AI Hallucination Risk in SEC Filings: A 2026 Practitioner Walkthrough
If your team uses AI to draft any part of a 10-K, 10-Q, 8-K, proxy statement, or ESG report, this article is for you. The question is not whether your AI tool will hallucinate. It is whether your controls will catch the error before it reaches a filed disclosure and triggers antifraud liability.
Every article ranking on this topic right now is written for litigators worried about Rule 11 sanctions and fake case citations. That is a real problem, but it is not your problem. Your problem is that a materially false statement in an SEC filing, whether drafted by a human or generated by an AI model, carries the same exposure under Section 10(b) of the Exchange Act and Rule 10b-5. There is no technology exception.
This walkthrough covers the specific hallucination failure modes that matter for disclosure teams, the regulatory framework already in force, and the concrete governance steps you need before your next filing cycle.
Key takeaway: The Sullivan and Cromwell incident in April 2026 proved that even a 900-lawyer firm with formal AI policies and a secondary review process can fail to catch AI-generated errors in high-stakes financial documents. The same failure mode applies directly to SEC disclosure workflows.
Why AI Hallucination Risk in SEC Filings Is Different from the Court-Filing Problem
The stakes in SEC filings are higher, and the failure mode is harder to detect. When a litigator files a brief with a fake case citation, opposing counsel or the court will often catch it. When a CFO files a 10-K with a hallucinated GAAP reference or a fabricated ESG metric, the error may sit in the public record for months before anyone notices.
The court-filing cases are instructive precisely because they reveal the pattern. In Mata v. Avianca (SDNY, 2023), Judge P. Kevin Castel sanctioned two lawyers $5,000 after they filed a brief with fake cases invented by ChatGPT and then defended the citations when challenged. The Layer3 Labs sanctions tracker now logs over 1,000 US court decisions involving AI-hallucinated material. The pattern across every case is identical: AI generated plausible-looking but fabricated content; no human verified it before filing; the error was discovered by someone else.
That pattern is directly replicable in SEC disclosure workflows. The difference is that the governing framework is not Rule 11. It is the antifraud provisions of the federal securities laws.
The SEC Regulatory Framework That Already Governs AI-Generated Content
No AI-specific SEC rule exists yet, but the existing framework applies in full. The SEC's position, stated explicitly by Chair Gensler in October 2023, is that the antifraud provisions carry no technology exception. A materially false or misleading statement in an SEC filing is actionable whether a human or an AI drafted it.
The relevant framework has four components:
-
Section 10(b) and Rule 10b-5 prohibit any materially false or misleading statement in connection with securities. A hallucinated financial figure, a misquoted GAAP standard, or an invented ESG benchmark in a 10-K is a potential Rule 10b-5 violation.
-
The SEC's March 2024 AI-washing enforcement actions are the most directly relevant precedent. The SEC charged Delphia (USA) Inc. and Global Predictions Inc. with making false and misleading statements about their use of AI. Delphia paid $225,000 and Global Predictions paid $175,000 in civil penalties. The enforcement signal is clear: AI-related misrepresentation, including failing to disclose AI limitations, is treated as a violation of existing antifraud provisions.
-
Regulation S-K Item 105 requires disclosure of material risk factors. Securities practitioners and Big-4 firms have begun advising public companies to consider naming AI hallucination risk explicitly, specifically the risk that AI-assisted drafting could introduce material errors into disclosures.
-
SOX Section 302 requires the CEO and CFO to certify that disclosure controls and procedures (DC&P) are designed to ensure material information is accurately reported. If AI tools are used in the disclosure drafting process without being incorporated into the DC&P framework, the certification may be deficient. This is the question that keeps general counsels up at night: does a SOX 302 certification cover AI-generated content that was never independently verified?
The SEC's Staff Bulletin No. 20 (2024), while focused on investment advisers, reinforces the same principle: AI output is subject to the same accuracy standards as human output.
