SEC Liability for AI-Generated Financial Disclosures: 2026 Enforcement Reality
If your team uses AI to draft MD&A, populate ESG metrics, or generate earnings release language, the SEC holds you to exactly the same standard as if a human wrote every word. There is no AI carve-out, no safe harbour, and no "the model did it" defence in current securities law.
This article is for CFOs, ESG teams, and compliance officers deciding right now whether to use AI in disclosure workflows, what controls to put around it, and how to brief the audit committee on the liability picture. It focuses on the risk most articles miss: not what you say about AI, but what happens when AI generates the disclosure itself and gets something wrong.
Key takeaway: Two distinct liability vectors exist. AI washing, making false claims about AI capabilities, is the one enforcement has targeted so far. Process liability, where an AI hallucination or stale data point ends up in a filed document, is the more immediate operational risk for finance teams. The SEC's existing anti-fraud rules cover both, fully.
What Securities Law Already Says About AI-Generated Disclosures
The foundational legal reality is simple: Section 10(b) of the Securities Exchange Act of 1934, Rule 10b-5, and Section 17(a) of the Securities Act of 1933 apply to every word in a filed document, regardless of who or what produced it. The issuer bears legal responsibility for accuracy. The AI vendor does not.
The SEC's Investor Advisory Committee confirmed this directly in May 2024: "If AI systems are used to make investment decisions or generate financial reports, there may be concerns about the transparency and interpretability of these systems. The SEC requires clear disclosure of material information to investors."
No new legislation is needed for the SEC to act. As the NYSBA analysis notes, three enforcement tools already exist: anti-fraud provisions, the Marketing Rule (Rule 206(4)-1), and the Investment Company Act's advertising rules. The machine that produced the content changes nothing about who is responsible for it.
The Two Liability Vectors CFOs Must Separate
Most commentary conflates two distinct risks. Separating them is essential for building the right controls.
| Liability Type | What It Covers | Enforcement Status |
|---|---|---|
| AI washing | False or inflated claims about AI capabilities in investor-facing materials | Actively enforced (March 2024 actions) |
| AI-output errors | AI hallucinations, stale data, or fabricated figures in the disclosure itself | Covered by existing anti-fraud rules; no enforcement action yet, but the legal exposure is identical |
AI Washing: The Enforcement Record
In March 2024, the SEC brought its first two AI-related enforcement actions against investment advisers Delphia (USA) Inc. and Global Predictions Inc. Both firms falsely claimed to use AI in their investment processes. Delphia paid $225,000 in civil penalties; Global Predictions paid $175,000. Combined: $400,000, charged under the Investment Advisers Act's anti-fraud provisions (Sections 206(2) and 206(4)) and the Marketing Rule.
AI washing takes several forms beyond outright fabrication, each capable of constituting a material misstatement under Rule 10b-5:
- Calling rule-based logic "machine learning"
- Showing back-tested AI performance while omitting real-world failures
- Omitting material AI risks such as algorithmic bias or model drift
- Rebranding traditional statistical analytics as AI
Over 40% of S&P 500 companies included AI-related risk disclosures in their 2023 Form 10-K filings, and AI mentions on earnings calls rose 77% in Q4 2023 alone, according to Alston & Bird's analysis. That volume of AI references, without corresponding specificity, is precisely what drew SEC comment-letter scrutiny through 2024 and 2025.
AI-Output Errors: The Process Liability Gap
This is the risk the top-ranking articles largely ignore, and the one most relevant to finance teams deploying AI today.
When an AI tool drafts your MD&A narrative and hallucinates a revenue figure, or aggregates ESG data and produces a metric that does not match the underlying records, the resulting misstatement in a filed document is treated identically to a human-authored error under Rule 10b-5. Former SEC Chair Gary Gensler stated this plainly: "AI hallucinations may pose problems for the brokers and advisers that regularly use AI to inform their investment decisions and may additionally threaten the stability of public markets."
The SEC's IAC also flagged a related concern: "AI could potentially be used to commit or conceal accounting fraud, such as by manipulating financial data or creating fake transactions." The Commission is thinking about AI not only as a disclosure subject but as a tool that could falsify financial statements, a concern that shapes how examiners will evaluate AI controls.
Shareholder litigation has already followed. Multiple securities class actions alleging AI-related disclosure fraud have survived motions to dismiss, with courts applying standard materiality and scienter analysis. The AI origin of the statement creates no new legal standard and no defence, per Alston & Bird's litigation review.
SOX Certifications: The CEO and CFO Personal Exposure
This is the angle almost no commentary addresses, and it matters enormously for signing officers.
Under SOX Sections 302 and 906, CEOs and CFOs certify that disclosure controls and procedures are effective and that the financial statements fairly present the company's financial condition. That certification does not distinguish between human-authored and AI-generated content. If AI tools are used in preparing financial statements without adequate human oversight, and AI-generated errors produce material misstatements, the certifying officers face personal exposure.
