Guardrail Technologies Releases Benchmark Report on S&P 500 AI Cybersecurity Risk Disclosure

Guardrail Technologies Releases New Benchmark Report Tracking How the S&P 500 Discloses AI Cybersecurity Risk
🕧 7 min

New research finds that 97 percent of S&P 500 companies discuss AI in their annual filings, while fewer than 1 in 5 document an AI-specific cyber-risk process and fewer than 1 in 20 describe a governed one

Guardrail Technologies,(opens in new tab) the leading provider of AI security and governance software for enterprises building with AI, released The AI Cyber-Disclosure Gap Report, the first study to measure how S&P 500 companies describe their use of artificial intelligence against how they document managing its cybersecurity risk. The first of its kind, the report is what Guardrail intends to make an ongoing benchmark, revisited on a recurring basis as filings update and disclosure practice evolves.

Also Read: IT Tech Pulse Exclusive Interview with Syed Ali Founder and Chief Executive Officer of EZO

Guardrail reviewed all 503 Form 10-K filings currently on file for S&P 500 companies against the SEC’s Item 1C cybersecurity disclosure requirement. The results were stark and consistent: 97 percent of companies mention AI somewhere in their annual report, but only about 16 percent document an AI-specific cyber-risk process at all, and fewer than 1 in 20 describe a governed one, meaning a named policy, program, or committee with a stated activity connected to cybersecurity controls.

Across every reading applied, including an independent human review, the distance between discussing AI and documenting a process for its cyber risk was at least 77 percentage points.

“Nearly every company in the S&P 500 says AI matters to their business, but almost none can prove how they’re keeping it under control,” said T.J. Marlin(opens in new tab), founder and CEO of Guardrail Technologies. “A policy written after a breach carries no weight with an investigator, and a control that only lived in someone’s memory is no control at all. This report shows how few companies could survive that kind of scrutiny today.”

Even the most heavily regulated sectors, financial services, health care, utilities, energy, and real estate, don’t close the gap. These 218 companies document an AI-specific process only slightly more often than the rest of the index: 18 percent versus 15 percent on the more generous reading. A sharper split appears within the group. Utilities, energy, and real estate, whose regulators oversee physical infrastructure, are read as treating AI as a specific cybersecurity risk in about 70 percent of filings. Financial services and health care, whose regulators oversee data, do so in only 37 to 48 percent, despite discussing AI just as heavily as everyone else in the index.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

Guardrail plans to repeat this analysis on a recurring basis to track whether disclosure practice moves as the regulatory calendar advances and to give boards, insurers and investors a consistent benchmark rather than a one-time snapshot.

“Every board, public or private, should treat this AI security disclosure gap as urgent,” Marlin added. “If you’re on a public company board, look at what you’re already saying out loud about AI and make sure a documented, governed process backs it up. The alternative won’t hold up.”

A Board Diagnostic for any public company

Alongside the report, Guardrail is launching a Board Diagnostic for any publicly traded company. Using the same framework applied to all 503 filings in the study, Guardrail reviews a company’s most recent cybersecurity disclosure and returns one of three verdicts: Green for a documented, governed AI risk process, Amber for a partial one, or Red for none. It’s the same signal Guardrail already uses in AI Traffic Light™ to flag code and agent behavior, now applied to the disclosure itself. The verdict comes with an executive insights report showing exactly where the disclosure falls short, what a stronger one would say, and how it compares to peers, ready to bring straight to the audit committee.

Guardrail has identified the six critical questions every board should be able to answer about its AI lifecycle; the Board Diagnostic is built to guide the board to the deeper questions related to AI and support in identifying what needs to be addressed.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • Business Wire has been synonymous with well-known press release distribution for more than half a century. Owned by Berkshire Hathaway, it combines regulatory compliance expertise with a powerful media network, helping enterprises large and small share news that influences markets and decision-makers alike.

Recommended Reads :