โ†
AI Agent Builders & Citizen Developers
Visionary ยท M15 ยท lesson 15 of 24 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
SEC AI Risk Disclosure and the 10-K AI Risk Factor
๐Ÿ“–
now learning

SEC AI Risk Disclosure and the 10-K AI Risk Factor

15 min

In 2025, the SEC's Division of Corporation Finance started treating one paragraph of generic "we use AI" boilerplate in a 10-K as a material omission. In 2026, they started naming names. If your agent program is real enough to matter to operations, it is real enough to disclose. The question for the strategist is not whether to write the AI risk factor โ€” it is whether yours will survive scrutiny.

The Comment Letter That Changed the Pattern

The first widely-discussed SEC comment letter on an AI risk factor went out in late spring 2025 to a mid-cap SaaS company. The 10-K had a single paragraph in Item 1A acknowledging "the use of artificial intelligence systems in certain products and operations" and noting "competitive risks from rapidly evolving AI technology." The comment letter, posted to EDGAR three months later, asked the registrant to:

  • Identify the specific products and operations in which AI is used.
  • Describe the material risks of those uses, including risks of inaccurate outputs, data leakage, and third-party model risk.
  • Describe the controls and oversight mechanisms in place.
  • Discuss any incidents in the prior fiscal year and their material impact.
  • Identify the foundation model vendors and the company's degree of dependence.

By the end of 2025, similar comment letters had gone to at least 30 registrants across software, financial services, healthcare, and consumer. The Q1 2026 10-K filings showed a marked shift: median AI risk factor length went from 180 words (2024) to roughly 920 words (Q1 2026 filings). Several registrants now include sub-headings, named vendors, named risks, and named controls.

The 2025-26 SEC pattern is to treat vague "we use AI" boilerplate as a material omission. The disclosure obligation is not new โ€” it flows from Reg S-K Item 105 and the Caremark line of duty-to-monitor cases. What is new is enforcement attention. A specific, calibrated AI risk factor is now table stakes.

The Materiality Test, As Applied to Agents

SEC materiality, as articulated in TSC v. Northway and Basic v. Levinson, is whether a reasonable investor would consider the omitted fact important in making an investment decision, or whether the omitted fact would significantly alter the total mix of information. For agent programs, four factors collectively push past the materiality threshold:

1. Scope of agent program

If agents touch revenue-impacting workflows (sales, support, marketing), cost-impacting workflows (operations, supply chain), or risk-impacting workflows (credit, fraud, compliance), the program is operationally material. The threshold isn't dollar-precise; the question is whether a serious investor would want to know.

2. Concentration of failure mode

If an agent failure could meaningfully impair revenue (CS agent misroutes 10% of escalations), increase cost (back-office agent triples processing costs through retry loops), or trigger regulatory action (credit agent produces disparate-impact outcomes), the failure mode is itself a material risk.

3. Vendor concentration

Heavy dependence on a single foundation model provider, or on a single vertical agent vendor, creates concentration risk that is material to operations and possibly to going-concern analysis. SEC has been particularly attentive to disclosures of multi-quarter outages or change-in-control of critical vendors.

4. Regulatory exposure

Annex III high-risk classification under EU AI Act, NYC Local Law 144 audit posture, Colorado SB 24-205 enforcement, BIPA exposure, ECOA-Reg-B AI-credit attention โ€” each can rise to materiality on its own. Aggregate exposure across jurisdictions is typically material for any multi-national operator.

The Anatomy of a Defensible AI Risk Factor

The pattern that has held up under SEC review in 2026 has six sections, roughly 800-1,500 words. Below is the structure, with annotated language patterns.

Section 1: Scope of AI program

Begin by stating what AI does in the business. Avoid the word "leverage." Be specific.

"We deploy AI agents โ€” autonomous systems that combine large language models with tool integrations to perform multi-step tasks โ€” across customer success (drafting responses, summarizing accounts), sales operations (lead enrichment, meeting preparation), and back-office finance (invoice categorization, expense triage). As of fiscal year end, AI agents touch approximately 38% of customer interactions and 12% of internal operational workflows. We do not currently deploy AI agents in product underwriting, hiring decisions, or other contexts that would constitute high-risk uses under the EU AI Act."

Section 2: Material risks

Name the risks. The three SEC has named in comment letters are: hallucination-driven misstatements, indirect-prompt-injection data leakage, and third-party agent vendor concentration. There are usually two-three more specific to the company.

"Our use of AI agents creates risks including: (i) inaccurate outputs ('hallucinations') that could mislead customers or internal users, including in regulatory filings or financial disclosures if not caught; (ii) data leakage through indirect prompt injection or supply-chain compromise of upstream model providers; (iii) concentration risk on foundation model providers, including [Anthropic, OpenAI, Google] which collectively account for substantially all of our agent inference; (iv) third-party agent platform concentration; (v) regulatory exposure under the EU AI Act (effective August 2, 2026 for deployers), Colorado SB 24-205 (effective February 1, 2026), NYC Local Law 144 (active enforcement since 2025), and analogous state laws; (vi) potential intellectual property claims arising from agent outputs."

