Skip to main content
Bespoke Mentis

AI Disclosure: This news brief was drafted with AI assistance by Mentis Intelligence and reviewed by Zain Aamer, CEO of Bespoke Mentis, before publication. All regulatory and factual claims reference publicly available sources cited below.

News BriefCompliance 3 min read September 25, 2026 at 03:01 PM UTC Updated Sep 25, 2026

SEC Mandates AI Risk Disclosures, Tightens Oversight for Public Companies

SEC’s new rules require public companies to disclose material AI-related risks and incidents, targeting transparency and curbing misleading AI claims.

Zain Aamer

CEO, Bespoke Mentis · AI-assisted + reviewed before publication · AC11 Governed

Key Takeaway

SEC’s new rules require public companies to disclose material AI-related risks and incidents, targeting transparency and curbing misleading AI claims.

Topics: SEC · AI risk disclosure · public companies

The SEC has adopted new rules obligating public companies to disclose significant AI-related risks and incidents, aiming to increase transparency and prevent misleading statements about AI capabilities SEC Official Website Financial Times. This move signals heightened regulatory scrutiny on AI governance and risk management for all publicly traded firms.

On June 27, 2024, the U.S. Securities and Exchange Commission (SEC) finalized regulations requiring all public companies to promptly disclose material risks, incidents, and limitations associated with their use of artificial intelligence systems SEC Official Website. The rules specifically target misleading or exaggerated claims about AI capabilities, mandating that companies provide investors with accurate, timely information about how AI is used in their operations and the associated risks. The new disclosure requirements take effect for fiscal years ending after December 15, 2024, affecting all SEC-registered entities Financial Times.

The SEC’s action comes amid mounting concerns about the ethical, operational, and reputational risks posed by AI in regulated industries. The new rules align with the SEC’s broader mandate to protect investors and maintain fair, orderly markets by ensuring that companies do not misrepresent the safety, reliability, or impact of AI systems in their disclosures SEC Official Website. This regulatory update dovetails with global trends, such as the EU AI Act’s transparency requirements and the NIST AI Risk Management Framework’s emphasis on incident reporting and risk communication NIST AI RMF. For enterprises in sectors like healthcare, finance, and critical infrastructure, the rules reinforce the need for robust AI governance and compliance mechanisms.

CTOs, CISOs, and Compliance Officers at public companies should immediately review their AI risk management and incident reporting protocols to ensure compliance with the new SEC requirements. This includes establishing clear processes for identifying and documenting material AI-related risks, training teams on the new disclosure standards, and updating public reporting templates. Over the next 30-90 days, organizations should conduct internal audits of AI deployments, assess the adequacy of their risk disclosures, and prepare for increased scrutiny from both regulators and investors Financial Times.

What This Means for Enterprise AI

Public companies must now treat AI-related risks and incidents as material events subject to SEC disclosure, similar to cybersecurity breaches or financial irregularities. This raises the bar for internal documentation, risk assessment, and board-level oversight of AI systems, especially in regulated sectors like healthcare (HIPAA), finance (SEC, OCC), and critical infrastructure SEC Official Website. Failure to comply could trigger enforcement actions, investor lawsuits, or reputational damage.

Operationally, enterprises should map all AI use cases, identify potential sources of material risk (e.g., bias, safety failures, data privacy violations), and implement incident response plans that meet SEC standards. Compliance teams must coordinate with IT and data science groups to ensure that all AI-related incidents—such as model failures, unexpected outputs, or misuse—are promptly escalated and disclosed as required NIST AI RMF. Companies should also review marketing and investor communications to eliminate any unsubstantiated claims about AI capabilities, as the SEC will be monitoring for misleading statements.

Finally, this rule change underscores the need for ongoing AI governance maturity. Enterprises should benchmark their practices against frameworks like the NIST AI RMF and prepare for similar requirements from other regulators, including the EU and sector-specific agencies. Early compliance will not only reduce regulatory risk but also build trust with investors and customers.

Share X / Twitter LinkedIn
ZA
Zain AamerMentis Intelligence

AI systems analyst and governance specialist at Bespoke Mentis. Covers enterprise AI compliance, regulated industry strategy, and the operational decisions that determine whether AI deployments succeed or fail audit.

View all articles· AC11 Governed · Reviewed before publication
Stay Informed on AI Governance

This development affects your AI strategy.

Bespoke Mentis tracks every regulatory shift, enforcement action, and governance development so you can act before your competitors. Talk to us about what this means for your architecture.