Back
Information Technology

Guardrail Technologies Releases New Benchmark Report Tracking How the S&P 500 Discloses AI Cybersecurity Risk

AQi

FOR IMMEDIATE RELEASE

Guardrail Technologies Releases New Benchmark Report Tracking How the S&P 500 Discloses AI Cybersecurity Risk

New research finds 97 percent of S&P 500 companies discuss AI in their annual filings, while fewer than 4 in 100 describe a governed process for managing its cyber risk

PERTH, Australia (Aug. 31st, 2026)  Guardrail Technologies, a leading provider of AI security and governance software for enterprises building with AI, today released The AI Cyber-Disclosure Gap Report, the first study to measure how S&P 500 companies describe their use of artificial intelligence against how they document the management of its cybersecurity risk.

The first of its kind, the report is intended to become an ongoing benchmark, revisited regularly as company filings are updated and disclosure practices evolve.

Guardrail Technologies independently reviewed all 503 Form 10-K filings currently on record for S&P 500 companies against the US Securities and Exchange Commission’s Item 1C cybersecurity disclosure requirement.

The results were stark and consistent: 97 percent of companies mention AI somewhere in their annual report, but only about 1 in 5 document a process for managing its cyber risk, and fewer than 4 in 100 describe a governed one. That represents a 77-point gap between what companies say about AI and what they disclose about how they manage it, making it one of the widest disclosure gaps ever measured in corporate cybersecurity reporting.

While the report examines US-listed companies, its findings have direct relevance to Australia, where many S&P 500 companies maintain substantial operations, customer bases, supply chains and commercial relationships.

It is estimated that between 55 and 70 percent of S&P 500 companies have a substantial presence in Australia, meaning their AI governance and cybersecurity practices are not confined to the United States. These practices may also affect Australian customers, employees, business partners, financial institutions and supply chains.

In Australia, Guardrail Technologies works in partnership with AQi, managing Australian market presence and supports local organisations seeking to strengthen AI security, governance and risk management.

“Nearly every company in the S&P 500 says AI matters to their business, but almost none can prove how they’re keeping it under control,” said T.J. Marlin, founder and CEO of Guardrail Technologies.

“A policy written after a breach carries no weight with an investigator, and a control that only lived in someone’s memory is no control at all. This report shows how few companies could survive that kind of scrutiny today.”

The report provides an important benchmark for Australian boards and executives as organisations accelerate their adoption of generative AI, automated decision-making and other AI-enabled systems.

Discussing AI adoption is not the same as demonstrating that an organisation has documented, governed and auditable processes for managing its risks.

As Australian businesses increase their use of AI, boards must understand who is accountable for AI, how systems and tools are approved, how risks are assessed, what controls are applied and how incidents are detected, reported and managed.

These issues are particularly important for Australian organisations operating in regulated or data-sensitive industries, as well as companies responsible for critical infrastructure, essential services and sensitive customer information.

Even the most heavily regulated sectors financial services, healthcare, utilities, energy and real estate do not close the disclosure gap identified by Guardrail Technologies.

The 218 companies in the report, document an AI-specific process only slightly more often than the rest of the index: 18 percent compared with 15 percent under the report’s more generous assessment criteria.

A sharper split appears within the group. Utilities, energy and real estate companies, whose regulators oversee physical infrastructure, describe AI as a specific and actively managed cyber risk in approximately 70 percent of filings.

Financial services and healthcare companies, whose regulators oversee data, do so in only 37 to 48 percent of filings, despite discussing AI just as heavily as other companies in the index.

For Australian organisations, the findings demonstrate that operating within a highly regulated sector does not automatically mean a business has mature or adequately documented AI governance.

Guardrail Technologies plans to repeat the analysis regularly to track whether disclosure practices change as regulatory expectations develop and to give boards, insurers and investors a consistent benchmark rather than a one-time snapshot.

“Every board, public or private, should treat this AI security disclosure gap as urgent,” Marlin added.

“If you’re on a public company board, look at what you’re already saying out loud about AI and make sure a documented, governed process backs it up. The alternative won’t hold up.”

 

A Board Diagnostic for any public company

Alongside the report, Guardrail Technologies is launching a Board Diagnostic for any publicly traded company, including companies operating in the Australian market.

Using the same framework applied to all 503 filings in the study, Guardrail Technologies reviews a company’s most recent cybersecurity disclosure and returns one of three verdicts: Green for a documented and governed AI risk process, Amber for a partial process, or Red where no process is documented.

It is the same signal Guardrail Technologies already uses in AI Traffic Light™ to flag code and agent behaviour, now applied to corporate disclosure itself.

The verdict is accompanied by an executive insights report showing exactly where the disclosure falls short, what a stronger disclosure would say and how the company compares with its peers. The report is designed to be taken directly to the board, risk committee or audit committee.

Guardrail Technologies has identified six critical questions every board should be able to answer about its organisation’s AI lifecycle. The Board Diagnostic is designed to guide boards towards the deeper questions surrounding AI and help identify the governance, documentation and accountability issues that need to be addressed.

Australian companies will be able to access and discuss the Board Diagnostic and Guardrail Technologies’ broader AI security and governance solutions through its Australian partner, AQi.

Through the partnership, AQi is bringing Guardrail Technologies’ global AI security and governance insights to the Australian market and supporting local organisations to strengthen their approach to responsible AI adoption.

Companies interested in requesting a Board Diagnostic can do so at [insert link].

The full AI Cyber-Disclosure Gap Report, including sector-level findings is available at http://guardrail.tech/the-ai-cyber-disclosure-gap/

 

#####

 

 


About us:

About Guardrail Technologies

Guardrail Technologies is a leading provider of independent AI security and behavioural governance software for enterprises and the people building and deploying with AI.

The company delivers defence in depth throughout the AI lifecycle, from the point of creation through operation, detection and incident response, through two core products: AI Traffic Light™, which scans AI-generated code and verifies the people behind it, and AI Command Center™, which provides centralised governance, behavioural controls and compliance audit trails for enterprise AI operationalisation.

Founded in Q2 2025 and headquartered in Park City, Utah, Guardrail Technologies holds three issued patents, with six additional patents pending.

In Australia, Guardrail Technologies works in partnership with AQi, which manages its presence in the Australian market and supports the delivery of its AI security and governance solutions to Australian organisations.

For more information, visit www.guardrail.tech.

 

About AQi

AQi is Guardrail Technologies’ partner company in Australia and manages Guardrail Technologies’ Australian market presence.

AQi works with Australian businesses, boards and organisations to support the secure, governed and responsible adoption of artificial intelligence. Through its partnership with Guardrail Technologies, AQi provides Australian organisations with access to independent AI security, behavioural governance and enterprise risk-management solutions.

 


Contact details:

Media Contact:
Sandra Tricoli

[email protected]

0415 199 861