![]()
Guardrail Technologies, the leading provider of AI security and governance software for enterprises building with AI, today released The AI Cyber-Disclosure Gap Report, the first study to measure how S&P 500 companies describe their use of artificial intelligence against how they document managing its cybersecurity risk. The first of its kind, the report is what Guardrail intends to make an ongoing benchmark, revisited on a recurring basis as filings update and disclosure practice evolves.
Guardrail reviewed all 503 Form 10-K filings currently on file for S&P 500 companies against the SEC’s Item 1C cybersecurity disclosure requirement. The results were stark and consistent: 97 percent of companies mention AI somewhere in their annual report, but only about 16 percent document an AI-specific cyber-risk process at all, and fewer than 1 in 20 describe a governed one, meaning a named policy, program, or committee with a stated activity connected to cybersecurity controls.
Across every reading applied, including an independent human review, the distance between discussing AI and documenting a process for its cyber risk was at least 77 percentage points.
“Nearly every company in the S&P 500 says AI matters to their business, but almost none can prove how they’re keeping it under control,” said T.J. Marlin, founder and CEO of Guardrail Technologies. “A policy written after a breach carries no weight with an investigator, and a control that only lived in someone’s memory is no control at all. This report shows how few companies could survive that kind of scrutiny today.”
Even the most heavily regulated sectors, financial services, health care, utilities, energy, and real estate, don’t close the gap. These 218 companies document an AI-specific process only slightly more often than the rest of the index: 18 percent versus 15 percent on the more generous reading. A sharper split appears within the group. Utilities, energy, and real estate, whose regulators oversee physical infrastructure, are read as treating AI as a specific cybersecurity risk in about 70 percent of filings. Financial services and health care, whose regulators oversee data, do so in only 37 to 48 percent, despite discussing AI just as heavily as everyone else in the index.
Guardrail plans to repeat this analysis on a recurring basis to track whether disclosure practice moves as the regulatory calendar advances and to give boards, insurers and investors a consistent benchmark rather than a one-time snapshot.
“Every board, public or private, should treat this AI security disclosure gap as urgent,” Marlin added. “If you’re on a public company board, look at what you’re already saying out loud about AI and make sure a documented, governed process backs it up. The alternative won’t hold up.”
A Board Diagnostic for any public company
Alongside the report, Guardrail is launching a Board Diagnostic for any publicly traded company. Using the same framework applied to all 503 filings in the study, Guardrail reviews a company’s most recent cybersecurity disclosure and returns one of three verdicts: Green for a documented, governed AI risk process, Amber for a partial one, or Red for none. It’s the same signal Guardrail already uses in AI Traffic Light™ to flag code and agent behavior, now applied to the disclosure itself. The verdict comes with an executive insights report showing exactly where the disclosure falls short, what a stronger one would say, and how it compares to peers, ready to bring straight to the audit committee.
Guardrail has identified the six critical questions every board should be able to answer about its AI lifecycle; the Board Diagnostic is built to guide the board to the deeper questions related to AI and support in identifying what needs to be addressed.
Companies interested in requesting a Board Diagnostic can do so here. The full report, including sector-level findings and the technical appendix detailing the study’s methodology, is available here.
About Guardrail Technologies
Guardrail Technologies is the leading provider of independent AI security and behavioral governance software for enterprises and the people building and deploying with AI. The company delivers defense in depth throughout the AI lifecycle, from the point of creation through operation, detection and incident response, through two core products: AI Traffic Light™, which scans AI-generated code and verifies the people behind it, and AI Command Center™, which provides centralized governance, behavioral controls and compliance audit trails for enterprise AI operationalization. Founded in Q2 2025 and headquartered in Park City, Utah, Guardrail Technologies holds three issued patents with six additional patents pending. For more information, visit www.guardrail.tech.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260826093157/en/
Media gallery
