A new report from Guardrail Technologies exposes a major gap between how much companies talk about AI and how they are actually managing its risk. After reading all 500 S&P 500 annual reports, Guardrail found that 97% of companies discussed AI, but only 3% document a process for managing AI-related cyber risk. That is about a 77-point gap, and it shows up in almost every industry. Banks and health systems talk about AI the most — yet describe the risk in the vaguest terms. Here to break this down is T.J. Marlin, CEO of Guardrail Technologies. TJ, thanks so much for joining us.
I am great. Real pleasure to be here.
Walk us through the 77-point gap. What does it actually mean when a company discusses AI versus documenting a process for managing its risk?
AI is in every process, every piece of software. Everyone is using it — at home and at the office. What we found when looking at the S&P 500 is that this gap is like highlighting the upside — everybody is talking about AI as the future, as innovation, as tremendous benefits. But under the disclosure requirements, they are not explaining the downsides or the risks. Think of it in financial statement terms: it is almost like saying here is the profit, here is the revenue — but not really disclaiming what can go wrong, and what investors and the public need to be aware of.
Why do even the most regulated industries barely lead everyone else on this?
Two things. Number one, I question whether management and the board really understand the impact of AI in their organisations. Number two, given that the regulations are not specific to AI, it has almost become a check-the-box exercise. It says almost nothing, perhaps as a risk mitigation technique.
Health and banking systems stand out because they have the thinnest disclosure despite talking the most about AI. What is the disconnect?
The risks of AI are not well understood by the people managing these companies. This is the fastest adopted technology in history — but the people managing these companies understand it the least. They understand books and records. They do not understand bits and bytes. Think of it this way: it was quickly adopted because you can converse with it like a human. But how it works inside — how it makes decisions, generates content, manages behaviour — I would be very interested to know if you asked the chairman of the board, the heads of audit and governance, and the C-suite: how does it work? It would be very interesting to get their answers.
Have you actually seen this disconnect across all sectors?
I have met with hundreds of companies in the last year. Very rarely, when you ask them if they understand how it works under the hood, do you get anything but a blank stare. Before you can discuss the risks, you have to take a step back and explain how it actually works.
How do C-suite executives actually get to a better understanding of AI under the hood?
They all have a fiduciary duty to figure it out. There are online courses, there is reading. But here is the framing: we all drive cars, and many people drive cars. You have to get a driver's licence — it establishes a minimum standard. Well, AI is now in everything. If you start to think about AI as critical infrastructure itself, then it should be at the top of the agenda for the C-suite, the boards, and frankly the regulators to step in and establish minimum standards. We can no longer be in a place where we are self-certifying and leaving a laissez-faire approach. It is just too important.
What does it mean for a company if the cybersecurity section of its annual report says almost nothing about AI?
The cybersecurity section is there for investors and the general public. If AI is as significant as everyone says — and the S&P 500 says it is — and nowhere in the annual report does it mention the downside or what the company is doing to mitigate the downside, I would be concerned. It should be a wake-up call for the public. It should be a wake-up call for the S&P 500. And it should be a wake-up call for the regulators.
TJ, thanks so much for joining us.
Pleasure. Thank you so much.