Skip to content

Risk Digest

Which SEC rules require AI capex disclosure?

No SEC rule singles out AI capital spending, but several existing disclosure obligations can compel public companies to surface AI capex, from MD&A known-trends analysis to risk factors and antifraud liability. This record maps each legal hook, its trigger, and the enforcement consequences so disclosure teams can see where AI spend becomes a filing obligation.

By Editorial TeamUpdated Aug 5, 2026Verified Aug 5, 2026
CONFIRMED
Jurisdiction
US federal
Court
SEC administrative proceeding
AI tool named
AI-enabled investment advice
Ruling date
Mar 18, 2024
Source document
View primary court order ↗
Last verified
Aug 5, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

Current as of Q3 2026, for U.S. public-company securities disclosure. This is a source-linked regulatory map, not legal advice.

There is no SEC rule called an “AI capex disclosure requirement.” That phrase is useful only if it sends the disclosure team to the existing rules that actually do the work: MD&A, risk factors, business description, cybersecurity governance, the financial statements, and the antifraud rules. The filing problem is not finding a new AI box to check. It is deciding whether AI spending, commitments, operating costs, vendor dependence, and public AI claims have become material under rules that already apply.

Translucent legal document layers with an empty dashed frame and an AI chip below

That distinction matters because a company cannot draft around a rule that does not exist. It has to locate the obligation in the disclosure architecture it already uses. The most direct route is Item 303 of Regulation S-K: if AI spending changes results of operations, creates a known trend or uncertainty, affects liquidity through commitments, or becomes an internally tracked performance metric, it may need to appear in MD&A. Troutman Pepper Locke’s June 2026 analysis frames token and usage costs in exactly those MD&A terms, including period-over-period expense movement, reasonably likely trends, liquidity effects from AI commitments, and AI metrics that function as KPIs. It also reports the practical reason this analysis is hard: citing KPMG figures reported through the Wall Street Journal, only 26% of companies had a comprehensive view of AI costs, while 22% had no visibility until they were billed. [1]

Where the obligation actually lives

The current U.S. disclosure map is an obligations stack, not an AI-specific regime. Corp Fin has been explicit that AI disclosure belongs in the ordinary disclosure-review framework. In June 2024, then-Division Director Erik Gerding told companies to define what they mean by AI, tailor disclosures to their actual use, avoid boilerplate, and have a reasonable basis for claims about AI prospects. [2] That is a review posture, not a new line item. But it is enough to make AI capex a filing issue when the spending affects the business in ways existing rules already recognize.

Disclosure hookTrigger for AI capex or AI spendingFiling consequence
MD&A — Regulation S-K Item 303AI costs, commitments, or usage patterns materially affect results, liquidity, capital resources, or known trendsDiscuss expense changes, liquidity effects, known trends or uncertainties, and any material AI KPIs
Risk factors — Regulation S-K Item 105AI deployment, vendor dependence, implementation costs, data risks, or capital expenditure risks are material to the companyProvide tailored, company-specific risk disclosure rather than generic AI language
Business description — Regulation S-K Item 101AI has become material to products, operations, strategy, supply chain, or competitive positionDescribe the role of AI in the business with enough specificity for investors to understand the dependency
Cybersecurity — Regulation S-K Item 106AI systems materially affect cyber risk management, governance, incident exposure, or third-party technology riskAddress AI-related cyber risk in the company’s cybersecurity governance and risk-management disclosures
Financial statementsAI costs are capitalized, expensed, impaired, committed, or otherwise reflected under applicable accounting rulesRecognize, classify, and disclose amounts through the financial statements and notes where required
Antifraud provisionsAI claims, projections, automation statements, or capex narratives are materially misleading or lack a reasonable basisExposure can arise through SEC enforcement, private securities litigation, or both
Diagram of an AI chip connected to six SEC disclosure hooks

MD&A is the first place to look

AI capital expenditure often starts life inside the company as something narrower than “AI capex”: cloud consumption, token usage, model-training spend, GPU access, software subscriptions, data-center buildout, colocation commitments, power arrangements, consulting invoices, or vendor minimums. MD&A does not care what the procurement team called the invoice. It asks whether the company’s financial condition, results of operations, liquidity, or capital resources have been materially affected, and whether known trends or uncertainties are reasonably likely to have a material effect.

The period-over-period analysis is the cleanest example. If AI usage costs materially increased cost of revenue, research and development, selling expense, or general and administrative expense, the MD&A question is not whether those costs are fashionable. It is whether investors need an explanation for the movement. A company that tells investors margins declined because of “technology investments” may still need to decide whether the more specific driver was AI infrastructure, model usage, or implementation expense.

