Hypothetical Risk Factor SEC Enforcement: The Disclosure Trap Catching Public Companies in 2026
If your 10-K or 20-F says a cybersecurity breach, pricing investigation, or AI failure "could" happen, but it already has, you have not hedged your disclosure. You have made an affirmative misrepresentation under Rule 10b-5. That is the core of the SEC's hypothetical risk factor enforcement doctrine, and it has been catching public companies since at least 2019 with no sign of slowing.
This article traces the full enforcement timeline, explains the precise legal mechanism that makes hedging language legally useless once an event has occurred, and gives CFOs and disclosure teams a concrete pre-filing audit process to identify stale hypotheticals before the SEC does.
Key takeaway: A risk factor framed as hypothetical becomes an affirmative misrepresentation, not merely an omission, the moment the described event materializes internally. Hedging words like "could," "may," or "if" provide no protection once the risk has already occurred.
What Makes a Risk Factor "Hypothetical" Under SEC Enforcement Theory?
A risk factor is hypothetically framed when it describes a future possibility using conditional language, but the described event has already occurred inside the company. Common formulations include "we may experience a data breach," "if a government investigation were to occur," or "we could face pricing pressure from regulators." None of these phrases are inherently problematic. They become enforcement problems the moment the company knows the event has already happened.
The legal mechanism matters here, and it is what most published guidance glosses over. Under Rule 10b-5(b), it is unlawful to make any "untrue statement of a material fact" or to "omit to state a material fact necessary in order to make the statements made, in the light of the circumstances under which they were made, not misleading." The hypothetical risk factor doctrine operates under that second prong: the omission of the fact that the risk has already materialized makes the conditional statement misleading as a whole.
This distinction carries significant practical weight. Omission liability under Rule 10b-5 generally requires establishing a duty to disclose. Affirmative misrepresentation liability does not. By framing a known, present risk as a future possibility, a company converts what might have been a close omission question into a cleaner fraud charge. That is why the SEC finds this theory so useful, and why hedging language is not a safe harbor.
Item 105 of Regulation S-K, updated in 2020, reinforces this by requiring risk factors to be "specific to the particular company or offering" rather than generic. A boilerplate hypothetical risk factor that does not reflect the company's actual, known risk profile fails both the specificity requirement and the anti-fraud provisions simultaneously.
The Enforcement Timeline: From Mylan to AI-Washing
The doctrine did not emerge from cybersecurity. It has a longer lineage.
2019: Mylan and Facebook Establish the Foundation
The Mylan N.V. enforcement action (settled September 2019) is the foundational pre-cybersecurity case. The SEC alleged that Mylan's risk factors warned it "could" be subject to government investigations and pricing pressure related to its EpiPen product, when in fact the company was already under active DOJ and state attorney general investigation. The SEC charged Mylan with making materially misleading statements.
In July 2019, the SEC charged Facebook with making misleading statements about the misuse of user data. Facebook's risk factors described the risk of data misuse as hypothetical after the company already knew that Cambridge Analytica had improperly harvested user data. Facebook settled for $100 million, a penalty that signaled the SEC was prepared to use this theory against large-cap issuers.
2021: The Cybersecurity Mini-Sweep
June 2021 was the doctrine's high-water mark to that point. The SEC simultaneously charged four companies in what remains the largest single-day hypothetical risk factor enforcement action:
| Company | What Happened | SEC Order |
|---|---|---|
| First American Financial | Risk factors described breach risk as hypothetical; a vulnerability had already exposed approximately 800 million documents containing Social Security numbers, bank account numbers, and mortgage records | Release No. 34-92176 |
| Chegg, Inc. | Maintained hypothetical breach language after at least three separate data security incidents between 2017 and 2020 | Release No. 34-92177 |
| Pearce Companies | Smaller company, signaling the doctrine applies below large-cap | Release No. 34-92178 |
| Marriott International | Described breach risk as hypothetical after inheriting the ongoing Starwood breach through its 2016 acquisition | Release No. 34-92180 |
The First American case also illustrates the disclosure controls failure that typically underlies these violations. Senior executives were informed of the vulnerability by a journalist, but information security personnel had identified it five months earlier and failed to escalate it. The SEC found that this breakdown in internal information flow, not just the risk factor language itself, constituted a violation of disclosure controls and procedures requirements.
The Pearce Companies charge is worth noting specifically: the SEC did not limit this theory to large-cap issuers. Mid-market companies that assume they are below the enforcement radar should reconsider.
2021: The Alphabet Case Extends the Doctrine to Private Litigation
In In re Alphabet Securities Litigation, the 9th Circuit reversed a district court dismissal in July 2021, holding that the complaint plausibly alleged that Alphabet's hypothetical-framed cybersecurity risk factors were materially misleading. The underlying facts, as alleged: Google discovered the "Three-Year Bug" in March 2018, a software vulnerability in Google+ that had, since 2015, left private data of hundreds of thousands of users exposed to third-party developers. Google+ had approximately 395 million monthly active users at the time.
Google's legal and policy staff prepared a memo warning that disclosure "would likely trigger 'immediate regulatory interest.'" Key officers and directors, including the CEO, "chose to conceal this discovery, made generic statements about how cybersecurity risks could affect their business, and stated that there had been no material changes to Alphabet's risk factors since 2017," according to the 9th Circuit's recitation of the complaint.
That last phrase is critical. Alphabet's Form 10-Q for Q1 2018 stated there were "no material changes to our risk factors since our Annual Report on Form 10-K for the year ended December 31, 2017." The 9th Circuit treated this incorporation-by-reference statement as independently actionable, not just the underlying risk factor language. The court found scienter adequately alleged because executives approved a plan of nondisclosure after being warned by legal staff.
2023: SolarWinds and the CISO
The SEC charged SolarWinds Corporation and its CISO Timothy Brown in October 2023 with fraud and internal controls failures. Among the allegations: SolarWinds' risk factors described cybersecurity risks in hypothetical terms while the company knew of specific, serious vulnerabilities. A federal judge dismissed some claims in July 2024 but allowed the core fraud claims to proceed. The case remains active litigation, keeping the hypothetical risk factor theory alive in federal court.
The SolarWinds case also introduced a new dimension: individual liability. Charging a CISO personally raised the stakes for every officer involved in the disclosure process, not just the CFO and CEO who sign Sarbanes-Oxley certifications.
2024: AI-Washing and the Next Frontier
In March 2024, the SEC charged two investment advisers, Delphia and Global Predictions, with AI-washing: making false and misleading statements about their use of artificial intelligence. For operating companies, the parallel risk is structurally identical to the hypothetical risk factor doctrine. A company that describes AI-related risks as hypothetical, "we may face risks from AI errors," when it has already experienced AI-related incidents, regulatory inquiries, or material failures, faces the same exposure.
White & Case has flagged this directly: "Appropriate risk factor disclosure is crucial to address SEC concerns of 'AI-washing,' or misleading investors as to their true artificial intelligence capabilities." ESG risk factors carry the same risk. A company that describes climate transition risks or supply chain human rights risks as hypothetical, when internal audits or assessments have already identified these as present, known risks, is in the same doctrinal territory.
For a deeper look at how AI disclosure requirements are evolving in SEC filings, see Finrep's AI Disclosure in Your Q2 2026 Form 10-Q.
The "No Material Changes" Trap in Quarterly 10-Q Filings
The incorporation-by-reference statement in quarterly 10-Q filings is one of the most underappreciated exposure points in this doctrine. Most companies routinely include language stating there are "no material changes to our risk factors since our Annual Report on Form 10-K." This is efficient. It is also an affirmative certification that nothing has changed.
The Alphabet case turned partly on exactly this statement. When a company knows that a risk factor has become stale because the described event has occurred, the incorporation-by-reference statement is not neutral boilerplate. It is an independent misrepresentation.
