., state attorneys general on both ends of the political spectrum are actively challenging environmental claims — some for being unsubstantiated, others for being implausible.
Environmental data inside most large organizations was built to serve internal decisions: supplier selection, operational planning, target-setting, internal reporting. It relies on sector averages, spend-based proxies, and modeled projections. That data is fit for those purposes. It wasn't designed to be deposed.
When enforcement agencies or plaintiff attorneys examine environmental claims, they're looking at a specific question: can the company produce a documented, traceable evidentiary trail that connects the public claim to an underlying data set that would survive expert scrutiny? For most large companies, the answer is no — not because the claims were invented, but because the data governance architecture that would support them was never built.
The most common pattern in enforcement actions to date: a company publishes a claim about carbon neutrality, net-zero progress, or sustainable sourcing. A regulator or plaintiff counsel requests the underlying data. The company produces the data it has — spend-based estimates, sector averages, third-party certifications of varying quality. The gap between that data and the specificity of the claim becomes the center of the case. Not the claim itself, but the evidentiary distance between the claim and what can be verified.
The reason this issue belongs at the C-suite level is that it requires cross-functional authority to fix. The sustainability team can identify the gap. Legal can assess the exposure. But closing the gap requires decisions that cross organizational lines: communications teams need to modify claims in ways that sustainability teams don't control; data systems need investment that IT and finance jointly own; supplier engagement standards need to be embedded in procurement in ways that change cost and relationship dynamics.
No single function can close the architecture gap without executive mandate. And without executive mandate, the default is incremental improvement — annual sustainability report revisions, modest data system upgrades, legal review of the most visible claims — that doesn't move fast enough to match the enforcement timeline.
The practical place to start is a cross-functional inventory of what's actually live: every environmental claim in public-facing materials — marketing, investor presentations, product labels, website content — that could be subject to the EU ECGT Directive or parallel state-level regulations. Not a theoretical list. The actual claims, pulled from the actual materials.
For each of those claims, someone needs to ask a blunt question: what data exists internally to substantiate it, and has that data been independently verified? Not 'do we have a sustainability report that talks about this' — but 'could we produce a traceable evidentiary trail if a regulator or plaintiff attorney asked for one?'
Companies that have run this kind of review proactively — and some have, either because their legal team got ahead of it or because they've been through an enforcement situation before — tend to find the same pattern: most claims are defensible with modest documentation improvements. A smaller number need more significant revision. And a few need to come down entirely, because the data that was supposed to support them was never there.
Knowing which category you're in — before enforcement asks — is the decision that's available right now. The companies most exposed going into the second half of this year aren't necessarily the ones that made the boldest claims. They're the ones that haven't looked.