Gana Misra
By Gana MisraCEO, Finrep
Mon Sep 07 2026

AI-Generated MD&A: What the SEC Actually Requires in 2026

Share
AI-Generated MD&A: What the SEC Actually Requires in 2026

AI-Generated MD&A: What the SEC Actually Requires in 2026

Generative AI is now inside the MD&A drafting workflow at hundreds of public companies. The SEC has not issued a rule that explicitly governs it. That gap is not a green light.

The existing framework, built from Item 303 of Regulation S-K, the 2003 MD&A interpretive release, SOX Sections 302 and 906, Rule 10b-5, and the SEC's October 2023 sample AI comment letter, collectively impose substantial obligations on any company that uses AI to draft or assist in drafting MD&A. As of September 2026, the SEC's Office of the Chief Accountant has signaled it will issue formal reminders on AI in financial reporting in the coming months, but has deliberately stopped short of prescriptive rules.

This article maps those existing obligations onto the AI-assisted MD&A workflow, section by section, so CFOs, general counsel, and disclosure teams know exactly where the liability sits.

Key takeaway: The absence of an AI-specific MD&A rule does not create a regulatory vacuum. As Smarsh's Q2 2026 regulatory analysis puts it: "The absence of AI-specific regulation doesn't equate to a regulatory vacuum. As firms adopt increasingly sophisticated tools, regulators are watching how they apply long-standing principles of supervision, transparency, and documentation to new technologies."

What Item 303 Actually Requires, and Why AI Creates a Problem

Item 303 of Regulation S-K requires MD&A to let investors see the company "through the eyes of management." That phrase is not rhetorical. The SEC's 2003 interpretive release states it directly: "MD&A should be a discussion and analysis of a company's business as seen through the eyes of those who manage that business. Management has a unique perspective on its business that only it can present."

The same release warns that "MD&A should not be a recitation of financial statements in narrative form or an otherwise uninformative series of technical responses to MD&A requirements." That is precisely what LLMs tend to produce when given a prior-period filing and a prompt to update it.

The November 2020 modernization of Item 303, effective February 10, 2021, retained and sharpened this standard. Item 303(b)(2)(ii) now explicitly requires disclosure of "any known trends or uncertainties that have had or that are reasonably likely to have a material favorable or unfavorable impact on net sales or revenues or income from continuing operations." An AI model that lacks access to internal management information, board discussions, and forward-looking operational data cannot identify company-specific known trends. It can only approximate them from public data, which is not what the rule requires.

Note: most AI-in-MD&A commentary still references the pre-2020 version of Item 303. The 2021 version is the operative standard.

The SOX 302/906 Problem Nobody Is Talking About

When AI drafts the MD&A, the CEO and CFO still sign the SOX certifications. That personal liability does not diminish because a machine wrote the text.

SOX Section 302 requires the CEO and CFO to certify, personally, that they have reviewed the report, that it does not contain material misstatements or omissions, and that disclosure controls and procedures (DC&P) are effective. The certification is not a formality. Our SOX Section 302 practitioner walkthrough covers the paragraph-by-paragraph obligations in detail.

SOX Section 906 raises the stakes further. Executives who knowingly certify a false or misleading periodic report face criminal penalties of up to $5 million and 20 years imprisonment. If AI-generated MD&A contains a hallucinated figure, omits a material trend, or presents generic industry analysis as company-specific insight, and management failed to catch it through inadequate review, Section 906 exposure is real.

The practical implication: the SOX certification process must now include an explicit step that verifies AI-generated content. That means human reviewers who actually understand the underlying business, not just editors checking grammar.

Disclosure Controls and Procedures Must Cover AI

Exchange Act Rules 13a-15 and 15d-15 require companies to maintain DC&P designed to ensure that material information is recorded, processed, summarized, and reported accurately. If AI is part of the MD&A drafting workflow, the company's DC&P must be designed to catch AI errors, hallucinations, and omissions.

This is a concrete, immediate compliance obligation that almost no current commentary addresses. PwC's 2024 guidance on AI in financial reporting recommends that companies using AI in MD&A drafting explicitly update their DC&P documentation to cover AI-assisted workflows, including the human review steps, version control, and prompt retention. The CEO and CFO then certify the effectiveness of those updated controls under SOX 302.

If a company's DC&P documentation does not mention AI tools used in the drafting process, and the SEC or an auditor later asks, that gap is a problem.

What the SEC's October 2023 AI Comment Letter Actually Said

The SEC's Division of Corporation Finance published a sample letter to companies regarding AI disclosures in October 2023. It is the closest thing to specific SEC staff guidance on AI disclosure quality, and it is underutilized in current commentary.

