Report by Guardrail Technologies

The AI Cyber-Disclosure Gap

7 FINDINGSPublished Aug 26, 2026
View Original Report →

Key Findings

Fewer than 5% of S&P 500 companies describe a governed AI cyber-risk process (a named policy, program, or committee with stated cybersecurity activity).

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
AIGovernanceCyber RiskS&P 500

The gap between mentioning AI and documenting a cyber-risk process for AI in S&P 500 filings is at least 77 percentage points.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
AICorporate DisclosureCyber RiskS&P 500

About 70% of utilities, energy, and real estate filings treat AI as a specific cybersecurity risk.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
Critical InfrastructureAICyber Risk

Financial services and health care filings treat AI as a specific cybersecurity risk in 37% to 48% of filings.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
Financial ServicesHealth CareAICyber Risk

97% of S&P 500 companies mention AI somewhere in their annual reports.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
AIS&P 500Corporate Disclosure

About 16% of S&P 500 companies document an AI-specific cyber-risk process.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
AI Cyber RiskCorporate GovernanceS&P 500

Companies in the financial services, health care, utilities, energy, and real estate sectors document an AI-specific process at 18%, compared with 15% for the rest of the S&P 500.

Guardrail TechnologiesThe AI Cyber-Disclosure Gap·5d ago
Cyber RiskAICorporate GovernanceFinancial ServicesHealthcare