Among the constituents of the S&P 500 index, more than 70% of listed companies have already listed artificial intelligence (AI) as a major risk in their public disclosures. This conclusion comes from a recent report released by The Conference Board.

The report shows that this proportion has surged significantly from 12% in 2023, reflecting that major companies are rapidly advancing the implementation of AI applications.

"This powerfully illustrates how AI has rapidly evolved from a niche topic to a widespread phenomenon that is broadly adopted and embedded in corporate operations," Andrew Jones, lead researcher at The Conference Board's Governance and Sustainability Center, said in an email to Cybersecurity Dive, a sister publication of CFO Dive.

Jones noted that AI has moved beyond the experimental stage in large enterprises and is deeply integrated into core business systems such as product design, logistics, credit modeling, and customer interaction.

The report shows that corporate boards and senior management are addressing a range of risk factors surrounding AI deployment.

Among these, reputational risk is the most common disclosure category, accounting for 38%. This reflects the potential impact of declining brand trust due to service disruptions, improper handling of consumer privacy, or customer-facing tools failing to meet expectations.

Cybersecurity risk was mentioned by 20% of companies. AI expands the attack surface, while companies also face risks brought by third-party applications.

Legal and regulatory risks also constitute a significant issue, as U.S. states and the federal government are rapidly establishing safety guardrails to protect the public while providing sufficient support for continued corporate innovation.

Although AI deployment in enterprises is evolving rapidly, corporate leaders still find it difficult to fully establish governance structures to manage AI usage.

According to PwC's 2025 Annual Corporate Directors Survey, only 35% of boards have formally incorporated AI into their oversight responsibilities, indicating that companies are still striving to develop stricter guardrails.

"Directors recognize that AI brings both strategic opportunities and fiduciary responsibility risks. Many are beginning to consider how to strengthen governance through regular education, clear oversight structures, and responsible use frameworks," Ray Garcia, leader of PwC's Governance Insights Center, told Cybersecurity Dive.