The Four Hallucination Failure Modes That Matter for Disclosure Teams
Not all hallucinations carry equal risk in a disclosure context. The four failure modes below are the ones most likely to survive cursory human review and make it into a filed document.
| Failure Mode | Example | Primary Risk |
|---|---|---|
| Fabricated regulatory citation | AI cites "ASC 606-10-25-14" for a revenue recognition rule that does not exist at that codification address | Materially misleading disclosure; auditor finding |
| Hallucinated financial data | AI generates a prior-period comparative that does not match the audited financial statements | Rule 10b-5 violation; restatement risk |
| Invented ESG metric | AI summarises scope 2 emissions as 12,400 tCO2e when the underlying data shows 124,000 tCO2e | ESRS/ISSB data quality failure; CSRD audit finding |
| Fabricated forward-looking statement | AI drafts an MD&A outlook citing a "market study" that does not exist | Securities Act Section 17(a) exposure; safe harbour loss |
The reason these are dangerous is not that they look wrong. It is that they look exactly right. As the Layer3 Labs tracker notes, AI generates outputs with "the right format, a confident tone, and a made-up holding that supports your argument. Nothing on the page warns you the case is fiction." The same dynamic applies to a hallucinated GAAP reference or a fabricated Federal Reserve study, like the one embedded in the Harrison and Greene securities filing in March 2025, which cited a "23% increase in insider-trading prosecutions" from a study that did not exist.
For a broader task-by-task risk map of where hallucination risk concentrates across the financial reporting cycle, see Finrep's AI hallucination in financial reporting practitioner walkthrough.
The Sullivan and Cromwell Incident: What It Means for Your Disclosure Workflow
In April 2026, Sullivan and Cromwell admitted to a New York federal judge that a filing in the Prince Group bankruptcy case, a matter involving a $9 billion bitcoin seizure and securities-adjacent wire fraud and money laundering charges, contained AI-generated hallucinations. The errors included misquoting the US bankruptcy code and incorrectly citing cases. They were discovered not by S&C's own review process but by opposing counsel at Boies Schiller Flexner.
Andrew Dietderich, co-head of S&C's global restructuring group, wrote in his letter to Judge Martin Glenn: "S&C maintains comprehensive policies and training requirements governing the use of AI tools in legal work that are designed to catch any potential errors. [However,] those AI policies were not followed and a secondary review process also did not identify the inaccurate citations generated by AI."
Three things make this incident directly relevant to SEC disclosure teams:
- S&C is not a careless firm. It employs more than 900 lawyers and carries one of the strongest reputations for corporate work in the US. If a firm at that level, with formal AI policies and a secondary review process, fails to catch hallucinations, a finance team running AI-assisted disclosure drafting without equivalent controls faces the same or greater risk.
- The errors were discovered by an adversary, not internal review. In an SEC context, the equivalent is a whistleblower tip, an SEC comment letter, or a short-seller report. The SEC's Office of the Whistleblower has seen a significant increase in AI-related tips since 2024.
- The case context is securities-adjacent. This was not a routine commercial dispute. It involved a high-stakes financial crime matter, exactly the kind of proceeding where AI-assisted drafting of financial and legal documents is most tempting and most dangerous.
What the PCAOB and ESG Frameworks Add to the Risk Picture
PCAOB scrutiny of AI in audit workpapers
The PCAOB's 2024 inspection priorities flagged AI use in audit workpapers as an emerging risk area. Auditors using AI tools for substantive testing or documentation must ensure AI-generated outputs are appropriately supervised and verified. The implication for companies: if your auditor discovers that management used AI to generate financial data or disclosure language without adequate controls, it can trigger audit findings. In a worst case, it raises going-concern considerations.
CSRD and ESRS data quality requirements
EFRAG's ESRS Set 1, effective for large EU companies from 2024 with phased implementation through 2026, requires that sustainability disclosures be accurate, verifiable, and auditable. CSRD applies to approximately 50,000 companies across the EU. An AI-generated ESG metric that cannot be traced to primary data sources fails the ESRS data quality requirements. ESG teams using AI to aggregate or summarise sustainability data face a specific hallucination risk: a plausible-looking but fabricated emissions figure or supply chain metric could pass internal review and appear in a CSRD-audited report.
