Disclosure · 10 filers

Artificial Intelligence Risk

10 companies wrote this into a filing in the last 14 days, up from 4. Below: which of them, and what the corpus says they now owe.

Data measured , page built 22 September 2026 at 16:18 UTC.

Accelerating

10 companies against 4, a rise of 150%.

10filers, current period
4the period before
2controls it touches
2frameworks
first appears Dec 2023 2008 2026 10 filings in the busiest month
Artificial Intelligence Risk in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
Companies disclosing it 10 wrote this into a filing with the SEC
What it obligates 2 controls across 2 frameworks whose text speaks to it
Employers hiring for it 28 open US roles name it, and the ones below are hiring now

The long view, in annual and quarterly filings

A 10-K or 10-Q is a periodic report, so this counts how often the phrase appears in routine annual and quarterly reporting. It moves far more slowly and the numbers are larger. Every month since 2008. The last point is the current month and is still filling, so it always looks lower than it will be.

 
0510
2008 peak 10 in February 2026 2026

Who disclosed it

From SEC full-text search over 8-K filings. Every row links to the filing itself.

CompanyFormFiled
SUI Group Holdings Ltd. SUIG8-K2026-08-06filing
GORMAN RUPP CO GRC8-K2026-07-24filing
TFS Financial CORP TFSL10-Q2026-08-06filing
McKinley Acquisition Corp8-K2026-08-05filing
HUNTINGTON BANCSHARES INC /MD/10-Q2026-07-28filing
DocGo Inc. DCGO8-K2026-08-17filing
GOLDMAN SACHS GROUP INC10-Q2026-08-03filing
5E Advanced Materials, Inc.10-K2026-09-17filing
ADI GLOBAL DISTRIBUTION INC. ADIG8-K2026-08-04filing

The full search on EDGAR

Which industries file it

Companies grouped by the industry classification on their own filing. A count, not a survey.

IndustryCompanies
Banking4
Insurance4
Industrial machinery2
Not classified2
Chemicals and pharmaceuticals2
Holding and investment offices1
Securities and investment1
Transport and logistics1
Mining and extraction1
Hotels and personal services1

What it obligates

Our corpus holds 2 controls across 2 frameworks whose text speaks to this. Not a judgement: these controls say so, and each is one lookup from its source document. Ordered by how much each framework has to say about it, so the one that will cost you the most work is first. Every name opens that framework in the corpus.

FrameworkControls
SIG (Shared Assessments) verified
International
1
NIST AI 600-1: Generative AI Profile verified
United States
1

What an auditor will ask you to produce

The artefacts named on those controls, most frequently cited first.

How it usually fails

Recorded when each control was verified against its source. This is where programmes that think they are covered turn out not to be.

ISO/IEC 42001:2023 AI Management System Evidence & Implementation Kit

79 controls sit behind ISO/IEC 42001:2023, and this is the documentation set for them: an adopt-ready artifact per control, and the evidence an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

ISO/IEC 42001:2023 NIST SP 800-53 Rev 5245 shared controlsSOC 2201 shared controlsNIST Cybersecurity Framework 2.0180 shared controlsISO 27002:2022160 shared controlsISO 27001:2022157 shared controlsISO/IEC 38500:2024142 shared controlsPCI DSS 4.0138 shared controlsEU AI Act112 shared controlsNIST AI Risk Management Framewor…68 shared controlsCIS Controls v864 shared controls
ISO/IEC 42001:2023 holds 79 controls. They appear again inside 129 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.
79If you already run ISO/IEC 42001:2023, that is the 79 controls behind this disclosure, already evidenced.
229And ISO 27001:2022 is not a separate programme. 229 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
228And ISO/IEC 38500:2024 is not a separate programme. 228 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
160And ISO 27002:2022 is not a separate programme. 160 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

Run as two programmes

308 controls

ISO/IEC 42001:2023 and ISO 27001:2022 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

229 already done

229 of ISO 27001:2022's controls are controls you evidenced for ISO/IEC 42001:2023. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

first appears Dec 2023 2008 2026 10 filings in the busiest month
Artificial Intelligence Risk in 10-K and 10-Q filings, by month. The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.

What this actually means

Why now
10 public companies wrote this into an 8-K in the last seven days, 150% more than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
Who already cares
28 open US roles name this work today, which suggests increased attention to it beyond what any filing says. A job advertisement clears a budget holder and a filing clears legal, so the two answer to different people. We have not measured which moves first, only that both are moving.
What comes into scope
Once the phrase is on the record it maps to obligations within ISO/IEC 42001:2023, NIST AI Risk Management Framework (AI RMF 1.0), ISO/IEC 23894:2023. 255 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
Who is quietly ahead
Anyone already running ISO/IEC 42001:2023 has done 229 of the controls that carry ISO 27001:2022 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.

What this obligates

The instruments in our corpus that govern this disclosure, and how many controls sit behind each. This is not a filing count. It is what applies once a company has written the phrase down.

4 frameworks, 255 controls between them.

ISO/IEC 42001:2023 NIST SP 800-53 Rev 5245 shared controlsSOC 2201 shared controlsNIST Cybersecurity Framework 2.0180 shared controlsISO 27002:2022160 shared controlsISO 27001:2022157 shared controlsISO/IEC 38500:2024142 shared controlsPCI DSS 4.0138 shared controlsEU AI Act112 shared controlsNIST AI Risk Management Framewor…68 shared controlsCIS Controls v864 shared controls
ISO/IEC 42001:2023 holds 79 controls. They appear again inside 129 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.

What closing it also moves

The same controls appear in other frameworks through mappings held in our corpus. Work done here is already progress there. This is the part that is not in EDGAR and not in any public dataset: it comes from mappings built and verified by hand, control by control.

ISO 27001:2022229
ISO/IEC 38500:2024228
ISO 27002:2022160
ISO 22301:201960
ISO 9001:201546
ISO 27701:201944
ISO 31000:201844
ISO 22000:201842

Counted as controls reached through cross-framework mappings. It measures overlap of work, not compliance with the named framework.

Run as two programmes

308 controls

ISO/IEC 42001:2023 and ISO 27001:2022 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

229 already done

229 of ISO 27001:2022's controls are controls you evidenced for ISO/IEC 42001:2023. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

79If you already run ISO/IEC 42001:2023, that is the 79 controls behind this disclosure, already evidenced.
229And ISO 27001:2022 is not a separate programme. 229 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
228And ISO/IEC 38500:2024 is not a separate programme. 228 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
160And ISO 27002:2022 is not a separate programme. 160 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

If that number surprised you, the same measurement across every topic we track:
What changed this week →

This is what it looks like when the same failure is named by standards bodies who never spoke to each other:
How compliance programmes fail →

And the companies that have already written this into a filing:
Artificial Intelligence Risk filers →

Tell me when Artificial Intelligence Risk files something new

One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

Where this comes from

The left half is public record: SEC full-text search over 8-K filings, counted across a 14 day window against the equivalent window before it. You can check every row.

The right half is ours: 723 frameworks and 20,473 controls, 531 of those frameworks verified against their source documents, with the auditor evidence and common failure modes recorded control by control. Controls appear here because their own text names this term.

Cite this

The Art of Service Signals. Artificial Intelligence Risk corporate disclosure activity: 10 filers against 4 in the prior period, in 10-K and 10-Q filings, this quarter against the same quarter last year. Accessed 23 September 2026. https://signals.theartofservice.com/t/artificial-intelligence-risk/

Free to use with attribution, no permission needed. The chart downloads as an SVG with the source printed on it. If you cite it we would like to know, but you do not need to ask.

Today's edition · How programmes fail · The obligation index