Report Finds AI Security Fails to Match AI Usage

A report by Guardrail Technologies analyzed how S&P 500 companies document their AI usage alongside their AI cybersecurity measures.
Researchers reviewed all 503 Form 10-K filings currently on file for S&P 500 companies against the SEC's Item 1C cybersecurity disclosure requirement. The results were stark and consistent: 97% of companies mention AI somewhere in their annual report, but only about 16% document an AI-specific cyber-risk process at all, and fewer than one in 20 describe a governed one, meaning a named policy, program, or committee with a stated activity connected to cybersecurity controls.
Across every reading applied, including an independent human review, the distance between discussing AI and documenting a process for its cyber risk was at least 77 percentage points.
Even the most heavily regulated sectors, financial services, health care, utilities, energy, and real estate, don't close the gap. These 218 companies document an AI-specific process only slightly more often than the rest of the index: 18% versus 15% on the more generous reading. A sharper split appears within the group. Utilities, energy, and real estate, whose regulators oversee physical infrastructure, are read as treating AI as a specific cybersecurity risk in about 70% of filings. Financial services and health care, whose regulators oversee data, do so in only 37 to 48%, despite discussing AI just as heavily as everyone else in the index.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!




.webp?height=200&t=1782826087&width=200)