ISSB S1 and S2
IFRS S1 and S2, effective January 2024, require that sustainability-related financial disclosures be based on reasonable and supportable information available at the reporting date. AI-generated estimates or forward-looking statements that cannot be grounded in verifiable data do not meet this standard. The ISSB has not yet issued specific guidance on AI use in IFRS S1/S2 reporting, which means the burden of demonstrating data quality falls entirely on the reporting company.
For a full walkthrough of AI use in ESG reporting workflows, see AI ESG reporting automation: a 2026 practitioner walkthrough.
The Governance Checklist: What to Implement Before Your Next Filing Cycle
This is the section the top-ranking articles do not provide, because they are written for litigators, not finance teams. The following steps address the specific governance gaps that create SEC liability exposure.
Step 1: Map every AI touchpoint in your disclosure workflow
Before you can control AI hallucination risk, you need to know where AI is actually being used. This means a structured inventory across every disclosure document type: 10-K, 10-Q, 8-K, proxy, CSRD/ESRS report, ISSB-aligned sustainability report. Ask each team, IR, legal, finance, ESG, tax, to identify which drafting, summarisation, or data aggregation tasks involve AI tools, including general-purpose tools like Microsoft Copilot or ChatGPT that may not be formally sanctioned.
Shadow AI use, employees using unapproved tools without disclosure to the compliance function, is a documented risk in financial reporting contexts. For a detailed treatment, see shadow AI SEC disclosure risks.
Step 2: Classify AI use by hallucination risk tier
Not every AI task carries equal risk. A tiered classification helps allocate review resources.
| Risk Tier | Task Type | Example | Required Control |
|---|---|---|---|
| High | Free-text narrative generation | MD&A, risk factors, ESG narrative | Senior human review + source verification |
| High | Regulatory citation or standard reference | GAAP/IFRS standard numbers, SEC rule citations | Independent lookup against primary source |
| Medium | Data summarisation | Variance commentary, KPI tables | Cross-check against audited source data |
| Low | Formatting and structure | Section headers, table of contents | Standard editorial review |
Step 3: Update your DC&P framework to cover AI-generated content
Under SOX Section 302, the CEO and CFO certify that DC&P are designed to ensure material information is accurately recorded, processed, summarised, and reported. Legal experts have begun arguing that AI tools used in the disclosure drafting process must be incorporated into the DC&P framework. This means:
- Documenting which AI tools are approved for use in disclosure workflows.
- Requiring that AI-generated content be subject to the same human review and sign-off as any other disclosure input.
- Maintaining an audit trail showing that AI-generated content was reviewed and verified before filing.
The audit trail requirement is not optional. In an SEC investigation, the absence of documentation showing human review of AI-generated content is the gap that turns an honest mistake into a control failure. For a detailed treatment of audit trail requirements, see AI audit trail requirements for SEC filers.
Step 4: Build source-verification checkpoints into the drafting workflow
Every regulatory citation, financial figure, and ESG metric generated by AI must be verified against a primary source before it enters a draft disclosure. This is not a new obligation. It is the same standard that applies to human-drafted content. The difference is that AI-generated errors are harder to spot because they are confident and plausible.
The verification workflow for high-risk content should follow this sequence:
- AI generates draft language.
- The drafter identifies every factual claim, regulatory citation, and data point in the AI output.
- Each item is independently verified against the primary source: the FASB Codification for GAAP references, the official ESRS or ISSB text for sustainability standards, the company's audited financial statements for financial data.
- The verification is documented in a log that captures the item verified, the source consulted, the verifier's name, and the date.
- No AI-generated content proceeds to the disclosure committee review without a completed verification log.
Retrieval-Augmented Generation (RAG), which grounds AI output in a verified, real-time corpus rather than relying solely on model parameters, reduces hallucination risk substantially. For SEC disclosure workflows, this means connecting AI drafting tools to verified sources: the SEC's EDGAR database, the FASB Codification, official ESRS and ISSB texts, and the company's own audited financial data. RAG does not eliminate hallucination risk, but it narrows the gap between what the AI generates and what the underlying sources actually say.
