What a year of corporate filings shows about how companies frame AI — as opportunity, or as threat
Last year, Wynn Resorts filed a 10-K that did not contain the words “artificial intelligence.” This year’s does. The new mention isn’t in the section where the company describes its business, or the one where management explains its results. It’s in the risk factors, filed alongside cyberattacks and regulatory exposure, noting that AI has made attempts to breach the company’s systems more frequent and harder to stop.
Wynn is not unusual. It’s the pattern.
We wanted to see not just how companies frame AI in their filings, but which way that framing is moving. So we took a sample of companies that filed an annual report in both 2025 and 2026, and for each one we compared where AI showed up across the two years. A 10-K is a structured document. The business description and the Management’s Discussion and Analysis are where a company makes its case for itself. The risk factors, Item 1A, are where it lists what could go wrong. AI in the first is offense. AI in the second is defense. Watching a company move AI from one section to another, or introduce it into one and not the other, tells you how its view of the technology is changing.
The short version: AI is still spreading through annual reports, and it is arriving as a risk faster than it is arriving as an opportunity.
Adoption is still climbing
First the unsurprising part. AI mentions kept rising. The cleanest read is our matched sample, where we follow the same companies across both years and hold each to its primary filing: the share mentioning AI rose from 59% to 64%. The broader index points the same way, up from roughly half of 2025 annual reports to about 57 to 58% in 2026, consistent with the figure in our earlier AI-risk analysis. That wider count includes amendments and reflects a later pull than that analysis, so the matched figure is the one we lean on. However you cut it, more companies are putting AI in their filings than did a year ago.
That much matches the headlines. The interesting part is what kind of language is doing the growing.
The growth is lopsided toward risk
When we tally the actual volume of AI language in the matched sample and sort it by section, both kinds grew, but not evenly. Mentions of AI in the business and MD&A sections, the offense, grew about 13% year over year. Mentions in the risk factors, the defense, grew about 27%. Defensive AI language expanded roughly twice as fast. The balance between the two, which already leaned defensive last year, leaned further that way this year.
You can see the same thing in how companies enter the conversation. The table below tracks the companies that were silent on AI in 2025 and where they landed in 2026:
| Where AI sat in the 2025 filing | Stayed silent | Entered risk factors | Entered business / MD&A |
| Said nothing about AI (62 companies) | 46 | 10 | 4 |
Of the companies that said nothing about AI in 2025 and started in 2026, two and a half times as many walked in through the risk factors as through the sections where they describe their business. Not one large company in the sample introduced AI as a pure growth story while ignoring the risk. Several did the reverse.
Who enters on defense, and who enters on offense
The names are the point. The companies that added AI to their risk factors this year, and nowhere else, are established and spread across the economy. SolarEdge, the solar inverter maker, added two lines, both about AI as a source of legal, regulatory, and reputational exposure. Virtus Investment Partners, an asset manager, added AI to its list of escalating cyber threats. First Community Bankshares, a regional bank, noted that criminals can now use AI to run better fraud. Wynn runs casinos. None of these companies sells AI. All of them now file it as something to defend against.
Contrast the companies that entered on offense, describing AI in their business sections as an opportunity. In our sample they were uniformly small and speculative. SmartKem, a semiconductor-materials company, is a representative case: it added AI to its business description as a target application for its chip-packaging technology. That’s a real offensive framing, but it comes from a micro-cap with a story to tell, not from an incumbent with a business to protect. The pattern across the sample is consistent. The offense is coming from companies that need AI to be their future. The defense is coming from companies that already have a present and are protecting it.
The split runs along sector lines
Widen from the new entrants to the whole 2026 cross-section and the same divide shows up sector by sector. In every sector we sampled except one, a majority of the companies that mention AI lean defensive. Utilities is the most lopsided, with essentially all of its AI language in the risk factors, driven by the same data-center power-demand concerns that surface whenever utilities discuss the technology. Consumer discretionary, materials, financials, and industrials all sit around 80 to 90% defensive. Information technology and health care are the closest to an even split, because those are the sectors where AI is most often the product rather than a threat to it. Communication services is the only group where more companies lean offensive than defensive.

The incumbents mostly don’t move
Among companies that were already discussing AI in both sections, most didn’t shift at all. Of 79 that mentioned AI in their core sections both years, 62 kept the same lean. The ones that did move tilted defensive, seven toward risk versus three toward opportunity, though these are small numbers and the shifts are changes in emphasis rather than companies literally relocating a sentence.
One of those shifts is worth pausing on because it rhymes with something we found last year. MSCI, which sells AI-enhanced analytics and talks up the technology in its business section, added a line to its risk factors this year observing that AI has lowered the barrier for its own clients to build capabilities in house. That’s the disintermediation worry, the same fear JPMorgan flagged in our AI-risk post, showing up at a company that is otherwise an AI enthusiast. Even the offense players are starting to write down the ways AI could come for them.
What it adds up to
Put the pieces together and you get a picture of diffusion. AI is moving out of the technology sector and into the rest of the market, the casinos and pipelines and regional banks, and as it arrives in each new place it is being written down as a risk before it is written up as an opportunity. That’s not necessarily companies being timid. It’s closer to the normal order of operations for a general-purpose technology. You notice the threat to your existing business before you’ve worked out how to use the thing yourself, and the risk factors are where a careful company records a threat it doesn’t fully understand yet.
Which means the number to watch next year is not how many more companies mention AI. It’s how many of this year’s defensive entrants start moving AI into their business sections, out of the risk factors and into the growth story. That migration, if it happens, is what maturing adoption actually looks like in the disclosure record. Right now it hasn’t happened. The direction of travel is still toward more defense, not less, and the companies filing AI as an opportunity are mostly the ones who have no other choice.
The offense narrative you hear on earnings calls is real. It’s just, for now, being made by a smaller and more speculative group than the volume of AI talk would suggest. The broad market is still standing at the risk door.
Run this on your own coverage. The filing and sentiment data behind this analysis is Context Analytics’ own. If you want to cut it by section, sector, or year across your own coverage universe, or see how AI framing lines up with our sentiment signals, get in touch.
This analysis is based on a matched sample of 151 companies that filed an annual report (Form 10-K) in both 2025 and 2026, drawn via the Elastic Filings index and sampled independently of whether a company mentions AI. Each company’s filing was reduced to its primary 10-K to avoid double-counting amendments. Offensive framing was measured as AI mentions in the business description (Item 1) and MD&A (Item 7); defensive framing as AI mentions in the risk factors (Item 1A). The sector chart reflects roughly 15 AI-mentioning filings sampled per sector and should be read as directional. The matched-sample penetration and volume figures are robust; the inflow, dropout, and section-switch counts rest on smaller cells and are directional. Full-index penetration is computed on the raw 2026 and 2025 indices (about 6,500 and 7,100 documents). Because these include 10-K/A amendments, they run above the number of distinct annual reports, which is closer to 6,000 for 2026 and is the basis for the 57% cited in our earlier AI-risk analysis. Those raw counts also reflect a later pull, so the matched-sample figures, which reduce each company to a single filing, are the more reliable measure. Company statements are paraphrased from the filings, not quoted.