SEC AI Disclosure 2026: What Public Companies Must Report
With the SEC sharpening its focus on AI risks for 2026 filings, public companies must proactively address AI governance and risk disclosures—even in the absence of a formal rule—to meet regulatory expectations and sustain investor trust.
Bespoke Mentis · Governed by AC11 Framework · Reviewed before publication
In April 2024, the U.S. Securities and Exchange Commission (SEC) publicly signaled that public companies should begin addressing artificial intelligence (AI) risks in their 2026 filings, despite the absence of a formal AI disclosure rule[1]. This directive, highlighted by the Harvard Law School Forum on Corporate Governance, marks a pivotal shift in the SEC’s regulatory posture: AI risk reporting is now an explicit expectation, not a theoretical future requirement. For CTOs, CISOs, and compliance officers at publicly traded companies, this means that AI governance and transparency must become integral to both risk management and investor communications—well before any formal rulemaking is finalized.
The SEC’s Evolving Expectations: From Guidance to De Facto Mandate
The SEC’s approach to AI disclosure is rooted in its broader mandate to protect investors and ensure market integrity. While the Commission has not yet promulgated a standalone AI disclosure rule, it has repeatedly emphasized that existing disclosure obligations under Regulation S-K—particularly Items 105 (Risk Factors) and 303 (Management’s Discussion and Analysis, or MD&A)—require companies to report material risks, trends, and uncertainties, regardless of whether those risks stem from traditional sources or emerging technologies like AI[1][2]. In recent public statements and enforcement actions, SEC officials have drawn parallels between the current AI moment and the early days of cybersecurity risk reporting, where companies were expected to disclose material threats even before prescriptive rules were in place.
This regulatory posture is not merely theoretical. In 2023 and 2024, the SEC issued comment letters to several large-cap technology and financial firms, questioning the sufficiency of their AI-related disclosures and seeking greater detail on how AI systems could impact financial performance, operational resilience, and reputational standing[1]. The SEC’s Division of Corporation Finance has also updated its interpretive guidance to clarify that companies must consider whether their use of AI introduces new or heightened risks—such as algorithmic bias, model drift, or systemic vulnerabilities—that are reasonably likely to have a material effect on the business. These developments signal that, for 2026 filings, the SEC expects companies to move beyond generic statements about “innovation” or “digital transformation” and instead provide granular, decision-useful information about their AI governance frameworks, risk controls, and incident response protocols.
Materiality, Risk Factors, and the New AI Disclosure Paradigm
For public companies, the threshold question is not whether to disclose AI risks, but how to determine which risks are material and how to communicate them effectively in SEC filings. Under the Supreme Court’s TSC Industries v. Northway standard, information is material if there is a substantial likelihood that a reasonable investor would consider it important in making an investment decision. In the context of AI, this means companies must assess and disclose risks that could affect financial results, operational continuity, legal compliance, or corporate reputation.
The SEC’s evolving guidance suggests that AI-related disclosures will become a critical component of the Risk Factors and MD&A sections of annual reports (Form 10-K) and registration statements (Form S-1)[1][2]. Specifically, companies are expected to address:
- The scope and scale of AI deployment across business units, including mission-critical applications (e.g., automated underwriting, clinical decision support, trading algorithms).
- The governance structures in place to oversee AI development, testing, and deployment, including board-level oversight and cross-functional risk committees.
- The methodologies used to identify, assess, and mitigate AI-specific risks, such as model bias, data quality issues, adversarial attacks, and explainability gaps.
- The potential for regulatory, legal, or ethical challenges arising from AI use, including compliance with anti-discrimination laws, data privacy statutes, and sector-specific regulations.
- The impact of AI incidents—such as model failures, data breaches, or regulatory investigations—on financial results, customer trust, and business operations.