The sample letter asked companies to explain:

  1. Whether and how AI is integrated into their business
  2. The material risks associated with AI use
  3. Whether AI-related disclosures are specific to the company's circumstances

While the letter targeted risk factor disclosures rather than MD&A narrative quality directly, the staff's scrutiny of generic, boilerplate AI language signals exactly how they will approach AI-generated MD&A text. The SEC's cybersecurity disclosure rule, effective December 15, 2023 for large accelerated filers, established the same pattern: specific, non-boilerplate, process-level disclosure. That is the template the staff will apply to AI.

As of June 2026, the SEC's Office of the Chief Accountant confirmed it is monitoring AI use in financial reporting and expects to issue formal reminders, though not prescriptive rules. Deputy Chief Accountant Michal Dusza, speaking at the SEC and Financial Reporting Conference on June 4, 2026, described three areas of concern: third-party AI service providers embedded in financial reporting systems, data quality fed into AI tools, and management's risk assessment of AI deployment across the organization.

Anti-Fraud Rules Apply Regardless of Who Wrote the Text

Rule 10b-5 prohibits any untrue statement of a material fact or omission of a material fact in connection with the purchase or sale of securities. The rule does not care whether a human or an AI generated the statement.

AI-generated MD&A that contains hallucinated figures, omits material trends because the model lacked access to internal data, or presents generic industry analysis as company-specific insight could constitute a material misstatement under Rule 10b-5. The SEC's enforcement posture remains aggressive on disclosure fraud, and the agency's technology-neutral position means existing anti-fraud provisions apply in full to AI-assisted filings.

The SEC's Investor Advisory Committee recommended in December 2025 that the Commission require issuers to define "Artificial Intelligence," disclose board oversight mechanisms, and report separately on AI deployment effects. SEC Chair Paul Atkins and Commissioner Hester Peirce both signaled at that meeting that they prefer the existing principles-based framework over new prescriptive rules. That posture confirms the current compliance environment: existing rules apply, new AI-specific rules are unlikely near-term, and materiality is the governing standard.

The Auditor's Role: PCAOB AS 2710

Auditors are a second line of defense, and a second source of liability exposure, for AI-generated MD&A errors.

PCAOB AS 2710 requires auditors to read MD&A and consider whether it is materially inconsistent with the audited financial statements. If AI-generated MD&A contains a hallucinated revenue figure, an unsupported trend claim, or analysis that contradicts the audited numbers, the auditor has an obligation to raise it. Deloitte's 2024 analysis of AI in financial reporting notes that auditors are increasingly scrutinizing the provenance of MD&A text and whether adequate human review occurred before filing.

This creates a practical workflow implication: the auditor communication process should now include disclosure of which sections of MD&A were AI-assisted and what human review steps were taken. Auditors who discover AI-generated inconsistencies after the fact face their own professional obligations under AS 2710.

Recordkeeping: AI Drafts Are Probably Company Records

If AI-generated MD&A drafts are emailed among the drafting team, shared in collaboration tools, or transmitted to auditors, they almost certainly trigger retention requirements under SEC recordkeeping rules.

Skadden's September 2024 analysis draws the line clearly: "AI-generated information that is not subsequently transmitted likely does not constitute a written communication that must be retained under relevant IA and BD recordkeeping rules. In contrast, AI-generated records that are transmitted through email, chat or otherwise, would trigger retention requirements, assuming the subject matter brings them within the rules."

For MD&A drafting workflows, virtually every AI output will be transmitted at some point. That makes retention obligations near-universal in practice. Rules 17a-4 (broker-dealers) and 204-2 (investment advisers) are the primary vehicles, but the principle extends to any company whose communications touch regulated activities.

As one Eversheds Sutherland panelist noted at Smarsh's Q2 2026 regulatory roundup: "It's probably the most difficult question for last, books and records requirements. When is an AI-generated communication a record of the firm? There's not a good answer to this yet."

The practical answer for MD&A teams: retain AI prompts, outputs, and review logs as if they are records, because they probably are.

Does AI Use in MD&A Need to Be Disclosed?

There is no SEC rule that currently requires companies to disclose that AI was used to draft MD&A text. But two related disclosure risks are live.

First, "AI washing" in MD&A: overstating AI's role in the company's operations or understating material AI-related operational risks. The SEC has already brought enforcement actions against firms for misrepresenting AI capabilities in investor-facing materials. The SEC AI bodies article covers the SEC's Corporate Enforcement and Transparency Unit (CETU), established February 2025 specifically to address AI washing.

Second, if AI use in MD&A drafting is material to understanding the company's disclosure controls, it may need to be disclosed as part of the DC&P discussion. The SEC's cybersecurity rule established the precedent that process-level disclosure of how material risks are managed belongs in the annual report. The same logic applies to AI governance over financial reporting.

