What IROs can learn about AI disclosure from the UK government’s proposals to simplify corporate reporting

Work by former Office of Fair Trading CEO John Fingleton investigates whether money, controls and words still connected to the outcome they are meant to protect

The UK government’s latest proposals to simplify corporate reporting are part of its push for growth. The real test is whether companies can spend less time reporting while giving investors a clearer picture of the business.

AI is a useful place to look. Companies are under pressure to say more about how they use AI, how boards oversee it and what could go wrong. That is sensible up to a point. AI can create real risks around data, cyber-security, intellectual property, business disruption and reputation. Investors need to understand those risks.

But there is another risk that receives less attention: companies may end up saying so much about AI that investors learn very little. John Fingleton, the former head of the UK’s Office of Fair Trading, has previously offered a useful way of thinking about this problem. His work on regulation raises a broader question: what happens when a process becomes detached from the outcome it was designed to achieve? Companies and public bodies can spend an increasing amount of time showing that they have followed a process, without showing that it has reduced risk.

The same thing could happen with AI disclosure.

The growth of AI disclosure

AI risk disclosure by US-listed companies has increased sharply. According to the Conference Board, the proportion of S&P 500 companies disclosing AI as a risk rose from 12 percent in 2023 to 83 percent in 2025. That may suggest boards are taking AI seriously – or it may mean companies are reacting to rising expectations before anyone has worked out what investors actually need to know.

Anthropic shows how wide that 83 per cent can stretch. As it prepares for its own listing, its chief executive Dario Amodei has put the odds of things going badly at somewhere between 10 and 25 percent, and researchers inside the company have said much the same in public. That is not a business managing ordinary AI exposure, but a business that may need risk factor language most of its peers will never require – even though, once drafted, it will probably read exactly like theirs.

For IR teams, the practical question is not whether to disclose AI risk, but how to connect that disclosure to materiality, accountability and financial relevance

A company can describe faulty models, bias, poor data, cyber-attacks, third-party suppliers and regulatory uncertainty in considerable detail. None of that, on its own, tells an investor how important AI is to the business. Is it embedded in a product sold to customers? Is it helping staff draft documents? Is it part of a decision that affects a customer’s money? Is it built in-house or bought off the shelf from a large technology provider? Those questions tell investors more about a company’s actual exposure than another page of hypothetical risks.

For IR teams, the practical question is not whether to disclose AI risk, but how to connect that disclosure to materiality, accountability and financial relevance.

The lesson from the fish and the bats

Fingleton’s comments on BBC Radio 4’s The Bottom Line provide a striking example of what can happen when process becomes detached from purpose.

He estimated the cost of fish protection measures at Hinkley Point C at around £700 mn, or roughly £250,000 per protected fish. For the HS2 project, he put the cost of the bat protection tunnel at about £330,000 per bat, assuming every train would otherwise kill one. A bat charity, by contrast, had created habitat for 1,000 bats for £100,000, or £100 per bat. These are different ways of protecting bats, rather than directly comparable prices for a bat’s life. Even so, the gap is striking. Presumably the bats have not been informed of the discrepancy.

The question is whether following the rules produces a sensible outcome. Infrastructure mitigation and AI disclosure are very different things, but the example suggests a useful test: can a company follow a process perfectly and still tell an investor almost nothing?

A company can have a policy, a board committee and several pages of risk disclosure, and still have no real idea what would happen if a model got something badly wrong

Fingleton’s point was not that fish or bats should be ignored. It was that a process can quietly become the objective, while the outcome it was meant to protect gets left somewhere in the paperwork.

A company can have a policy, a board committee and several pages of risk disclosure, and still have no real idea what would happen if a model got something badly wrong. The paperwork is easier to assess than the protection it provides. Investors can see that a policy exists. They cannot easily see whether anyone follows it, or whether the controls would hold up under pressure.

Some AI risk reporting reads as though it was written to pass a compliance check rather than inform a shareholder. That is not dishonesty. It is caution dressed up as diligence, and it manages to be neither reassuring nor useful.

