Fortune 100 companies accelerate disclosure of AI and cybersecurity-related risks
According to EY's latest report, Fortune 100 companies are accelerating the disclosure of AI strategies and related risks, with board oversight rising from 16% in 2024 to 48%, and the proportion of companies listing AI as a risk factor in 10-K filings increasing from 14% to over one-third. Meanwhile, transparency in cybersecurity governance has improved, with over 70% of companies adhering to external security frameworks. Another report from AuditBoard points out that nearly half of companies face risk management challenges in AI implementation.

Fortune 100 companies are significantly accelerating public disclosure and governance oversight of AI strategies and related risks, with a growing number of enterprises eager to incorporate AI technology into their strategic growth plans. This trend comes from a recent report released by EY.
The report shows that nearly half of Fortune 100 companies have disclosed AI as a key area of board oversight, a proportion that jumped from 16% in EY's 2024 report to 48% in the current study. Meanwhile, four in ten companies stated that AI has been assigned to the scope of at least one board committee, compared to just one in ten a year ago.
"Which committee is responsible for oversight and how the board provides guidance are becoming an increasing focus," Patrick Niemann, leader of EY's Americas Board Matters Center, told Cybersecurity Dive. "At the same time, boards need to consider how to keep pace with this rapidly evolving field in order to ask the right questions and adjust governance of AI and its related risks to support the company's strategic objectives."
Fortune 100 companies refer to the top 100 U.S. companies ranked based on revenue analysis.
More than one-third of companies listed AI as a risk factor in their annual 10-K reports submitted to federal regulators, compared to just 14% a year earlier.
The report also elaborated on specific AI risks facing top companies, including the intensifying threat of deepfakes and the risk of data breaches that may result when employees use unauthorized AI applications in the workplace.
EY's report also shows increased board engagement and transparency regarding cyber readiness.
More than seven in ten companies adhere to some external cybersecurity framework, with two-thirds of surveyed companies citing standards from the National Institute of Standards and Technology (NIST).
Nearly six in ten companies disclosed some level of cyber readiness in regulatory filings, including the use of tabletop exercises, simulation drills, or response readiness testing.
In nearly eight in ten cases, the audit committee was designated as responsible for cyber oversight.
Approximately 85% of companies stated that they either already have board members with cybersecurity expertise or are actively seeking board members with such knowledge.
Another independent report released by AuditBoard on Wednesday shows that nearly half of companies struggle to effectively manage AI-related risks while advancing ambitious AI implementation plans.
As a result, adoption of these AI-based tools and services has begun to show signs of stalling just months after launch.
"Early pilot projects often progress quickly but lack discipline," Richard Marcus, Chief Information Security Officer at AuditBoard, told Cybersecurity Dive via email. "But once questions around ownership, validation, and accountability arise, confidence quickly declines, thereby slowing down decision cycles."