The known-trends analysis is more uncomfortable because it reaches forward. If management knows that AI usage is accelerating, that vendor pricing will change, that a model migration will require larger compute commitments, or that a new AI product depends on expensive third-party infrastructure, the question becomes whether that trend is reasonably likely to materially affect future results or liquidity. Troutman’s MD&A analysis identifies AI token and usage costs as capable of triggering this known-trends framework when they are material or reasonably likely to become material. [1]

Liquidity is the part that can be missed when the company treats AI as an operating initiative rather than a financing question. A multi-year cloud commitment, data-center lease, take-or-pay power arrangement, or vendor minimum may not look like a classic factory build, but it can still affect capital resources. If the commitment is material, MD&A may need to explain the expected funding burden, the timing of cash requirements, and the dependence of the business plan on continued access to that infrastructure.

The KPI issue is equally practical. If management tracks AI requests processed, inference volume, automation rate, model cost per transaction, data-center utilization, or AI-assisted revenue internally, those measures can become part of the disclosure analysis when they are used to manage the business or communicate performance. The obligation is not to publish every dashboard. It is to avoid presenting the business through selected metrics while omitting the measures or cost drivers needed to make the presentation understandable.

Scattered invoices, contracts, server icons, and dashboards showing fragmented AI spending visibility

This is where internal visibility becomes a legal control issue. The KPMG figures reported by Troutman are not a legal standard, and they do not prove that any particular issuer’s disclosure is deficient. They do show how a good-faith process can fail before the materiality meeting starts. If invoices sit across engineering, product, procurement, cloud operations, finance, and business units, the disclosure committee may never see the total spend, the full commitment stack, or the unit economics behind an AI product claim. [1]

Risk factors and antifraud exposure are now hard to separate

Item 105 does not require a company to confess every speculative AI anxiety. It requires disclosure of material factors that make an investment in the company risky. For AI capex, the relevant risks are usually not abstract. They include cost overruns, implementation failure, vendor concentration, inability to obtain enough compute, failure to monetize AI investments, data and privacy exposure, cybersecurity vulnerabilities, regulatory constraints, and dependence on assumptions embedded in guidance.

Market practice has moved quickly. White & Case, citing The Conference Board, reported that 72% of S&P 500 companies disclosed at least one material AI risk in 2025, up from 12% in 2023; it also identified “capital expenditure and implementation risks” as one of the AI risk categories companies were addressing. [3] Those percentages are not law. They do, however, make boilerplate harder to defend as a drafting habit when peer disclosures have become more specific.

The antifraud side enters when the company’s AI story outruns the facts. In March 2024, the SEC announced settled charges against Delphia (USA) Inc. and Global Predictions Inc. for allegedly making false and misleading statements about their use of AI; Delphia agreed to pay a $225,000 civil penalty and Global Predictions agreed to pay a $175,000 civil penalty. [4] Those settlements were not about a public-company AI capex line item. They are still important because they show the enforcement theory: AI claims must have factual support.

Saniger raises the enforcement gravity, but it should be kept in procedural focus. Quinn Emanuel describes SEC v. Saniger as an April 2025 parallel SEC civil and DOJ criminal matter involving allegations that the company raised more than $40 million while claiming its retail platform was powered by AI automation that was, in the government’s telling, “effectively zero.” The same analysis states that pretrial motions are due in September 2026. [5] That posture matters; it is not a final liability precedent. It is a live example of how AI automation claims can become securities-fraud evidence when investors were allegedly sold a technology narrative the company could not substantiate.

For companies spending heavily on AI infrastructure, the drafting point is direct. Risk factors cannot say implementation risk is merely hypothetical if the company is already experiencing material cost pressure, capacity constraints, vendor failures, or delays. Public statements cannot celebrate AI-driven productivity, margin expansion, or automation if the supporting data is incomplete or contradicted by internal records. The same facts that belong in the MD&A workpapers may also be the facts that determine whether a risk factor was tailored and whether an AI claim had a reasonable basis.

Business description, cyber governance, and financial statements

Item 101 becomes relevant when AI is no longer a side project. If AI is material to a product line, service delivery model, supply chain, customer acquisition strategy, or competitive position, the business description may need to explain that dependency. The disclosure does not have to reveal trade secrets. It does have to avoid a business narrative that reads as if AI were decorative when the company’s operations or strategy now depend on it.