Step 5: Decide whether to disclose AI use in your filing
The SEC has not yet required companies to disclose that AI was used to help prepare their filings. But the question is live, and the answer has two dimensions.
Risk factor disclosure. Under Regulation S-K Item 105, if AI hallucination risk is material to your business or your disclosure process, it should be named as a risk factor. Several securities practitioners and Big-4 firms have begun advising public companies to consider adding language along these lines: "We use AI tools to assist in the preparation of certain disclosures. AI-generated content may contain errors or inaccuracies that, if not detected by our review processes, could result in materially false or misleading statements in our filings." This disclosure is protective, not an admission of weakness.
Process disclosure. There is currently no SEC requirement to disclose the use of AI in filing preparation as a process matter. However, if the SEC's AI-washing enforcement posture continues to develop, companies that use AI extensively in disclosure drafting without disclosing it may face scrutiny. The safer position is to document the use and the controls, even if the documentation is internal rather than public.
For a detailed treatment of AI disclosure language in the 10-Q context, see AI disclosure in your Q2 2026 Form 10-Q.
Step 6: Ask the right questions of your AI vendor
Before deploying any AI tool in a disclosure workflow, the CFO or general counsel should get written answers to the following:
- What is the tool's documented hallucination rate on financial and regulatory content?
- Does the tool use RAG, and if so, what corpus does it retrieve from? Is that corpus updated in real time?
- Does the tool provide an audit trail of its outputs, including the source documents it drew on?
- What controls does the vendor have in place to prevent the tool from generating fabricated regulatory citations?
- Has the tool been tested against the FASB Codification, ESRS texts, and ISSB standards specifically?
For a full vendor due diligence framework for AI tools in finance, see AI vendor due diligence for finance: a 2026 practitioner walkthrough.
FAQ
Can our company be held liable under SEC antifraud rules if AI-generated content in our 10-K turns out to be wrong?
Yes. Section 10(b) of the Exchange Act and Rule 10b-5 prohibit materially false or misleading statements in connection with securities, regardless of whether a human or an AI generated the error. The SEC has stated explicitly that existing antifraud provisions carry no technology exception. The March 2024 enforcement actions against Delphia and Global Predictions confirm the agency will act on AI-related disclosure failures.
Does a SOX 302 certification cover AI-generated content?
It should, but most DC&P frameworks were not designed with AI drafting tools in mind. If AI-generated content in a disclosure was never independently verified, the CEO and CFO may be certifying the effectiveness of controls that did not actually catch a material error. Legal experts recommend updating DC&P documentation to explicitly cover AI tools used in the disclosure process.
Do we need to disclose to the SEC that we used AI to help draft our filings?
Not yet as a mandatory process disclosure. But if AI hallucination risk is material to your disclosure process, it should appear as a named risk factor under Regulation S-K Item 105. Companies that use AI extensively without any disclosure also face growing scrutiny from the SEC's AI-washing enforcement posture.
How does AI hallucination risk affect CSRD and ISSB reporting?
EFRAG's ESRS framework requires sustainability disclosures to be accurate, verifiable, and auditable. ISSB S1 and S2 require disclosures to be based on reasonable and supportable information. AI-generated ESG metrics that cannot be traced to primary data sources fail both standards. ESG teams using AI to aggregate or summarise sustainability data need the same source-verification controls as financial disclosure teams.
What is the single most important control to implement first?
The audit trail. Document every instance where AI contributes to a disclosure: the tool used, the output generated, the verifier's name, and the primary source consulted. Without that documentation, you cannot demonstrate to the SEC, your auditors, or a court that AI-generated content was reviewed before filing. It is also the control that most companies currently lack.
Should we add AI hallucination risk to our Item 105 risk factors?
If AI tools are used in your disclosure drafting process, yes. The risk is real, the SEC is watching, and a named risk factor that accurately describes the risk and your controls is protective. Boilerplate language that overstates your AI capabilities or understates the risk creates its own exposure under the AI-washing enforcement framework.







