The AI Disclosure Problem Isn't Your Model. It's Your Description of It.
Nearly every securities matter involving artificial intelligence has turned on the same thing, and it is not model quality. It is the distance between what a company told investors about its AI and what the company actually runs. That distance is created by marketing, ratified by filings, and discovered by someone with a screenshot.
Why AI Never Got Its Own Disclosure Rule
Companies keep waiting for a definitive artificial intelligence disclosure regulation the way they waited for the cybersecurity incident rules. It is a reasonable expectation and a misleading one, because the securities framework already handles this category without amendment. Material risks belong in risk factors. Statements made to investors cannot be materially false or misleading, including by omission. Management is expected to maintain controls sufficient to know what it is asserting. None of those obligations care whether the subject is a supply chain, a data center or a model.
The practical consequence is that the trigger date has already passed. A company that began describing itself as AI-driven in an earnings call two years ago has been inside this framework since that call. There is no grace period pending guidance, and waiting for a rule mostly means accumulating statements that were never reviewed against the underlying facts.
The Enforcement Pattern: Description, Not Capability
The cases that have emerged share a structure. A company describes a capability in elevated terms — proprietary artificial intelligence, autonomous decisioning, a model trained on a unique corpus — and the underlying operation turns out to be a general-purpose API call, a rules engine, or a team of people doing the work by hand. The regulator does not argue that the company should have built something better. It argues that the company said something untrue.
That framing matters because it removes the defense most executives reach for first. "Everyone in our sector describes it that way" is not responsive to a claim that a specific sentence was false. Neither is "the roadmap says we will build it," which converts a present-tense capability claim into an admission that the capability did not exist when the claim was made.
A useful internal test: for every AI claim on your public surfaces, can someone name the system that performs it and produce evidence it ran in production during the period the claim was live? If the answer requires a caveat, the claim needs the caveat too.
Risk Factors That Do Nothing
The most common AI risk factor in circulation says roughly that artificial intelligence is subject to rapidly evolving regulation and that new requirements could increase costs. It is true, it is universal, and it protects almost nothing, because boilerplate warning of a hypothetical does not insulate a company from a risk that had already materialized when the language was filed.
A risk factor earns its place by being specific to the business. Which parts of revenue depend on a model performing? Which vendors supply that model, and what happens if pricing, availability or terms change on short notice? Are AI systems involved in decisions that are themselves regulated — credit, employment, insurance, health? Is training data licensed, scraped, customer-supplied or of uncertain provenance, and what is the exposure if that changes? Those questions produce disclosure that describes an actual company.
- Dependency risk: concentration on one model provider, with switching cost and quality variance if you migrate.
- Regulated-decision risk: AI touching outcomes that carry their own statutory duties, which converts a product issue into a compliance issue.
- Provenance risk: training or retrieval data whose rights are unclear, including customer data used beyond what the contract allows.
- Claim risk: the company's own public statements about AI, which is the exposure most filers forget to disclose.
Board Oversight Is a Record, Not a Result
Oversight claims fail on documentation far more often than on judgment. The recurring allegation is not that directors made a bad call about artificial intelligence — it is that no system existed for the board to receive information about it, so no call was ever made. That is why the remedy is unglamorous: assign the responsibility somewhere specific, put it on a recurring agenda, require management reporting that includes incidents and failures, and let the minutes reflect that the conversation happened.
Where it sits is less important than that it sits somewhere. Audit committees often take it because they already own risk and controls; some boards give it to technology or risk committees; smaller boards keep it at full-board level. What does not work is the arrangement where AI is discussed enthusiastically in strategy sessions and never appears in any oversight record, because that pattern documents interest without documenting supervision.
Your Public Pages Are Part of the Filing Record
Disclosure teams review the document. Almost nobody reviews the website, and the website is where the aggressive language lives. Product pages, solution briefs, customer stories, press releases and investor-relations content are public, dated and archived by third parties. When they describe capabilities in stronger terms than the filings do, the inconsistency is available to anyone before a single discovery request is served.