Section 3: Mitigations

Describe the controls. The SEC's 2026 comment letters have rejected boilerplate. Name the program.

"We maintain controls including: (i) an AI governance committee, chaired by the Chief Risk Officer, that approves new agent use cases and reviews material changes quarterly; (ii) an eval-set program that scores agent quality on representative inputs and gates deployment on regressions; (iii) human-in-the-loop approval for irreversible actions; (iv) signed contractual commitments from foundation model vendors regarding data use, residency, and model-change notification; (v) decision logging compliant with EU AI Act Article 26 retention requirements; (vi) Fundamental Rights Impact Assessments for any deployment classified as high-risk under EU AI Act Annex III; (vii) annual independent bias audits for any deployment that qualifies as an Automated Employment Decision Tool under NYC Local Law 144."

Section 4: Incidents and material impact

If there have been material incidents in the fiscal year, disclose them. If there have not, say so.

"During the fiscal year, we experienced [N] AI agent incidents that we determined to be material under our governance framework. [Brief description and resolution.] We did not determine any AI agent incident to result in material loss of customer data, financial loss above [threshold], or regulatory action."

Section 5: Forward-looking risk environment

The regulatory environment is moving. Acknowledge that.

"The regulatory environment for AI agents is evolving rapidly. EU AI Act Article 26 deployer obligations bind August 2, 2026, creating documentation, monitoring, and oversight requirements that we are implementing across our European operations. Colorado SB 24-205, effective February 1, 2026, imposes impact-assessment and notice obligations for consequential-decision systems. Several other US states have introduced or are considering analogous legislation. The cost of compliance, the risk of enforcement action, and the operational impact of new requirements may be material to our results of operations or financial condition in future periods."

Section 6: Concentration disclosure (if applicable)

If a single vendor exceeds 25% of agent workload or is mission-critical to operations, name the concentration.

"We depend on [Anthropic] for [approximately X%] of our agent inference workload through [Claude] models. An extended outage, material change in terms, or cessation of service by this provider could materially impair our operations until alternative providers are integrated, a process we estimate would take [N] weeks."

The Audit Committee Briefing Template

The AI risk factor is the public artifact. The audit-committee briefing is the private artifact that produces it. The pattern: one document, delivered quarterly to the audit committee (or risk committee in companies that have one), whose language flows directly into the 10-K, the proxy disclosure, and the board minutes. Same words. Same metrics. Same incident summaries.

The 10-page audit committee briefing structure

  1. Page 1: Executive summary โ€” one paragraph on agent program scope, key metrics, material developments since last briefing.
  2. Page 2: Program scope โ€” agent inventory by business function, use-case classification, regulatory risk tier per use case.
  3. Page 3: Key metrics โ€” eval scores by agent, p95 latency, cost per interaction, deflection/automation rate, error rate.
  4. Page 4: Incidents โ€” list of incidents in the period, severity, root cause, remediation status.
  5. Page 5: Vendor scorecard summary โ€” top 5 vendors, SLA performance, sub-processor changes, concentration metrics.
  6. Page 6: Regulatory developments โ€” EU AI Act implementation status, state-law tracking, FRIA updates, audit results.
  7. Page 7: New deployments and material changes โ€” what changed in the period, approval status, risk classification.
  8. Page 8: Outlook and forward-looking risks โ€” pending regulation, planned program changes, identified risks.
  9. Page 9: Disclosure language โ€” the recommended risk-factor language for the next 10-K filing, marked-up against current.
  10. Page 10: Action items and recommendations โ€” committee decisions requested, budget asks, governance changes.

The flow-through discipline

The disclosure language drafted on Page 9 of the audit-committee briefing becomes the AI risk factor in the next 10-K. The same language appears, summarized, in the proxy "AI Risk Oversight" section. The board minutes record the committee's review and approval. Three identical narratives, three distinct documents, one source. When a securities-class plaintiff or an SEC examiner asks "what did the board know and when did they know it?" the answer is documented continuously.

The strategist's most powerful artifact is the audit-committee briefing that turns into the 10-K disclosure. Same language, same metrics, same incident summaries. Three documents, one source. When the question comes, the answer is documented continuously.

The Three Disclosure Failure Modes

The "We Use AI" omission

Pattern: a single paragraph acknowledging AI generally, no specific use cases, no vendor names, no material risks identified. Failure: SEC has now consistently treated this as material omission per Reg S-K Item 105. Remediation: replace with the 6-section pattern above.

The "Cut-and-paste from competitor" risk factor

Pattern: registrant copies a similar company's risk factor word-for-word. Failure: the SEC examiners do read multiple filings, and identical language combined with materially different operational profile invites scrutiny. Remediation: tailor to actual program scope, vendors, and use cases.

The "Disclosure but no controls" gap

Pattern: the risk factor describes mitigations that don't exist (no governance committee, no eval program, no decision logs). Failure: when a plaintiff or examiner asks for evidence of the controls, the gap becomes the case. Remediation: build the controls before describing them, and ensure the audit-committee briefing reflects ground truth.