The certification question is not theoretical. It is the reason that "we used AI" is not a mitigating factor in an SEC enforcement investigation, it is a controls question. Did the disclosure controls and procedures, required under Rule 13a-15, cover the AI-generated content? If not, the SOX certification may itself be defective.
For practical guidance on building the review process that makes a SOX certification defensible when AI is involved, see Reviewing AI-Drafted Financial Commentary: A CFO's Process Guide.
The PCAOB Audit Dimension: A Second-Order Liability Path
Here is a liability pathway that practitioners rarely see discussed: the audit side.
The PCAOB's 2024 inspection priorities flag AI use in audit processes as a priority area. Auditors must evaluate whether AI tools used by management to prepare financial statements introduce new risks of material misstatement. If an auditor identifies inadequate controls over AI-generated financial data, the result could be a control deficiency finding, potentially a material weakness.
A material weakness finding itself triggers SEC disclosure obligations. So the liability chain runs: inadequate AI controls, auditor identifies control deficiency, material weakness disclosed, SEC scrutiny of the underlying disclosure controls. Companies that deploy AI in financial reporting without governance infrastructure are exposed to this second-order path even if no AI-generated error ever reaches a filed document.
For the full audit controls picture, see AI in Internal Audit 2026: A Practitioner Walkthrough and AI Journal Entry Testing and SOX 404 Controls.
The Proposed Predictive Analytics Rule: Status in 2026
The SEC proposed Rule 211(h) under the Investment Advisers Act in July 2023. The rule, formally titled "Conflicts of Interest Associated with the Use of Predictive Data Analytics by Broker-Dealers and Investment Advisers," would require firms to identify and eliminate or neutralise conflicts of interest embedded in AI and algorithmic tools used with retail investors.
As of October 2026, the rule has not been finalised. Chair Paul Atkins, confirmed in April 2025, has signalled a preference for principles-based over prescriptive AI regulation. At the SEC's Investor Advisory Committee meeting in December 2025, Atkins stated that "I believe that investors can rely on our current principles-based rules to inform them of how AI impacts companies" and cautioned against "prescriptive disclosure requirements for every 'new thing' that affects a business."
The practical effect: new AI-specific safe harbours are not coming in the near term. The proposed rule's underlying enforcement theory, that AI-embedded conflicts harm retail investors and are addressable under existing fiduciary and anti-fraud standards, is already being applied through existing law. Firms should not wait for a finalised rule to build controls; the exposure exists now.
What the SEC's Comment Letter Record Reveals
The SEC's Division of Corporation Finance identified AI disclosures as a formal review priority for 2024 filings. Director Eric Gerding stated the Division would scrutinise whether companies describing AI opportunities and risks are providing company-specific, material information rather than generic boilerplate.
An Orrick analysis of 92 SEC AI-related comment letters sent to 56 companies between 2021 and October 2024 found:
- Approximately 61% of comments demanded greater specificity about how AI is or will be used
- Approximately 30% flagged unsupported or unqualified AI capability claims
- Approximately 10% raised materiality threshold questions
The dominant issue is vagueness. Phrases like "extensive AI skill sets and machine learning capabilities" draw comment letters. The staff wants to know what the AI actually does, in which business process, and with what effect. Critically, the staff has also asked companies to disclose "the liability that you assume, if any, if your AI technology incorrectly evaluates" outcomes such as creditworthiness. That is a specific disclosure item, not a general prompt, and it applies directly to AI used in financial reporting processes.
For a section-by-section guide to what belongs in your 10-K, see SEC AI Disclosure Requirements for the 10-K: 2026 Practitioner Guide.
The ESG Disclosure Intersection
For companies using AI to aggregate ESG data or draft sustainability disclosures, the liability picture extends beyond the SEC.
The ISSB's IFRS S1 and S2 standards, effective for reporting periods beginning January 2024, require companies to disclose material sustainability-related risks and opportunities with the same rigour as financial disclosures. For SEC-registered foreign private issuers, AI-generated errors in IFRS S1/S2 reports carry the same materiality and accuracy obligations as financial statement errors, and potential SEC liability as well.
The parallel risk is real: an AI tool that aggregates Scope 3 emissions data and produces a figure that does not match the underlying supply chain records creates the same exposure as an AI tool that misquotes a revenue number in MD&A. The SEC's cybersecurity disclosure rules (effective December 2023) add another dimension: an AI system used in financial reporting that is compromised could trigger both Form 8-K Item 1.05 cybersecurity disclosure obligations and securities fraud liability simultaneously.
For the full ESG automation compliance picture, see AI ESG Reporting Automation: A 2026 Practitioner Walkthrough.
Board and Audit Committee Oversight: What the SEC Expects
At the December 2025 IAC meeting, the Committee recommended that the Commission require issuers to disclose board oversight mechanisms for AI deployment. Chair Atkins did not endorse mandatory rules, but the Committee's recommendation itself signals what sophisticated governance looks like to regulators and institutional investors.
Practically, audit committees should be asking management:
- Which AI tools are used in the preparation of financial disclosures, and at what stage?
- What human review and sign-off process exists before AI-generated content enters a filed document?
- What audit trail documents the AI tool version, prompts used, and reviewer identity?
- Are existing disclosure controls and procedures (DC&P) under SOX formally scoped to cover AI-generated content?
- Has outside counsel reviewed AI-related risk factors for specificity before the next annual filing?
For a full board briefing framework, see AI Board Reporting and Audit Committee Oversight in 2026.
The Vendor Contract Question: Who Actually Bears the Risk?
Practitioners ask this constantly, and no top-ranking article answers it: if an AI vendor's tool produces a hallucination that ends up in a 10-K, does the vendor bear any liability?
Under current securities law, almost certainly not. The issuer filed the document. The issuer's CEO and CFO certified it. The AI vendor's terms of service almost universally disclaim liability for output accuracy. Vendor indemnification provisions, where they exist, typically cover intellectual property claims, not regulatory enforcement actions.
This does not mean vendor contracts are irrelevant. Contractual provisions governing data retention, model version documentation, and audit log access are critical for building the evidence package an SEC examiner or enforcement investigation will demand. But the liability shield the vendor contract provides is narrow. The issuer owns the disclosure, and the issuer owns the risk.
A Practical Controls Checklist for AI-Generated Disclosure Content
The "reasonable basis" and "adequate procedures" standards that constitute mitigating factors in an SEC enforcement action require demonstrable process, not just policy. Here is what that process looks like in practice:
- Scope your DC&P to AI explicitly. Amend your disclosure controls and procedures documentation to confirm that AI-generated content is subject to the same review and sign-off requirements as human-authored content.
- Maintain an AI tool registry for disclosure workflows. Document which tools, model versions, and configurations are used in any stage of disclosure preparation.
- Log prompts and outputs. Retain the prompts used to generate disclosure content, the raw AI output, and the version of the document after human review. This is your audit trail.
- Require named human sign-off before any AI-generated content enters a draft filing. The reviewer should have the subject-matter expertise to catch errors, not just format the output.
- Run a fact-check pass against source data. Every AI-generated figure, metric, or factual claim should be traced to the underlying record before the draft is circulated.
- Write company-specific AI risk factors. Generic language draws comment letters. Name the specific AI tools used, the specific business processes they affect, and the specific failure modes that could harm the company.
- Brief the audit committee at least annually on AI tools used in financial reporting, the controls in place, and any incidents where AI-generated errors were caught before filing.
- Assess materiality of AI errors caught pre-filing. If an AI tool produces a material error that is caught and corrected, document the correction and assess whether the near-miss itself is disclosable as a control deficiency.
For the audit trail documentation requirements in detail, see AI Audit Trail Requirements for SEC Filers: 2026 Practitioner Walkthrough.
FAQ
Does disclosing that we use AI to draft disclosures protect us from SEC enforcement? No. Disclosure of AI use is necessary but not sufficient. The disclosure must be accurate and specific, and the underlying content must still be accurate. A correct disclosure about AI use does not immunise an AI-generated misstatement in the same filing.
Can shareholders sue us for AI-generated misstatements the same way they can for human-authored ones? Yes. Courts have applied standard materiality and scienter analysis to AI-related misstatements. Multiple securities class actions have survived motions to dismiss. The AI origin of the statement creates no new legal standard or defence.
What is the difference between AI washing and process liability for AI-generated errors? AI washing is making false or inflated claims about your AI capabilities to investors. Process liability arises when AI tools generate the disclosure content itself and produce errors. The first is about what you say about AI; the second is about what AI says on your behalf. Both are covered by existing anti-fraud rules.
Does the proposed predictive analytics rule apply to us? If you are a registered investment adviser or broker-dealer, the proposed Rule 211(h) is relevant. As of October 2026, it has not been finalised. But the enforcement theory it embodies, that AI-embedded conflicts harm retail investors, is already being applied under existing fiduciary and anti-fraud standards.
What does the SEC expect from AI risk factors in a 10-K? Company-specific, material information. The staff has flagged generic boilerplate in 61% of AI-related comment letters. Name the tools, the processes, the failure modes, and the liability the company assumes if the AI produces incorrect outputs.
Are our existing SOX disclosure controls sufficient to cover AI-generated content? Only if they are explicitly scoped to cover it. Most DC&P documentation predates AI deployment in disclosure workflows. Review and amend your controls documentation to confirm AI-generated content is within scope before your next annual certification.