The gap usually opens without anyone deciding to open it. Marketing writes to differentiate, so "assisted by machine learning" becomes "AI-powered" and then "autonomous." Legal writes to be accurate, so the filing says the system supports human reviewers. Both documents publish. Nobody reads them together until someone adverse does.
Practical control: run a claim inventory across every public page before each reporting cycle. Extract the verbs — detects, decides, predicts, automates, learns — and confirm each one against a system that exists. This is the cheapest securities-hygiene exercise available and the one most companies have never run.
Disclosure Controls Have to Reach the Model
Certifying officers attest that disclosure controls are effective. If artificial intelligence materially affects operations, those controls have to be capable of surfacing AI-related developments — a significant model change, a serious output failure, the loss of a provider, a regulatory inquiry — to the people who sign. In many companies that path does not exist, because model changes are handled entirely inside engineering and never cross into the disclosure process.
Building the path is mundane work: define what counts as a reportable AI event, name who escalates it, connect that escalation to the disclosure committee, and keep enough record to show the route was used. The absence of that route is what turns a single product incident into a controls finding.
What to Do in the Next Quarter
- Inventory every public AI claim across the marketing site, releases and investor materials, with the date each went live.
- Map each claim to the system that performs it and note where the description is stronger than the implementation.
- Rewrite the AI risk factor so it names dependencies, regulated decisions and data provenance instead of reciting that regulation is evolving.
- Assign board-level oversight explicitly and put it on a recurring agenda with management reporting that includes failures.
- Define reportable AI events and wire the escalation route into the disclosure process before you need it.
Frequently Asked Questions
We're pre-IPO. Does any of this apply yet?
The antifraud rules apply to statements made in raising capital regardless of listing status, so the claim-accuracy question is live now. The structural pieces — risk factors, oversight records, disclosure controls — are things underwriters and acquirers will reconstruct backwards. Building them late is possible; explaining why every prior year has no record is harder.
Our AI is a thin layer over a vendor model. Is saying 'our AI' misleading?
Not inherently. Building on a third-party foundation is ordinary and describing the product as yours is normal commercial speech. The problem starts with claims of proprietary models, unique training or performance attributable to your own technology when the underlying capability is a general-purpose service anyone can buy. Describe the layer you built accurately and the vendor relationship stops being a liability.
Should we disclose a model failure that had no financial impact?
Materiality is the test, and it is not purely quantitative — a failure in a regulated decision path, or one that reveals a controls weakness, can matter at a size that never shows up in revenue. The more useful question is whether an investor would consider the fact significant in the total mix. Decide it deliberately and record the reasoning, because an undocumented judgment call is the one that ages badly.
Does having an AI governance policy help if we don't follow it?
It hurts. An unfollowed policy establishes the standard you set for yourself and then documents your departure from it. Either operate the policy — with evidence that reviews happened — or write one you can actually run. A short program that is genuinely followed beats a comprehensive framework that exists only as a document.
Who should own the AI claim review — legal, marketing or IR?
Marketing produces the claims, legal assesses them and investor relations lives with the consequences, so all three have to touch it, but one of them has to own the calendar. In practice it works best inside the existing disclosure committee cadence, because that body already has authority to hold publication and a habit of documenting decisions.
How far back should we review old claims?
Far enough to cover the statements still reachable. Archived pages, old releases and prior filings remain available long after they are removed from navigation, and a claim from three years ago can still be produced side by side with today's description. Start with material claims still live on the site, then work backwards through releases and filings.
Start Where the Claims Actually Live
The filings get reviewed by counsel. The website usually does not, and it is where the strongest artificial intelligence language sits — on product pages, solution briefs and customer stories that publish without a disclosure review.
See what your site currently says. Run a free scan and pull every public page that makes a claim about what your AI does.