Work by Fingleton’s firm for the Global Infrastructure Investor Association raises a related question about complexity. It describes how regulators have accumulated responsibilities over time, adding duties and expectations that can make it harder to see what matters most. Companies face a similar problem when reporting expectations accumulate. Every new incident or investor question adds another expectation, and the report gets longer without getting clearer.

The cost of saying everything

There is a cost to saying everything, too, and it does not get much airtime. Investors have limited attention, and AI risk sections often seem determined to test it. When every company uses the same broad language, the important information gets harder to find. Generic disclosure can look like transparency while making comparison harder.

This bites hardest at companies where AI plays little part in business strategy. They can copy the language of technology companies and banks and end up implying a level of exposure they do not have. The reverse problem exists too. A company might talk up productivity and innovation while saying almost nothing about where AI is used. That is promotion without accountability.

Generic language is not always a failure of effort. When the Financial Times’ Alphaville blog asked Claude to draft a mock risk factor for Anthropic covering the possibility of catastrophic harm from its own products, the result read exactly like standard prospectus boilerplate, hedged with the same ‘may’ and ‘could’ that fill every other risk section. That vagueness does real work. It shields the company from liability while still signaling the scale of what it claims to be building. An IR team reading its own AI risk disclosure should ask which purpose the language is serving: honest uncertainty or a deliberately blurred line?

The fix is better judgment about what is worth saying.

What investors really need

Fingleton’s work on AI regulation argues that policymakers need to weigh the benefits of reducing AI harms against the risk of creating barriers to entry, expansion and innovation.

The same trade-off sits inside companies. Controls should address risks that matter to the business without shutting down sensible experimentation. Investors want to know that a company can innovate safely, not that it has eliminated every conceivable risk, which is impossible anyway.

That matters to the growth debate too. Investors need to distinguish companies putting AI to productive use from those simply talking about it. Pages of generic risks do little to help them decide which businesses deserve their money. A useful disclosure test is simple: where is AI used, what business outcome does it affect, what could go wrong, who is accountable and what would be material to investors?

Investors need to distinguish companies putting AI to productive use from those simply talking about it

AI regulation will keep evolving, and so will reporting expectations. Companies cannot control every new rule. What they can control is whether their response is another layer of process, or a clearer account of how the business actually works.

Fingleton’s fish and bats are worth holding on to as a test: are the money, the controls and the words still connected to the outcome they are meant to protect?

Read several dense pages of AI risks without learning where AI matters to the business, and it is fair to ask whether disclosure has become expensive, well-intentioned and disconnected from its purpose. If a company cannot explain where AI matters to its business, why should investors be reassured by how much it says about the risks?

Six questions IROs should be able to answer:

  • Where is AI material to strategy, revenue, cost or competitive advantage?
  • Which uses count as high risk and why?
  • Who is accountable, at executive and board level?
  • What controls apply to in-house tools versus third party providers?
  • What would trigger a market update?
  • Has AI caused a material financial, operational or reputational event?

Alex Dee is the former head of investor relations at LendInvest, Man Group and ICAP.

Upcoming events

  • Corporate Governance Forum
    Thursday, November 5, 2026

    Corporate Governance Forum

    About the event WHEN WHERE VENUE_ADDRESS Awards by nomination Categories Awards by research Categories What our attendees say IR Rankings – LOCATION The IR Rankings – LOCATION report is the ultimate benchmarking resource for any IRO looking to improve their IR program. It provides detailed analysis and statistics on the…

    New York, US
  • Corporate Governance Awards
    Thursday, November 5, 2026

    Corporate Governance Awards

    About the event WHEN WHERE VENUE_ADDRESS Awards by nomination Categories Awards by research Categories What our attendees say IR Rankings – LOCATION The IR Rankings – LOCATION report is the ultimate benchmarking resource for any IRO looking to improve their IR program. It provides detailed analysis and statistics on the…

    New York, US
  • Forum – AI & Technology
    Thursday, November 12, 2026

    Forum – AI & Technology

    About the event A year ago, the conversation around AI within investor relations centred on adoption and implementation: which tools to use, how to implement them and how to manage the associated risks. Today, the landscape has evolved significantly. AI is no longer an emerging concept for many IR teams,…

    New York, US

Explore

Andy White, Freelance WordPress Developer London