Voluntary disclosure of AI use in MD&A, where it is done, typically appears in a methodology note or in the risk factors section, not in the MD&A narrative itself. For the decision framework on what goes in risk factors versus MD&A, see Risk Factor vs. MD&A Disclosure Requirements: What Goes Where in 2026.

Different AI Use Cases, Different Risk Profiles

Not all AI use in MD&A carries the same compliance risk. The risk profile differs materially depending on how the AI is used.

AI Use CasePrimary RiskKey Control
AI as data extraction tool (pulling figures from financials)Hallucinated numbers, wrong periodHuman reconciliation to source financials
AI as drafting assistant (first-draft narrative from management inputs)Generic language, missed company-specific trendsManagement review and substantive revision
AI as primary author (minimal human input)Item 303 "management's perspective" violation, Rule 10b-5 exposureLikely inadequate without major restructuring
AI for ESG/sustainability narrative in MD&ACSRD/ISSB cross-compliance complexity, specificity failuresSeparate ISSB S1/S2 or CSRD materiality assessment required

The third use case, AI as primary author with minimal human input, is the highest-risk configuration. It is also the one most likely to produce the generic, boilerplate language that the SEC has repeatedly criticized in comment letters as inadequate MD&A. For ESG teams using AI to draft sustainability narrative that appears in or alongside MD&A, the ISSB S1 specificity requirements add a further layer of complexity, covered in the IFRS S1 disclosure requirements walkthrough.

A Practical Governance Checklist for AI-Assisted MD&A

Based on the existing regulatory framework, here is what a defensible AI-assisted MD&A process looks like in 2026.

Before drafting:

  • Document which AI tools are used in the MD&A workflow and update DC&P accordingly
  • Ensure AI tools are fed company-specific internal data, not just public filings
  • Confirm that AI vendor contracts prohibit unauthorized use of company data

During drafting:

  • Require substantive human review by someone with direct knowledge of the business, not just editorial review
  • Flag every AI-generated claim that references a specific figure, trend, or forward-looking statement for independent verification against source data
  • Retain all AI prompts, outputs, and review logs as potential company records

Before filing:

  • Run a consistency check between AI-generated MD&A narrative and the audited financial statements (PCAOB AS 2710 is the auditor's obligation, but management should not wait for the auditor to find it)
  • Confirm that the MD&A identifies company-specific known trends under Item 303(b)(2)(ii), not generic industry trends
  • Brief the CEO and CFO on AI-assisted sections before SOX 302 certification; they are personally attesting to the accuracy of that content
  • Confirm that DC&P documentation covers the AI workflow and that the SOX 302 certification reflects that coverage

Recordkeeping:

  • Archive AI-generated drafts transmitted via email or collaboration tools under the same retention schedule as other business records
  • Document the human review steps taken for each AI-assisted section

FAQ

Does the SEC require companies to disclose that AI was used to draft MD&A? No current SEC rule mandates disclosure of AI use in MD&A drafting. However, if AI use is material to understanding the company's disclosure controls, or if AI-related operational risks are material to the business, disclosure may be required under existing materiality principles.

Can AI-generated MD&A satisfy the "management's perspective" standard? Only if management meaningfully reviews, tailors, and takes ownership of the content. AI-generated text that is filed without substantive human review and customization is unlikely to satisfy the standard the SEC set in its 2003 interpretive release and codified in the 2021 Item 303 amendments.

What are the known trends and uncertainties requirements for MD&A? Item 303(b)(2)(ii) of Regulation S-K requires disclosure of any known trends or uncertainties reasonably likely to have a material impact on revenues or income. AI tools that lack access to internal management information cannot reliably identify company-specific known trends, making human input on this section particularly critical.

Is the CEO/CFO still personally liable under SOX when AI drafted the MD&A? Yes. SOX Section 302 certification obligations and Section 906 criminal penalties apply regardless of whether AI or a human drafted the underlying text. The certification attests to the accuracy and completeness of the filing, not to who wrote it.

Do recordkeeping rules apply to AI-generated MD&A drafts? Almost certainly yes, for any draft that is transmitted via email, shared in a collaboration tool, or sent to auditors. Skadden's September 2024 analysis concludes that transmitted AI-generated content triggers retention requirements under Rules 17a-4 and 204-2.

Is there an AI that can read SEC filings? Yes, the SEC itself uses AI-powered review tools to scan 10-K and 10-Q filings for inconsistencies and generic language. The SEC AI-powered review article covers what that means for disclosure teams preparing filings.

The compliance question for 2026 is not whether to use AI in MD&A drafting. It is whether the governance around that use is robust enough to survive a comment letter, an audit inquiry, or an enforcement review. The existing framework sets a high bar. The tools to meet it are process, documentation, and genuine management engagement, not a disclaimer.

Run your financial reporting on Finrep