A paper posted to arXiv on 1 October and announced in Monday’s listing ran a two-stage language-model classifier over 9,821 annual reports from 1,362 UK listed companies, covering 2020 to 2025 with partial 2026 data.
The first finding is how fast the subject became routine. The share of reports naming AI as a risk rose from 2.8% in 2020 to 41.2% in 2025. Disclosure of AI adoption rose over the same period from 13.8% to 45.2%. Where reports name a vendor, the mentions cluster on a small set of large providers, led by Microsoft.
The more interesting finding is about quality. The paper builds a “substantiveness” classification and reports that although 41.2% of 2025 reports mention AI as a risk, only 4.3% contain risk disclosure it counts as substantive. Disclosure of actual harm is close to absent: seven reports across the whole corpus.
Treat it as a preprint. The pipeline was validated against 474 human-annotated passages, which the paper describes as high recall but only moderate label-level agreement, and the 2026 data is incomplete. Code and dataset are published, so the classifications can be argued with.
Why it matters: annual reports are one of the few places companies are obliged to describe risk in writing, and this suggests most of that writing is currently boilerplate.
Source: the paper on arXiv.