Deloitte’s 2024 analysis underscores that boilerplate disclosures will not suffice[2]. The SEC expects tailored, company-specific narratives that reflect the unique risk profile of each organization’s AI portfolio. For example, a health system deploying AI for diagnostic imaging must address not only technical reliability but also patient safety, liability exposure, and compliance with FDA guidance on software as a medical device. A financial institution using AI for credit scoring must discuss potential disparate impact, fair lending compliance, and the safeguards in place to detect and remediate algorithmic bias.
AI Governance, Controls, and the Audit Trail Imperative
Effective AI risk reporting is inseparable from robust AI governance. The SEC’s scrutiny of AI disclosures is fundamentally an inquiry into whether companies have established credible, auditable processes for managing the lifecycle of AI systems—from design and data acquisition to deployment and ongoing monitoring[2]. This expectation is consistent with the SEC’s broader emphasis on internal controls over financial reporting (ICFR) and disclosure controls and procedures (DCPs), which require management to certify that material risks are identified, assessed, and communicated to investors.
For CTOs and CISOs, this means that AI governance cannot be an afterthought or a siloed function. Instead, it must be embedded in enterprise risk management (ERM) frameworks, with clear lines of accountability, escalation protocols, and documentation standards. Key elements of a defensible AI governance program include:
- Inventory and mapping of all AI systems in production, with risk classification based on potential impact and regulatory exposure.
- Formalized model validation and testing procedures, including independent review of training data, algorithmic fairness, and robustness against adversarial inputs.
- Continuous monitoring for model drift, performance degradation, and emerging vulnerabilities, supported by automated logging and alerting mechanisms.
- Incident response playbooks for AI-related failures or breaches, including protocols for root cause analysis, stakeholder notification, and remediation.
- Board and executive oversight, with regular reporting on AI risk metrics, audit findings, and compliance gaps.
The SEC has also indicated that companies should maintain an audit trail of key decisions related to AI system design, deployment, and risk mitigation[1]. This includes documenting the rationale for model selection, the results of bias and fairness testing, and the outcomes of internal or third-party audits. Such documentation not only supports accurate disclosure but also provides a defensible record in the event of regulatory inquiries or shareholder litigation.
Operational Implications: What CTOs and CISOs Must Do in 2024–2025
With the SEC’s expectations for AI risk reporting now explicit, CTOs and CISOs at public companies face a compressed timeline to operationalize AI governance and disclosure practices ahead of the 2026 filing cycle. The absence of a formal rule does not diminish the urgency; if anything, it increases the risk of regulatory scrutiny for companies that lag behind emerging best practices.
First, companies must conduct a comprehensive inventory of all AI systems in use, mapping each to its business function, risk profile, and regulatory touchpoints. This inventory should be dynamic, updated as new models are developed or acquired, and integrated into the broader ERM process. Second, organizations should establish or enhance cross-functional AI risk committees, bringing together technical, legal, compliance, and business leaders to oversee governance, set risk appetite, and approve high-impact deployments. Third, CTOs and CISOs must ensure that model validation, fairness testing, and security assessments are standardized, repeatable, and documented, with clear evidence trails for all material decisions. Fourth, disclosure teams should begin drafting tailored AI risk factors and MD&A narratives, working closely with legal counsel to ensure accuracy, completeness, and alignment with SEC guidance. These disclosures should be reviewed and updated at least quarterly, reflecting new developments in AI deployment, incident response, or regulatory landscape.
Finally, companies should invest in training and awareness programs for both technical and non-technical staff, emphasizing the importance of AI governance, ethical use, and regulatory compliance. This cultural shift is essential to sustaining investor trust and avoiding the reputational damage that can result from AI-related incidents or disclosure failures.
AI systems analyst and governance specialist at Bespoke Mentis. Covers enterprise AI compliance, regulated industry strategy, and the operational decisions that determine whether AI deployments succeed or fail audit.
Ready to build with us?
Bespoke Mentis builds governance-first AI infrastructure for regulated industries. If this article raised questions about your architecture, compliance posture, or AI strategy, let's talk.
