Executive summary
Nearly every large public company now describes artificial intelligence (AI) as central to its business. Far fewer describe how they manage the cybersecurity risk that AI introduces. This report measures that gap across the S&P 500, with particular attention to the sectors under the heaviest regulation, and finds the gap is wide, consistent, and largely unaddressed even where oversight is most intense.
Reviewing all 503 current S&P 500 annual reports (Form 10-K) against the Item 1C cybersecurity disclosure requirements of the Securities and Exchange Commission (SEC), two findings stand out. First, AI is discussed almost universally: about 97 percent of filings mention it. Second, formal disclosure of a process for managing AI cyber risk, the substance Item 1C(b)(1) was built to elicit, is rare. On the most generous review, only about 1 in 5 companies document such a process across the index, and no more than about 1 in 5 does so even in the most regulated sectors. Companies discuss AI far more than they document managing its risk, a gap of at least 77 percentage points that holds under every reading we applied, and an independent human review of a random sample reached the same conclusion. The disclosure is thinnest in data-regulated sectors such as banking and health care, where AI is discussed heavily but rarely pinned down as a specific, managed cyber risk.
We deliberately report the most company-favorable interpretation of the formal-disclosure figure, so the finding understates rather than overstates the shortfall.
What your filing says about AI, and what it doesn’t
Consider your company’s most recent annual report, and the cybersecurity disclosure it contains under Item 1C. Two things are almost certainly true. You mention artificial intelligence somewhere in the filing. And you probably do not describe a specific process for managing the cyber risk that AI creates. Across the most heavily regulated parts of the S&P 500, that pattern is close to universal.
Roughly 97 percent discuss AI in their annual report. It appears in strategy, in operations, and in the description of the business itself. When the same filings are read for a documented process to identify and manage AI-related cyber risk, the number collapses.
The gap: AI is everywhere, its governance almost nowhere
Among the 218 companies in the five most-regulated sectors (financial services, health care, utilities, energy, and real estate), roughly 97 percent discuss AI in their annual report. It appears in strategy, in operations, and in the description of the business itself. When the same filings are read for a documented process to identify and manage AI-related cyber risk, the number collapses. On the most generous reading, no more than about 1 in 5 companies document such a process.
The contrast is stark, and an independent human review of a random sample confirmed it.

The gap itself is not a modeling artifact: an independent human reviewer, committing a call for each filing before the corresponding automated label was revealed, found the same near-universal discussion (about 98 percent) and the same scarce documentation (about 20 percent). And the figure shown for documentation is the most generous independent reading available; the stricter read places it lower still. Whatever appears in your Item 1C is the record your board, your regulator, your insurer, and, after any incident, a plaintiff’s counsel will read. For most regulated companies today, that record shows AI nearly everywhere and a managed-cyber-risk process almost nowhere.
The 1 in 5 figure is the most generous count available from the readings this report relies on, and it is worth being precise about what such counts credit. When two independent readers must both find a documented process, the figure falls to about 1 in 10 across the index. Reading what those filings actually say narrows it further: most describe AI as an emerging threat or attach a single control to it, most often employee training, and no more than about 4 in 100 companies describe AI risk as governed, meaning a named AI policy, standard, or committee with a stated activity connected to cybersecurity controls. None of the filings examined at that level discloses an independent assessment of AI-specific controls. The generous reading was chosen so the finding could not be accused of overstatement. Read closely, it overstates how much is there.
The gap holds across every regulated sector
Broken out by sector, and grouped by the kind of asset each industry’s regulators protect, physical operational technology (OT) versus sensitive data, the gap appears in all five sectors.

In every sector, the taller grey bar (companies discussing AI) dwarfs the shorter blue bar (companies documenting a process). The rate of formal documentation varies only modestly across the five sectors and does not separate cleanly by regulation type. What does differ by regulation type is not how often companies document a process, but how specific the underlying cyber-risk disclosure is when it appears. It matters most for the data-regulated sectors, banking and health care, where AI is discussed heavily but, on close reading, less often characterized as a specific, managed cyber risk, so companies there may carry more exposure than the documentation counts alone suggest.
The market has largely completed the easy half of disclosure, saying that AI matters. The half the rule actually asks for, showing how its risks are governed, is for now mostly blank.
Regulation has not closed the gap
It would be reasonable to expect the most heavily supervised companies in the market to lead here. They do not. Across these five sectors, formal AI cyber-risk documentation runs only marginally ahead of the rest of the index. The regulatory expectation to demonstrate how a material risk is managed is, for roughly 4 filings in 5, still unmet, even where oversight is most intense.
The conclusion for anyone inside these companies is straightforward. The market has largely completed the easy half of disclosure, saying that AI matters. The half the rule actually asks for, showing how its risks are governed, is for now mostly blank. That blank space is both the exposure and, for the companies that move first, the opportunity to set the standard.
About the Authors
T.J. Marlin
T.J. Marlin is the CEO of Guardrail Technologies, where he guides the company in setting the standard for responsible AI innovation. A globally recognized leader in cybersecurity, data privacy, and AI, he previously served as EY’s Global Forensic Technology & Innovation Leader. T.J.’s mission is to empower organizations to scale with confidence by harnessing the power of AI without sacrificing privacy, security, or control.
Michael McCarthy
Michael McCarthy, PhD, is a tenured Associate Professor of Data Science at Utica University and Vice President of AI and Data Science at Guardrail Technologies. A researcher and practitioner, he brings experience in healthcare analytics, major technology companies, and organizational innovation. His work focuses on responsible AI, bias in data modeling, and helping leaders use advanced analytics with greater confidence, transparency, and control.
Contributors
Alejandra Torrico, Research Assistant
Alejandra Torrico is a Computer Information Systems student at James Madison University currently interning with Guardrail Technologies, where she supports research, AI output validation, and applied technology projects. She contributed to this research by reviewing and validating AI-generated outputs for accuracy, consistency, and alignment with source findings.