AI news ·
AI risk mentions in UK annual reports climb to 41.2% in 2025 but substantive disclosure remains rare
UK-listed firms mentioning AI risk in annual reports jumped from 2.8% in 2020 to 41.2% in 2025. Yet only 4.3% of those 2025 disclosures contained substantive detail beyond boilerplate language.

The share of UK-listed companies mentioning AI risk in their annual reports climbed from 2.8% in 2020 to 41.2% in 2025, according to an analysis of 9,821 reports published by the AI Risk Observatory. The sharp rise signals that boards are increasingly aware of AI as a material concern, yet the study also found that only a small fraction of those disclosures contain any real detail.
The paper, posted to arXiv on 5 October 2026, examined filings from 1,362 firms across the London Stock Exchange's Main Market and AIM segments. Researchers used a two-stage classification pipeline validated against 474 human-annotated passages to extract references to AI risk, AI adoption, and vendor names from the reports.
Adoption disclosures and vendor concentration
AI adoption disclosures rose in parallel with risk mentions, moving from 13.8% of reports in 2020 to 45.2% in 2025. When firms named technology suppliers, the references clustered around a small group of providers led by Microsoft. The concentration suggests a narrow supply chain for enterprise AI tools across UK public companies.
Disclosure rates varied by market segment and sector. AIM-listed firms and companies in Critical National Infrastructure sectors - particularly Energy and Data Infrastructure - lagged behind Main Market peers in both risk and adoption reporting. The gap points to uneven governance practices between larger and smaller listed entities.
Substance remains rare
The headline 41.2% figure masks a thinner reality. Only 4.3% of the 2025 reports that flagged AI risk contained what the authors classify as substantive disclosure - content that goes beyond boilerplate language to describe specific risks, controls, or scenarios. Across the entire six-year corpus, just seven reports disclosed actual harm events linked to AI systems.
For professionals in finance, legal, and compliance roles, the findings highlight a growing gap between acknowledging AI risk and explaining it in terms that investors and regulators can act on. The data suggests most firms are still at the stage of naming the issue rather than measuring or managing it. Leaders who move sooner to build internal frameworks for substantive AI risk reporting may find themselves ahead of an emerging disclosure expectation - one that internal training, such as AI Regulatory Compliance Courses, can help teams address before it becomes a mandated requirement.
Why this matters for executives and strategy
For executives, board members, and heads of strategy, the study provides a benchmark against which to measure their own organisation's AI disclosure maturity. If your firm mentions AI risk in its annual report but cannot point to a documented assessment behind that statement, you are in the 95.7% majority - and that majority is shrinking each year as expectations rise. The question is not whether AI risk belongs in the report, but whether the substance behind the sentence is ready for scrutiny.