97% of S&P 500 companies mention AI somewhere in their annual report, but only about 16% document an AI-specific cyber‑risk process, a Guardrail Technologies analysis found.
Guardrail Technologies' review of S&P 10‑K filings and the SEC Item 1C requirement
Guardrail Technologies examined all 503 Form 10‑K filings currently on file for S&P 500 companies against the SEC's Item 1C cybersecurity disclosure requirement. The firm's review applied multiple readings, including an independent human review, to determine whether companies merely discussed AI or also documented cyber‑risk processes tied to AI.
The numerical gap: conversation versus documented controls
The findings are stark and consistent. While 97% of companies mention AI somewhere in their annual report, only about 16% document any AI‑specific cyber‑risk process at all. Fewer than one in 20 filings describe a governed AI cyber‑risk program — defined by Guardrail as a named policy, program, or committee with a stated activity connected to cybersecurity controls. Across every reading the researchers applied, the distance between discussing AI and documenting a process for its cyber risk was at least 77 percentage points.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildGoverned AI cyber‑risk programs: a tiny minority
Guardrail singled out "governed" programs as a higher bar: a named policy, program, or committee with explicit activity tied to cybersecurity controls. By that measure, fewer than 5% of filings meet the threshold. The report frames this as more than a labeling issue: the governed‑program metric captures whether companies link governance structures to actionable cybersecurity controls in their public disclosures.
Sector patterns: where the gap narrows and where it remains wide
Guardrail also grouped companies by regulatory exposure. The 218 firms in the most heavily regulated sectors — financial services, health care, utilities, energy, and real estate — document an AI‑specific process only slightly more often than the rest of the index: 18% versus 15% on the more generous reading. Beneath that aggregate is a sharper split. Utilities, energy, and real estate filings are read as treating AI as a specific cybersecurity risk in about 70% of cases. Financial services and health care, even while discussing AI "just as heavily as everyone else in the index," are read as doing so in only 37% to 48% of filings.
What this means for security teams, regulators, and enterprises
- Security teams: The report notes, in promotional phrasing, that "Security teams have never had more visibility." Within the facts Guardrail reports, security practitioners will note a disconnect between widespread AI discussion and the comparatively sparse documentation of AI‑specific cyber‑risk processes and governed programs in public filings.
- Regulators (SEC and sector regulators): Guardrail's work was explicitly measured against the SEC's Item 1C cybersecurity disclosure requirement. The pattern — widespread mention of AI but limited evidence of governance tied to cybersecurity controls — presents a measurable discrepancy in disclosures that regulators and examiners can observe in 10‑K filings.
- Enterprises and procurement leaders: For the 218 companies in heavily regulated sectors, the report shows variation by sector in whether filings treat AI as a specific cybersecurity risk. Procurement and governance functions may read those sector splits as a signal that regulation and oversight do not produce uniform disclosure or governance across regulated industries.
Guardrail's analysis also referenced a training and sales note: an on‑demand claim that a "new decision layer" helps security teams move from detection to decision, and a live event listed for August 27, 2026 at 2 PM EDT titled "Explore how AI‑driven cloud security solutions can elevate your security domain." Those materials underscore the marketplace framing of the research, even as the core finding remains numerical and public‑record based.
The central fact stands unambiguous in Guardrail's review: nearly universal mention of AI in S&P 500 Form 10‑Ks, but only a small fraction of companies — roughly one in six — document AI‑specific cyber‑risk processes, and fewer than one in 20 tie that work to named governance with stated cybersecurity activity. That gap — at least 77 percentage points under the readings applied — is the clearest and most concrete takeaway of the report.




