>_ ANALYSIS
AI disclosure is rising, but most of it still isn’t decision-grade
## The gap is no longer whether companies mention AI The more consequential shift in Bart Jaworski’s AI Risk Observatory paper is not the rise in AI disclosure itself, but the size of the gap between mention and substance. On the paper’s own classification, 41.2% of 2025 reports mention AI as a risk, yet only 4.3% cont
The gap is no longer whether companies mention AI
The more consequential shift in Bart Jaworski’s AI Risk Observatory paper is not the rise in AI disclosure itself, but the size of the gap between mention and substance. On the paper’s own classification, 41.2% of 2025 reports mention AI as a risk, yet only 4.3% contain what it counts as substantive AI-risk disclosure. That matters because a filing that names AI without explaining exposure, dependencies, or mitigation may satisfy formal disclosure habits without giving boards, investors, or regulators much to act on.
The paper’s evidence points to a second split that is easy to miss if you only track headline prevalence: disclosure is uneven by market segment and sector. AIM reports disclose AI risk far less often than Main Market reports, and Energy and Data Infrastructure lag the rest of the Critical National Infrastructure sectors. Those differences are not just cosmetic. If AI-related operational dependence is emerging unevenly across sectors, then uneven disclosure means the places with the least visible reporting may be exactly where outside readers need the most clarity.
Why the pattern probably exists
The simplest reading is not that some sectors are uniquely candid and others uniquely evasive, but that disclosure practices still lag behind actual AI use. The paper notes that AI adoption disclosure rose alongside risk disclosure, and named vendors cluster around a small set of large providers. That suggests companies are beginning to recognize AI as a board-level topic, but many are still describing it in broad terms rather than turning it into a concrete risk register item.
A plausible alternative explanation is that some sectors genuinely have lower AI exposure, so they need less AI-specific disclosure. The paper partially supports that in Energy, which is low on adoption, vendor mention, and AI risk disclosure. But Data Infrastructure complicates the story: it sits near the middle on adoption and vendor mentions while still rarely discussing AI as a risk. That weakens the idea that low risk disclosure is simply a mirror of low AI use. It points instead to a second-order problem: firms may be adopting AI without translating that adoption into language about risk.
What the evidence does and does not show
The paper’s own method is useful, but it is still a disclosure study, not a direct audit of operational risk. The authors validate their classification pipeline against human-annotated passages and use a substantiveness framework, but that framework is theirs, not an externally standardized benchmark. So the cleanest conclusion is narrow: annual reports appear to be a usable signal for tracking how companies talk about AI risk, but not a complete signal for how exposed they actually are.
That limitation matters. The near-absence of harm disclosures — seven reports across the full corpus — does not tell us that realized harm is rare; it tells us annual reports are a poor instrument for capturing it. The paper is strongest when treated as a map of disclosure quality, not as a census of AI incidents.
The practical implication
For readers who rely on corporate filings, the implication is straightforward: count less, read more carefully. A rising share of AI mentions can create the illusion of better transparency, but the more important question is whether a company explains where AI enters operations, what failure modes it creates, and whether those risks are specific to the business rather than generic boilerplate.
For regulators and investors, the useful test is whether future filings begin to show entity-specific AI risks in the sectors where adoption is already visible but disclosure remains thin. If Data Infrastructure continues to report meaningful adoption without corresponding risk detail, the case for more prescriptive disclosure guidance grows stronger. If substantive disclosure rises faster than simple mention rates, then the current gap may be closing. The observable signal to watch is whether sector- and segment-level filings start naming concrete AI dependencies, not just AI itself.
Source: https://arxiv.org/abs/2610.02281