Item 106 is narrower. It is not an AI spending rule. It becomes relevant when AI deployment changes cybersecurity risk management, strategy, governance, or incident exposure. A company using AI tools in software development, customer support, identity workflows, security monitoring, or data processing should ask whether those tools materially affect its cyber-risk program or board oversight disclosures. Vendor AI systems can matter here as much as internally built systems, especially where sensitive data, model access, or operational resilience is involved.

The financial statements require a separate discipline. Some AI-related amounts may be expensed; others may be capitalized, impaired, committed, or disclosed through notes depending on the applicable accounting facts. Securities-law disclosure cannot rescue weak accounting classification, and accounting recognition does not end the MD&A inquiry. A properly recorded cost may still need narrative explanation if it materially changes results, liquidity, or known trends.

Regulatory direction is not the same as a current rule

The SEC Investor Advisory Committee’s AI recommendation belongs after the current-rule map, not before it. Crowell & Moring reported that the committee voted on December 4, 2025 to recommend AI disclosure guidelines that would integrate AI topics into existing Regulation S-K items, including Items 101, 103, 106, and 303. The reported recommendation included issuer definitions of AI, board oversight of AI deployment, and material effects of AI deployment on internal operations and consumer-facing matters. [6]

That recommendation is non-binding. It is a signal about where investor advocates may want the SEC to go, not a rule companies can cite as an adopted requirement. TheCorporateCounsel.net also reported that the SEC withdrew the prior predictive-data-analytics proposal, S7-12-23, in June 2025, a useful reminder that the current Commission has not chosen to build a broad new AI-specific disclosure regime around that proposal. [7]

The result is a familiar securities-law posture: principles first, specific AI rulemaking later if at all. For annual-report work, that means the disclosure team should not wait for a rule titled “AI capex.” It should test AI spending under the existing items now.

A boundary note on the EU AI Act

Do not confuse U.S. issuer disclosure with EU AI Act transparency obligations. Article 50 transparency workstreams concern matters such as AI interaction and AI-generated content marking, not a U.S. public company’s MD&A treatment of AI capex. For a jurisdiction-split approach to AI infrastructure obligations, see the site’s discussion of Microsoft’s AI data center buildout.

What should be in the disclosure record before the materiality call

The most useful disclosure-control question is not “are we an AI company?” It is “who has the full cost view?” If the answer is split across engineering, procurement, finance, cloud operations, legal, and investor relations, the materiality judgment is being made on a partial record.

  • Map AI spend by category: capital projects, cloud usage, token or inference charges, training costs, software licenses, consulting, data acquisition, hardware, colocation, energy, and vendor minimums.
  • Separate actual incurred costs from committed future payments, renewal exposure, minimum purchase obligations, and expected expansion costs.
  • Identify which AI metrics management uses internally and which metrics have appeared in earnings calls, investor decks, product announcements, or guidance.
  • Compare public AI claims against internal implementation status, automation rates, vendor limitations, margin data, and known failures or delays.
  • Route the same factual record through MD&A, risk factors, business description, cybersecurity, accounting, and antifraud review instead of treating each section as a separate drafting silo.

Private litigation around AI infrastructure, financing, and capex narratives should be read with the same caution. Reported matters involving large technology and data-center issuers may be useful warning signs, but a complaint is not an SEC rule and secondary coverage is not a settled legal holding. For companies tracking AI infrastructure litigation templates, the related site records on Nvidia-OpenAI securities theories and CoreWeave securities litigation context are better used as issue spotters than as disclosure checklists.

The legal risk does not concentrate because the SEC has created a new AI capex box to check. It concentrates because existing principles-based rules already require material AI spending, commitments, risks, dependencies, and claims to surface when they affect results, liquidity, operations, governance, or investor understanding. Build the internal cost view before making the materiality call. Once AI spend is invisible inside the company, the MD&A, risk-factor, and antifraud judgments become the weakest part of the filing record.

References

  1. AI Token Costs and MD&A Disclosure, Troutman Pepper Locke, June 2026.
  2. The State of Disclosure Review, U.S. Securities and Exchange Commission, June 24, 2024.
  3. Key considerations for updating 2025 annual report risk factors, White & Case, October 2025.
  4. SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence, U.S. Securities and Exchange Commission, March 18, 2024.
  5. The First Real Test: What Saniger Means For AI-Disclosure Fraud, Quinn Emanuel, June 11, 2026.
  6. Investor Advisory Committee Recommends SEC Disclosure Guidelines for Artificial Intelligence, Crowell & Moring.
  7. SEC Investor Advisory Committee: AI Disclosure Recommendations, TheCorporateCounsel.net, December 2025.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory