SEC AI Disclosure Requirements for the 10-K: 2026 Practitioner Guide
There is no standalone SEC rule requiring AI disclosure in your Form 10-K. There is, however, real enforcement liability, an active comment letter campaign, and a peer group where 76% of S&P 500 companies already disclose AI as a material risk. If your company uses AI operationally and your 10-K doesn't say so specifically, you may already have a problem.
This guide is for SEC reporting teams, CFOs, and legal counsel deciding what to disclose about AI in their 2026 annual filing. It maps the three enforcement channels that create real liability today, shows exactly which 10-K sections require or expect AI disclosure, and gives a drafting checklist derived from the SEC staff's own comment letter record.
Key takeaway: The SEC doesn't need a dedicated AI rule to come after you. Existing anti-fraud provisions apply fully to AI capability claims in public filings, and the comment letter record tells you precisely what the staff is looking for.
What Changed: The 2026 SEC AI Disclosure Landscape
The shift from 2023 to 2026 is dramatic. Just 12% of S&P 500 companies disclosed at least one material AI risk in their 2023 annual filings. By 2025, that figure reached 72%, a six-fold increase in two years. An Autonomy Institute report cited by Goodwin Law puts the number at 76% when counting companies that added or expanded AI as a material risk description.
As Goodwin partner Kaitlin Betancourt put it: "Companies risk being the outlier if not mentioning AI in filings." That cuts both ways. Companies that use AI and don't disclose it face staff scrutiny. Companies that claim AI capabilities they don't have face enforcement.
Three developments define the current landscape:
- No dedicated rule, but active enforcement. The SEC has not issued a standalone AI disclosure rule as of September 2026. A formal rulemaking petition (File No. 4-882, filed February 2026) requests mandatory AI governance disclosure rules, but the Atkins-led SEC's deregulatory agenda makes near-term rulemaking unlikely.
- Existing anti-fraud law fully applies. Securities Act Section 17(a) and Exchange Act Section 10(b)/Rule 10b-5 apply to every AI capability claim in a public filing. The March 2024 enforcement actions against Delphia and Global Predictions established the template.
- Comment letters are the primary enforcement tool. The SEC's Division of Corporation Finance sent at least 92 AI-related comment letters to 56 companies between 2021 and October 2024, with volume accelerating through 2025 and 2026.
Does the Atkins SEC Mean Less AI Disclosure Pressure?
No. This is the most important nuance missing from most coverage of the 2026 filing season.
Chair Atkins issued a Statement on Reforming Regulation S-K on January 13, 2026, seeking public comment on how Regulation S-K can be revised to "focus on eliciting disclosure of material information and avoid compelling the disclosure of immaterial information." The SEC's Spring 2025 Unified Agenda withdrew several Biden-era rulemaking proposals and added no AI-specific rulemaking.
But deregulatory posture on new rulemaking does not reduce enforcement under existing rules. Anti-fraud provisions don't require a rulemaking update to apply. The comment letter program continues. The Weil Gotshal 2026 10-K guide is explicit: AI disclosures "should be supported by disclosure controls and procedures and not include false and misleading information." That standard is unchanged regardless of who chairs the SEC.
The practical implication: the Atkins SEC may eventually reduce the volume of prescriptive AI disclosure requirements, but it will not protect companies that make false or misleading AI statements from enforcement under existing law.
What the SEC's 92 Comment Letters Actually Require
The most useful dataset for any drafting team is the Orrick analysis of 92 SEC AI comment letters sent to 56 companies between 2021 and October 2024. The patterns are consistent:
| Comment Type | Share of AI Comments |
|---|---|
| Demand for greater specificity about how AI is or will be used | ~61% |
| Unsupported or unqualified AI capability claims | ~30% |
| Materiality threshold questions | ~10% |
The dominant issue, by a wide margin, is vagueness. Phrases like "extensive AI skill sets and machine learning capabilities" get flagged. The staff wants to know what the AI actually does, in what business process, and with what effect.
The Three Questions the SEC Keeps Asking
Run every AI disclosure against these three questions before filing:
1. How is AI actually used? The staff has asked companies to "describe the scope of the current capabilities" and explain specifically how AI is integrated into disclosed initiatives. A risk factor that says a company "uses AI across its operations" without identifying which operations, what decisions AI influences, or what the failure modes are will draw a comment letter.
2. Is this current or aspirational? The SEC has explicitly asked companies to "clearly distinguish current technological capabilities from future aspirational capabilities" and to "describe any material steps that will need to be taken to fully develop" AI platforms. This applies to proxy statements too: the staff has asked companies to revise proxy bullet points to clarify "if true, that these are not yet products or services the company provides, and are instead areas of research or are aspirational."
3. What liability does the company assume? For customer-facing AI, the staff has specifically asked companies to disclose "the liability that you assume, if any, if your AI technology incorrectly evaluates" outcomes such as creditworthiness. This is a recurring, specific comment, not a general prompt.
The AI Washing Line: Delphia and Global Predictions
AI washing is the enforcement risk that existing anti-fraud law was built to address. On March 18, 2024, the SEC charged Delphia (USA) Inc. and Global Predictions Inc. with making false and misleading statements about their AI capabilities. Delphia claimed it used machine learning and client data to power investment algorithms. It had never incorporated client data into any AI or machine learning technology. These are the first SEC AI washing enforcement actions and define the line.
The enforcement template has three elements:
- Claiming AI capabilities that don't exist or aren't deployed
- Failing to disclose that a flagship AI product relies on a third party's technology rather than proprietary systems
- Describing AI as eliminating human involvement when substantial human involvement remains
All three elements can appear in a 10-K. All three are reachable under existing anti-fraud provisions without any new rule.
The 10-K Section-by-Section AI Disclosure Map
This is the gap no top-ranking article fills: exactly which form items require or expect AI disclosure, and what belongs in each. The primary form items are Regulation S-K Items 101, 105, and 303, with the 2023 cybersecurity rules adding Item 1C as a mandatory hook for AI-related threats.
Item 1 (Business Description)
What belongs here: How AI is integrated into your products, services, and operations, described with the specificity the staff expects.
The Weil Gotshal 2026 10-K guide explicitly lists AI disclosure as a key Item 1 consideration for 2026 filings, alongside human capital management and climate. Oracle's fiscal year 2026 10-K is a live benchmark: it describes "Oracle Autonomous AI Database offerings" and AI-integrated OCI services with enough specificity to show what the technology does and how it is delivered.
Practical checklist for Item 1:
- Name the specific AI systems or capabilities deployed (not just "AI")
- Identify which business processes or products they support
- Disclose material third-party AI dependencies (model providers, API vendors)
- Distinguish deployed capabilities from those in development
- Define terms like "generative AI" or "large language model" if you use them
Item 1A (Risk Factors)
What belongs here: Material risks from AI use, AI-related regulatory exposure, and AI-enabled threats to the business.
AI appears as a standalone risk factor in 33% of fiscal year 2025 10-K filings, up from 1% three years ago. The Weil Gotshal guide flags AI/cybersecurity as the top Item 1A priority for the 2026 filing season.
The Conference Board/ESGAUGE analysis identifies seven AI legal risk categories that sophisticated companies are disclosing:
- AI washing and misleading capability claims
- Cybersecurity and data privacy
- Intellectual property and copyright
- Regulatory and compliance risk (including EU AI Act exposure)
- Operational and model risk
- Third-party and vendor dependency risk
- Reputational risk
A standalone AI risk factor is not always the right structure. Some companies integrate AI risks into existing cybersecurity, operational, or regulatory risk factors. Either approach works if the disclosure is specific. What doesn't work is a generic paragraph that could apply to any company in any industry.
Item 1C (Cybersecurity)
What belongs here: AI-related cybersecurity risks, including how AI tools expand your attack surface and how AI-enabled threats affect your risk management program.
The SEC's 2023 cybersecurity disclosure rules (effective December 2023) require annual disclosure of cybersecurity risk management, strategy, and governance under Item 1C. AI-related cybersecurity risks fall squarely within this framework.
Twenty percent of S&P 500 companies cited cybersecurity as an AI-specific concern in their 2025 filings. The dual-trigger scenario is the compliance issue most companies haven't planned for: an AI-enabled cyberattack may require both a Form 8-K Item 1.05 cybersecurity incident disclosure and an update to your AI risk factor simultaneously. Your disclosure controls need to be wired to catch both triggers.
The Weil Gotshal guide also notes that the SolarWinds enforcement action dismissal is relevant to Item 1C calibration: companies should think carefully about the specificity and liability exposure of AI-related cybersecurity risk disclosures in light of that outcome.
Item 303 (MD&A)
What belongs here: How AI has materially affected (or may materially affect) results of operations, liquidity, or capital resources.
If AI investments are material to your cost structure, if AI-driven revenue is a meaningful portion of results, or if AI model failures have caused or could cause material operational disruption, that belongs in MD&A under Regulation S-K Item 303. The materiality standard under Basic Inc. v. Levinson (1988) governs what must be disclosed.
For teams using AI to draft or support MD&A narratives, see our companion piece on AI-generated MD&A SEC requirements, which covers the Item 303 and SOX 302 obligations that apply when AI tools touch the MD&A drafting process.
The SOX 302 Certification Problem
This is the gap almost no article addresses. Every AI disclosure in your 10-K is subject to the CEO and CFO certification requirements under SOX Section 302. The certifying officers are attesting that the disclosure controls and procedures are effective and that the filing contains no material misstatements.
That creates a concrete internal process requirement: your disclosure committee needs to be able to verify AI disclosure claims before the CEO and CFO sign. If your legal team is writing AI risk factors based on what the product team told them six months ago, and the AI deployment has changed materially since then, you have a certification problem.
Practical steps to support SOX 302 certification of AI disclosures:
- Include AI use in your disclosure committee's quarterly review scope
- Establish a process for the product and engineering teams to flag material changes in AI deployment between filing dates
- Document the basis for each AI capability claim in the filing
- Treat AI disclosure review as part of your sub-certification cascade
How to Disclose AI Without Over-Disclosing
The competitive sensitivity tension is real. Companies want to satisfy the SEC's specificity requirements without revealing proprietary AI capabilities or vendor relationships that competitors could exploit.
The resolution is to be specific about function and risk without being specific about architecture. The SEC staff wants to know what the AI does and what can go wrong, not how the model is built. Practical framing:
- Describe AI by business function ("AI-assisted credit underwriting," "AI-driven demand forecasting") rather than by technical implementation
- Disclose vendor dependency categories ("third-party large language model providers") without necessarily naming specific vendors if that information is genuinely competitively sensitive
- Describe the risk of vendor concentration or model failure without disclosing contractual terms
- Use forward-looking statement safe harbors for aspirational AI plans, but only after clearly labeling them as forward-looking and distinguishing them from current deployed capabilities
The line the SEC has drawn is between specificity about function and risk (required) and specificity about proprietary implementation details (not required). Boilerplate that avoids both fails the first test.
The Rulemaking Petition: What File No. 4-882 Signals for 2027
A formal rulemaking petition (File No. 4-882) was filed with the SEC in February 2026, requesting mandatory AI governance disclosure rules. If adopted, mandatory AI governance disclosure would likely require companies to disclose:
- Board-level AI oversight structures and committee assignments
- Internal AI governance policies and risk management frameworks
- Material AI incidents and their business impact
- Third-party AI vendor risk management programs
The Atkins SEC's deregulatory posture makes adoption in 2026 or 2027 unlikely. But the petition signals where institutional pressure is building. Companies that build AI governance infrastructure now, and disclose it proactively in their 10-K, will be better positioned if mandatory requirements arrive. The SEC has used CF Disclosure Guidance on cybersecurity (Topic No. 2, 2011) and climate (2010) as models for how staff guidance can precede formal rulemaking. No equivalent AI-specific CF Disclosure Guidance has been issued as of September 2026, leaving companies without an official interpretive anchor but also without a safe harbor.
For companies subject to both SEC and EU AI Act obligations, the disclosure complexity compounds. The EU AI Act's phased implementation creates overlapping AI governance requirements that may conflict with or supplement SEC disclosure obligations, particularly for companies with significant European operations.
2026 AI Disclosure Drafting Checklist
Before your 10-K is filed, run this checklist against every AI-related disclosure in the document:
Specificity (addresses ~61% of SEC comment letters)
- Each AI capability is described by business function, not just labeled "AI"
- The specific operations or decisions AI influences are identified
- Failure modes and their business consequences are described
- Generic phrases like "extensive AI capabilities" have been replaced with functional descriptions
Current vs. aspirational (addresses ~30% of SEC comment letters)
- Deployed AI capabilities are clearly distinguished from those in development
- Forward-looking AI plans are labeled as forward-looking
- Proxy statement AI references are consistent with 10-K disclosures
- Material steps needed to develop aspirational capabilities are described
Liability and risk (addresses recurring SEC staff questions)
- For customer-facing AI: the liability assumed if AI incorrectly evaluates outcomes is disclosed
- Third-party AI vendor dependencies are disclosed
- The dual-trigger scenario (AI-enabled cyberattack triggering both Item 1C and Item 1A) has been assessed
- AI disclosures are consistent across Item 1, Item 1A, Item 1C, and MD&A
SOX 302 support
- Disclosure committee has reviewed and verified AI capability claims
- Product and engineering teams have confirmed no material changes in AI deployment since last review
- Basis for each AI claim is documented in disclosure committee records
FAQ
Does the SEC require AI disclosure in the 10-K under a specific rule or form item? No dedicated AI disclosure rule or form item exists as of September 2026. AI disclosure is required when material under existing Regulation S-K Items 101 (Business), 105 (Risk Factors), and 303 (MD&A), plus Item 1C for AI-related cybersecurity risks under the 2023 cybersecurity rules. The materiality standard under Basic Inc. v. Levinson governs what must be disclosed.
What is AI washing and how does it create SEC liability? AI washing means making false or misleading statements about AI capabilities in public filings or investor communications. The SEC charged Delphia and Global Predictions in March 2024 under existing anti-fraud provisions (Securities Act Section 17(a), Exchange Act Section 10(b)/Rule 10b-5) for claiming AI capabilities they didn't have. No new rule was needed.
What language has the SEC flagged as insufficient in comment letters? Phrases like "extensive AI skill sets and machine learning capabilities" have been explicitly flagged. The staff demands companies explain what the AI actually does, in what business process, and with what effect. Approximately 61% of the 92 AI comment letters sent through October 2024 demanded greater specificity.
Will the rulemaking petition (File No. 4-882) change our 2026 obligations? No. The petition was filed in February 2026 and the Atkins SEC's deregulatory agenda makes near-term rulemaking unlikely. Your 2026 10-K obligations are governed by existing anti-fraud provisions and Regulation S-K materiality principles, not the petition.
How does AI disclosure interact with our Item 1C cybersecurity obligations? AI-related cybersecurity risks belong in Item 1C under the 2023 cybersecurity disclosure rules. An AI-enabled cyberattack may simultaneously trigger a Form 8-K Item 1.05 incident disclosure and require updates to your AI risk factor. Disclosure controls need to be designed to catch both triggers. See our Item 1.05 practitioner walkthrough for the four-business-day clock mechanics.
Should we add a standalone AI risk factor or integrate AI risks into existing categories? Either approach works if the disclosure is specific. A standalone AI risk factor makes the disclosure easier for staff to find and review. Integration into cybersecurity, operational, or regulatory risk factors can work if AI's contribution to each risk is clearly described. What doesn't work is a generic paragraph that reads the same regardless of how your company actually uses AI.
For teams managing AI use within the financial reporting and audit process itself, the AI audit trail requirements for SEC filers and AI model risk management framework cover the internal controls and documentation obligations that sit behind these disclosures.