The practical implication: the decision to use incorporation-by-reference in a 10-Q should be an active, documented choice, not a default. Disclosure teams should confirm, before each quarterly filing, that no internal events have made any annual report risk factor misleading. If they have, the 10-Q needs affirmative updated disclosure, not a blanket "no material changes" statement.
The 2023 Cybersecurity Rules Create a Dual-Exposure Problem
The SEC's 2023 cybersecurity disclosure rules (effective December 2023 for large accelerated filers) require disclosure of material cybersecurity incidents on Form 8-K within four business days of determining materiality, and annual disclosure of cybersecurity risk management, strategy, and governance on Form 10-K.
These rules create a compounding exposure that no top-ranking article on this topic currently addresses. A company that has experienced a material cybersecurity incident and has not filed a Form 8-K is simultaneously:
- Violating the 2023 cybersecurity disclosure rules directly.
- Potentially making its existing hypothetical risk factors materially misleading under Rule 10b-5.
The gap between when an incident is discovered internally and when it is disclosed publicly is precisely the window of maximum enforcement exposure. The 2023 rules narrow that window to four business days after a materiality determination, but they do not eliminate the underlying hypothetical risk factor problem. A company that determines an incident is not material for 8-K purposes but continues to carry hypothetical risk factor language may still face enforcement if the SEC later disagrees with that materiality call.
Does the Doctrine Apply to Foreign Private Issuers?
Yes. Item 3.D of Form 20-F requires risk factor disclosure, and the SEC's anti-fraud provisions under Section 10(b) and Rule 10b-5 apply to all issuers with securities registered under the Exchange Act, regardless of domicile. White & Case's 2025 guidance specifically addresses 20-F filers alongside 10-K filers. Foreign private issuers that assume the doctrine is a US-domestic concern are mistaken.
What Is the Legal Standard? Intent vs. Negligence
This question matters enormously for compliance officers assessing exposure.
- SEC administrative proceedings: Negligent failure to update a risk factor can suffice. The First American and Chegg orders did not require proof of intentional misconduct. The SEC brought charges based on disclosure controls failures and negligence-based fraud theories.
- Private Rule 10b-5 litigation: Scienter, meaning intent to deceive, manipulate, or defraud, is required. But the Alphabet case shows that scienter can be inferred from internal memos, executive approval of a nondisclosure plan, and the gap between what executives knew and what they said publicly.
The practical takeaway: a company does not need to have deliberately misled investors to face SEC enforcement. A broken internal information flow, where an incident is known to operational teams but never reaches the disclosure committee, is enough.
The Comment Letter Warning System
Before formal enforcement, the SEC's Division of Corporation Finance uses comment letters as a lower-stakes but high-frequency mechanism to flag hypothetical risk factor concerns. Staff routinely cross-reference risk factor language against other public statements, earnings call transcripts, press releases, and investor presentations. If a CEO says on an earnings call that "we have experienced some disruption from AI errors" but the 10-K risk factor says "we may experience disruption from AI errors," that inconsistency is precisely what comment letter staff flag.
These letters are publicly available on EDGAR and represent an early warning system companies can use proactively. A comment letter asking for revised risk factor language is far less damaging than an enforcement action. For guidance on responding to SEC comment letters effectively, see Finrep's SEC Comment Letter Response Best Practices.
The 5-Step Pre-Filing Audit for Stale Hypotheticals
As Cooley LLP has noted, "companies need to regularly review their risk factor disclosures, even when, or perhaps especially when, they are incorporating them by reference to ensure that they have been appropriately updated to reflect actual events that may have made the risks described as merely hypothetical no longer so."
Here is a concrete process for doing that before each 10-K, 20-F, or 10-Q filing:
Step 1: Inventory every conditionally framed risk factor. Pull all risk factors containing "could," "may," "might," "if," "in the event," or "were to occur." These are the candidates for staleness review. Do not assume last year's review is still valid.
