Report by Guardrail Technologies
The AI Cyber-Disclosure Gap
Key Findings
Fewer than 5% of S&P 500 companies describe a governed AI cyber-risk process (a named policy, program, or committee with stated cybersecurity activity).
The gap between mentioning AI and documenting a cyber-risk process for AI in S&P 500 filings is at least 77 percentage points.
About 70% of utilities, energy, and real estate filings treat AI as a specific cybersecurity risk.
Financial services and health care filings treat AI as a specific cybersecurity risk in 37% to 48% of filings.
97% of S&P 500 companies mention AI somewhere in their annual reports.
About 16% of S&P 500 companies document an AI-specific cyber-risk process.
Companies in the financial services, health care, utilities, energy, and real estate sectors document an AI-specific process at 18%, compared with 15% for the rest of the S&P 500.