The AI cyber-disclosure gap as adoption is racing ahead of governance
97% of S&P 500 companies mention AI in their annual filings, but only around 1 in 5 document a process for managing AI-related cyber risk.
Even more striking: fewer than 4% describe a genuinely governed process with clear accountability and controls.
Guardrail Technologies found a 77-percentage-point gap between talking about AI and demonstrating how its cybersecurity risks are actually managed.
Even heavily regulated industries show significant shortcomings—proof that regulation alone does not guarantee mature AI governance.
The message for boards is clear: AI governance must become documented, accountable and auditable, not just discussed.
Read nationaltribune.com.au article for more information.