Step 2: Cross-reference against internal incident data. For each hypothetical risk, check the following internal sources:
- Cybersecurity incident logs and vulnerability reports
- Regulatory correspondence files (DOJ, FTC, state AGs, non-US regulators)
- Internal audit reports and management letters
- Board and audit committee minutes
- Litigation hold notices and legal department matter lists
- Insurance claims filed in the relevant period
- Customer complaint escalations above defined thresholds
- AI system error logs and model performance reports (for AI-related risk factors)
- ESG audit findings and supply chain assessment reports
Step 3: Assess materiality for each match. Where an internal event matches a hypothetical risk factor, apply a materiality analysis. The standard is whether a reasonable investor would consider the information important. Document the analysis and the conclusion. If the event is material, the risk factor must be updated and, for cybersecurity incidents, a Form 8-K may be required within four business days of the materiality determination.
Step 4: Review the "no material changes" statement. Before using incorporation-by-reference in a 10-Q, affirmatively confirm that no internal events have made any annual report risk factor misleading. This confirmation should be documented. If there is any doubt, update the risk factor rather than rely on the blanket statement.
Step 5: Cross-check public statements for consistency. Compare risk factor language against recent earnings call transcripts, press releases, investor presentations, and website content. Any inconsistency between what executives say publicly and what the risk factors describe as hypothetical is a red flag that comment letter staff and plaintiffs' counsel will find.
For companies with significant AI or ESG risk factor exposure, consider engaging outside counsel to conduct a privileged review of risk factor currency before filing. The privilege protects the analysis; the update protects the company.
FAQ
Does this doctrine apply only to cybersecurity risk factors? No. The doctrine originated in the Mylan pricing investigation case (2019) and has since been applied to data privacy, inventory management (the Peloton Second Circuit case), and AI capabilities. ESG risk factors describing climate, supply chain, or regulatory risks as hypothetical face the same exposure if internal assessments have already identified those risks as present.
What are the penalties for hypothetical risk factor violations? Penalties in the 2021 mini-sweep ranged from approximately $500,000 (First American) to $1 million (Chegg). The Facebook settlement was $100 million. SolarWinds-related actions in October 2024 ranged from $990,000 to $4 million. Individual officers can face personal charges, as the SolarWinds CISO case demonstrated. Disgorgement and officer bars are also available remedies in administrative proceedings.
Can a company rely on the "bespeaks caution" doctrine or the PSLRA safe harbor to protect hypothetical risk factors? No. The PSLRA safe harbor for forward-looking statements does not protect statements that were false when made. A risk factor describing a future possibility is not forward-looking if the described event has already occurred. The safe harbor is for genuine predictions about the future, not for misdescribing the present.
How does the SEC find out that a hypothetical risk had already materialized? Three main channels: (1) journalists or whistleblowers who publish or report the incident, as in the Alphabet and First American cases; (2) SEC comment letters that flag inconsistencies between risk factor language and other public statements; and (3) the SEC's own data analytics capabilities, which cross-reference filings against news reports, regulatory databases, and other public information.
Is the doctrine live under the current SEC administration? Yes. White & Case confirmed in its 2025 annual report guidance that "the SEC remains vigilant on this issue and has instituted enforcement actions against numerous companies for disclosing as hypothetical risks that had already materialized." The theory is grounded in the basic anti-fraud provisions of the Exchange Act, which enjoy bipartisan support and are not subject to the deregulatory shifts affecting other SEC priorities.
Does the Second Circuit's Peloton decision expand private litigation risk? Yes. The Second Circuit held in City of Hialeah Employees' Retirement System v. Peloton Interactive that Peloton's inventory risk factor disclosures in its August 2021 Form 10-K and November 2021 Form 10-Q were potentially misleading because "the specific financial consequences described in these disclosures were not merely hypothetical but had already materialized." This extends the doctrine beyond cybersecurity into operational and financial risk factors, and it signals that private plaintiffs in the Second Circuit can survive a motion to dismiss on this theory.
The window between when an incident occurs and when it is disclosed is not a grace period. It is the period of maximum legal exposure.







