Batmandir · The Circle Full access to theatres, museums & exhibitions. S2 · ongoing membership, without a Founder’s seat. Explore membership →

In 2023, 12% of S&P 500 Companies Told the SEC That AI Was a Business Risk. In 2025, 72% Did.

5 min read · 1,077 words

Every S&P 500 company’s annual report to the Securities and Exchange Commission includes a “Risk Factors” section — a legally required list of the things a company itself believes could materially hurt its financial condition or future performance. In 2023, just 12% of S&P 500 firms named artificial intelligence as one of those risks. By 2024, that had jumped to 58%. By 2025, it reached 72%, according to research from The Conference Board, published through the Harvard Law School Forum on Corporate Governance. Over roughly the same two years that AI reshaped product roadmaps and earnings calls, it also became one of the fastest-normalizing risk disclosures in the history of the modern 10-K.

Top AI Risk Categories Cited in 2025 S&P 500 10-Ks

Share of S&P 500 firms citing each risk category. Hover for company counts.

Batmandir · Founders A numbered seat at the table. S3 · The Founders Club — 161 seats per location. By invitation. Explore membership →

What “risk factor” actually means, legally

A 10-K risk factor isn’t a company complaining or hedging casually — it’s a specific, SEC-mandated disclosure with legal weight, meant to inform investors of anything that could materially affect the business. Companies have genuine legal incentive to under-disclose rather than over-disclose, since naming something as a risk in a public filing can itself become evidence in later shareholder litigation if that risk materializes and investors argue the company didn’t take it seriously enough beforehand. That makes the jump from 12% to 72% harder to dismiss as boilerplate — it reflects a genuine shift in how corporate legal and disclosure teams have come to view AI: not as an optional forward-looking mention, but as something close to standard practice across the index. Still, more than a quarter of S&P 500 firms made no explicit AI risk disclosure at all in 2025, either because their AI exposure genuinely is limited, because it’s captured inside broader risk categories rather than called out separately, or because their disclosure practices simply haven’t caught up to their actual AI use yet.

Reputational risk, not technical risk, tops the list

The single most commonly cited AI risk category in 2025 wasn’t a technical concern about model accuracy or infrastructure — it was reputational risk, disclosed by 38% of S&P 500 firms, more than any other category. Within that group, the research breaks out specific concerns by how many companies raised them: 45 companies specifically warned that AI projects failing to meet promised outcomes could damage their reputation, 42 flagged consumer-facing AI applications (chatbots, recommendation engines, customer service tools) as a particular exposure point, 24 cited privacy and data-handling risks, and 11 explicitly named AI “hallucinations” — factually wrong or fabricated AI-generated output — as a named risk to brand credibility. Cybersecurity risk tied to AI held steady at 20% of firms in both 2024 and 2025, described in the research as AI functioning as a “force multiplier” for attackers — mentioned by 40 companies specifically — as well as a new category of vendor and third-party risk, cited by 18 companies concerned about dependence on cloud and AI infrastructure providers they don’t control.

Which industries are disclosing, and why

The surge in AI risk disclosures wasn’t evenly distributed across the S&P 500’s eleven sectors — it concentrated specifically in financials, health care, industrials, IT, and consumer discretionary. The pattern maps onto exposure type rather than simply company size or prominence: financials and health care face regulatory and reputational risk tied to sensitive data and fairness in algorithmic decision-making (credit scoring, underwriting, diagnostics); industrials are scaling automation and robotics with direct safety and liability implications; IT companies are, unsurprisingly, at the literal center of AI development and supply; and consumer discretionary firms carry direct brand exposure any time an AI tool interacts with an actual customer. Legal and regulatory risk specifically was cited by 41 companies grappling with the EU’s AI Act, which began phasing in obligations in 2025 and 2026, alongside unresolved uncertainty over how the FTC and Consumer Financial Protection Bureau will apply existing U.S. consumer-protection and privacy law to AI systems that didn’t exist when those laws were written.

The risk that’s barely shown up in filings yet

One category the research specifically flags as conspicuously absent from 2025 filings: agentic AI, meaning autonomous, goal-directed systems that can take actions with limited direct human oversight, as distinct from the chatbot- and content-generation tools that dominate current disclosures. The report describes agentic systems as “largely absent from current filings” despite advancing rapidly “from research labs to commercial use,” and specifically predicts that their “unpredictability, diminished human oversight, and unclear liability may create some of the most significant governance and reputational challenges in the next disclosure cycle.” If that prediction holds, next year’s filing season would be the point at which the AI risk-disclosure trend either plateaus around this year’s roughly three-quarters of the index, or takes another leg up as a genuinely new category of AI risk — not just more companies catching up on describing the AI risk they already have.

What we did

All figures in this article — the 12%/58%/72% year-over-year disclosure rates, the 38% reputational-risk and 20% cybersecurity-risk category shares, and every sub-category company count (45 companies on implementation risk, 42 on consumer-facing AI, 41 on regulatory uncertainty, and so on) — come directly from The Conference Board’s report “AI Risk Disclosures in the S&P 500,” authored by principal researcher Andrew Jones and published via the Harvard Law School Forum on Corporate Governance on October 15, 2025. That research is itself based on a systematic review of actual Form 10-K filings across the S&P 500 for filing years 2023 through 2025, conducted using The Conference Board’s ESGAUGE benchmarking platform — a primary analysis of SEC filings, not a survey or a secondhand estimate. We read the full report directly, including its category-by-category company counts, rather than relying on secondary news coverage summarizing only the topline percentage. Where the source reported a raw company count rather than a percentage (legal/regulatory risk at 41 companies, intellectual property at 24, standalone privacy risk at 13), we calculated the percentage of the 500-company index ourselves (8.2%, 4.8%, and 2.6% respectively) for the interactive chart, rather than treating those as directly-stated topline figures the way the 72%, 38%, and 20% numbers are.

Share this story