Adjacent Disclosure Obligations

Form 8-K material event disclosure

Item 8.01 (other events) and Item 1.05 (cybersecurity incidents) intersect with AI agent failures. The 2023 SEC cybersecurity rules require disclosure of material cybersecurity incidents within four business days of materiality determination. An AI agent incident that exposes customer data, enables unauthorized actions, or causes financial loss above a materiality threshold may trigger this clock. The audit committee briefing template should include a "is this 8-K reportable?" decision step for each incident.

Proxy statement AI Oversight disclosure

Many companies now include a board oversight section on AI in the proxy. The disclosure mirrors the risk factor in spirit but emphasizes governance structure: how the board oversees, which committee owns, what the chartering documents say, what the cadence of review is. The audit-committee briefing structure naturally generates this content.

Earnings call references and Reg FD

The CEO mentions "AI agents" on an earnings call. The investor relations team must apply Reg FD: any material non-public information shared on a call must be simultaneously disclosed. If the CEO discloses agent metrics, vendor relationships, or material developments, the same information must be available to all investors. Pre-script earnings call AI mentions with the IR and legal team.

S-1 and securities offering disclosures

For IPO candidates and follow-on offerings, the AI risk factor in the S-1 is held to higher scrutiny than annual filings, because underwriters and underwriters' counsel review independently. The 2025-26 pattern: pre-IPO companies are advised to build the risk factor in advance of filing and stress-test with underwriter counsel.

The Three-Question Board Test

The audit committee's defensible posture is built on the ability to answer three questions at any board meeting:

  1. What does our AI agent program do, materially? Scope, business functions, key metrics. The committee should be able to recite the scope without notes.
  2. What could go materially wrong? Top three risks, top three incidents, remediation status.
  3. How do we know we are in control? Eval scores, vendor scorecard, regulatory posture, governance cadence.

If the committee cannot answer in two minutes per question, the program is under-governed and the disclosure is under-supported.

The Rule of Three for 2026 Strategists

Three artifacts. Three audiences. Same source.

  • 10-K Item 1A risk factor โ€” for investors and the public.
  • Proxy AI Oversight section โ€” for shareholders and proxy advisors.
  • Audit committee briefing โ€” for the board and the internal governance record.

All three should say the same thing in different formats. The strategist's deliverable is the source-of-truth narrative, refreshed quarterly, that the IR team, legal team, and corporate secretary translate into the three external artifacts.

The 2026 SEC Trend Line

The Division of Corporation Finance is staffing an internal AI working group; the Division of Examinations included AI risk in its 2026 examination priorities for advisers; the Office of the Chief Accountant has signaled attention to AI's impact on financial reporting controls under SOX 404. The trend line for 2026-27:

  • Comment letters move from "describe your AI" to "demonstrate your controls."
  • Enforcement actions for misleading AI disclosures, particularly in fintech and consumer-credit.
  • Rulemaking specifically on AI disclosure (under discussion in commission meetings as of Q1 2026).
  • Cross-coordination with EU regulators on AI Act materiality, particularly for dual-listed companies.

Strategists who built the audit-committee-briefing-to-10-K flow in 2025 are ahead of the curve. Strategists who haven't will be playing catch-up under examiner pressure.

The cheapest AI risk factor is the one written in the calm of Q3, reviewed by the audit committee, refined over two quarters, and filed with confidence. The most expensive is the one written under SEC comment-letter pressure with three weeks to respond.

Key Takeaways

  • The 2025-26 SEC pattern treats vague "we use AI" disclosures as material omissions under Reg S-K Item 105. Median AI risk factor length grew from ~180 words (2024) to ~920 words (Q1 2026 filings).
  • The defensible risk factor has six sections: scope of program, material risks (hallucination, indirect prompt injection, vendor concentration named explicitly), mitigations (named controls), incidents and material impact, forward-looking risk environment (EU AI Act Aug 2 2026, Colorado SB 24-205 Feb 1 2026), and concentration disclosure where applicable.
  • Four materiality factors push agent programs over the threshold: scope (revenue/cost/risk-impacting workflows), failure-mode concentration, vendor concentration, regulatory exposure.
  • The audit-committee briefing template (10 pages, quarterly) is the source-of-truth document whose Page 9 disclosure language flows directly into the 10-K. Same language, three documents (10-K, proxy, board minutes).
  • Three disclosure failure modes: the "we use AI" omission, the cut-and-paste from competitor, the disclosure-but-no-controls gap.
  • Adjacent disclosure obligations: 8-K Item 1.05 for material AI-cyber incidents within four business days, proxy AI Oversight, Reg FD discipline on earnings calls, S-1 scrutiny for offerings.
  • The three-question board test: what does the program do, what could go materially wrong, how do we know we are in control. Two-minute answer per question without notes.
  • The rule of three: 10-K Item 1A, proxy AI Oversight, audit committee briefing โ€” same source narrative, three formats, three audiences.
  • The 2026-27 trend: comment letters move from describe to demonstrate; enforcement actions in fintech and consumer-credit; potential AI disclosure rulemaking; SEC-EU coordination on dual-listed companies.
  • The cheapest AI risk factor is written in the calm of Q3 and refined over two quarters; the most expensive is written under examiner pressure in three weeks.