A new measurement of what companies actually disclose about AI risk
A preprint published on arXiv on October 1, 2026, argues that most AI risk talk in UK company annual reports is compliance boilerplate rather than substance. The paper, "The AI Risk Observatory: What Can We Learn from AI Disclosures in Annual Reports About Societal Resilience?", is authored by Bart Jaworski and is a single-author, not-yet-peer-reviewed study that uses large language models to classify disclosures at scale. Its central finding is a gap: in 2025, 41.2% of the annual reports in the study mention AI as a risk, but only 4.3% contain AI risk disclosure the author classifies as substantive.
That gap matters for anyone who has to make decisions based on corporate AI claims. If the measurement holds up, investors cannot tell from most annual reports whether a company is genuinely managing AI risk or merely has the expected paragraph. Regulators reading the same documents face the same problem. The study measures disclosure, not safety: it does not show that companies are safe or unsafe, only that their documents rarely say much either way.
How the study was built, and where its limits are
The pipeline is explicitly built to be reproducible. Jaworski applied a two-stage LLM classification to 9,821 annual reports from 1,362 UK listed companies covering 2020 through 2025, with partial 2026 data. The study first validates the method against 474 human-annotated passages, reporting high recall but only moderate label-level agreement. That is an honest limitation worth stating plainly: moderate agreement means the machine's labels and human labels do not always match, so the aggregate percentages are a useful signal, not a courtroom-grade audit of every sentence.
The abstract summarizes the empirical patterns in the author's own words: "between 2020 and 2025, the share of reports mentioning AI risk rose from 2.8% to 41.2%, while AI adoption disclosure also rose, from 13.8% to 45.2%, and named vendor mentions cluster around a small set of major providers led by Microsoft". Attribution: Bart Jaworski, author, abstract of arXiv:2610.02281, submitted October 1, 2026. In other words, AI adoption talk and AI risk talk have both become common in UK reporting in a few years, and when companies name their AI suppliers, the names concentrate.
What a rising mention rate does and does not prove
The 41.2% figure describes mention rates, not prevalence of AI risk itself. A rising share of reports containing the words is consistent with several explanations at once: genuine growth in AI exposure, rising regulatory or investor pressure to mention AI, and simple fashion in risk-factor templates. The study measures what companies write. It cannot, on its own, tell you which explanation dominates, and the author does not claim it can.
The abstract's third pattern is also material: "harm disclosures are near-absent (seven reports across the entire corpus)". Attribution: Bart Jaworski, author, abstract of arXiv:2610.02281, submitted October 1, 2026. Out of 9,821 reports, seven contain disclosure the study classifies as describing actual AI harm. My reading of that number: either real harms are rarely disclosed in this channel, or the classifier rarely recognizes them when they are, or both. The study's own validation limits mean we should hold that question open rather than pick the alarming interpretation.
The sectors and markets that say the least
Disclosure is not evenly distributed. The study reports that AIM-listed companies, the smaller and less regulated tier of the London market, disclose AI risk at far lower rates than Main Market companies. By Critical National Infrastructure sector, Energy and Data Infrastructure lag behind the rest in AI risk disclosure. The author frames this as a societal resilience question: the sectors where AI failure could matter most to the public are the ones saying least about it.
This is where the study connects to policy without importing claims it does not make. The preprint is UK-only. It does not test the EU AI Act, the UK FCA's rules, or any specific regulation, so readers should treat sector comparisons as observations about UK disclosure practice, not as evidence about how any transparency law performs. But the governance problem it identifies is general: if disclosure quality cannot be distinguished from disclosure volume by the people who rely on it, volume becomes the compliance target and substance becomes optional.
Concentration, access, and what it means for the AI supply chain
The vendor-mention finding deserves attention from anyone who cares about practical access to AI. If named vendor mentions in UK annual reports cluster around a small set of major providers led by Microsoft, then the corporate AI supply chain visible in these documents is narrow. This is a disclosure-level observation, not a measurement of market share or capability, and the paper's corpus measures UK listed companies only. Still, concentration in the visible supply chain is the kind of signal that bears on dependency: if thousands of listed firms describe their AI exposure through the same handful of suppliers, disruption or policy changes at those suppliers propagate widely.
I will flag my own interpretation here as opinion: the interesting follow-up research is whether substantiveness can be improved by regulation, by investor pressure, or by better standards for what an AI risk paragraph should contain. The study provides the baseline for that conversation; it does not settle the mechanism.
Reproducibility, and what I could not independently verify
The arXiv abstract page states: "Code and data: this https URL (release dataset-v1.1)". Attribution: abstract page for arXiv:2610.02281, submitted October 1, 2026. The referenced repository is hosted on GitHub at the address 84rt/AI-Risk-Observatory. I was unable to retrieve the repository directly through this newsroom's research tools: two access attempts were blocked by the source allowlist, so the repository's contents and license were not independently verified for this article. The reproducibility claim therefore rests on the paper's own statement, which the dataset release is designed to support. I recommend reviewers check the repo directly before relying on the data release.
Because this is a preprint, it has not passed peer review. It is single-authored and its method is LLM-assisted, which is both its strength, scale, and its structural limitation, dependence on machine labeling validated against only 474 human-annotated passages. Those caveats should shape how much weight readers place on the 4.3% substantiveness figure. The number is a best-effort measurement of a hard-to-measure quality, and the study is unusually transparent about that difficulty.
Why the 4.3% number should set the agenda
For The Expectancy's audience, the actionable takeaway is a distinction: ask not whether a company mentions AI risk, but what its disclosure would let you verify. Four in ten UK annual reports now carry the phrase. One in twenty-three carries something the study would call substantive. Bridging that gap, through better standards, through investor diligence, or through regulators asking for specifics rather than sentences, is the governance task this paper puts on the table. The measurement is new, single-author, and imperfect. The gap it describes is large enough to be worth the reading.
