← Blog

SEC Cyber Disclosure AI Audit Evidence for Public Companies

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

SEC cyber disclosure AI audit evidence should connect a complete incident population to the registrant's materiality process, filing clock, annual risk disclosures, and retained source records. This guide shows where routed AI request evidence can support that chain without treating the SEC cyber rules as AI-specific requirements.

Industry Verticalsai-complianceai-governanceauditcybersecurityregulationforensic-audit
SEC Cyber Disclosure AI Audit Evidence for Public Companies

At 09:12 on a Monday, the incident register shows an LLM request denied for restricted merger data. The provider log also shows three direct calls outside the approved route. By noon, legal is asking when the company discovered the incident and which systems were affected, then when management reached its materiality decision. SEC cyber disclosure AI audit evidence has to preserve that chronology. A folder of policy PDFs cannot reconstruct it.

TL;DR

  • The SEC cyber disclosure rules apply to cybersecurity incidents and public-company disclosure processes. They create no AI-specific control or logging obligation.
  • Freeze the full incident population before selecting samples, then preserve discovery and escalation timestamps, plus materiality and filing timestamps.
  • Use routed AI HTTP records as incident and materiality support only. Legal and disclosure owners retain the SEC conclusions.
  • Test annual Item 106 disclosures against operating evidence and board records, plus third-party dependencies and prior incidents.

Start with the SEC rule's actual scope

The SEC adopted its public-company cybersecurity rules on July 26, 2023. Release Nos. 33-11216 and 34-97989 created Form 8-K Item 1.05 for material cybersecurity incidents and Regulation S-K Item 106 for annual disclosures about cybersecurity risk management and strategy, plus governance.

The cyber-incident provision in Form 8-K requires a registrant to disclose an incident after the registrant determines it is material. The filing describes material aspects of the incident's nature and scope, plus its timing and its material impact or reasonably likely material impact. The determination must occur without unreasonable delay after discovery. The Form 8-K is generally due within four business days after that determination.

The rules apply to public companies subject to Exchange Act reporting. Comparable provisions address foreign private issuers through Form 6-K and Form 20-F. The SEC fact sheet gives the filing and annual-report structure in two pages.

AI appears only when it intersects the defined cyber event or the registrant's cyber-risk processes. A prompt injection and unauthorized LLM call, or an exposed model endpoint and AI-assisted response, can contribute facts. The rule itself prescribes no AI gateway, model inventory, prompt log, or model validation program.

Freeze the populations before fieldwork

Build a dated incident population for the review period. Include investigated alerts and confirmed incidents, third-party notices and data-loss events, service disruptions and policy bypasses, plus customer complaints and events later closed as benign. Preserve the query and source systems, filters and extraction time, row count and schema version, plus the content hash.

Reconcile that export with SOC cases and legal matters, privacy events and insurer notices, help-desk escalations and provider notifications, plus business-continuity records. For AI routes, compare policy-gateway events with application egress and API-management telemetry, plus provider usage. A missing row remains visible as a discrepancy instead of disappearing during cleanup.

I would stop the audit when the incident population cannot be reconciled. A reviewer-selected sample drawn from an unreliable denominator gives management a clean workpaper and investors a weak process.

Create two related populations:

  • Materiality decisions, including incidents assessed as immaterial or pending, plus those assessed as material, with decision authority and timestamps.
  • Disclosure actions, including Item 1.05 filings and Item 8.01 voluntary disclosures, amendments and annual Item 106 workpapers, plus approved delay records.

The populations need stable incident IDs. AI audit log chain of custody describes correlation and custody for request-level records.

Reconstruct discovery and materiality chronology

Select one incident and build its chronology from original records. Start with the first observable signal and the company's discovery point. Continue through triage and scope changes, legal escalation and management review, materiality determination and drafting, plus approval, filing, and amendment. Record timestamps in UTC with source references and named decision owners.

The materiality memo should apply the traditional securities-law standard and show all relevant facts and circumstances. The SEC's Division of Corporation Finance stated on May 21, 2024 that companies should consider qualitative factors alongside quantitative factors. Its staff statement on cybersecurity incident disclosure names reputation and customer or vendor relationships, competitiveness and litigation, plus regulatory investigations among possible considerations. The statement also says it has no legal force and creates no new obligation.

For an AI-related event, useful factual inputs may include affected identities and data categories, provider destinations and bypass routes, output exposure and duration, business workflows and customers, systems and remediation, plus continuing access. Those facts support the company's analysis. The gateway operator should never label an event SEC material as a technical policy outcome.

Preserve contrary evidence throughout the review. If the first estimate showed 18 affected records and the later count reached 48,000, retain both estimates and their timestamps, plus the reason for revision.

Test the four-business-day filing chain

The clock starts when the registrant determines materiality, rather than when the incident is discovered. Evidence should prove both dates and show that the determination occurred without unreasonable delay. Preserve the calendar calculation and disclosure-committee materials, legal review and filing authorization, plus the accepted EDGAR submission and any later amendment.

Delay evidence needs its own approval trail. The rule permits delay when the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. A request alone leaves the original filing obligation in place. The SEC's Form 8-K compliance and disclosure interpretations say the registrant must file within four business days of its materiality determination when the Attorney General declines or fails to respond before the deadline.

Test one filed incident backward through the record. Start with the EDGAR acceptance time, then retrieve the approval and final draft, the materiality decision and supporting chronology, plus the incident population row. Test one closed incident forward through the same process. Begin with discovery and verify the assessment and rationale, plus authorized closure and the later aggregation review.

Separate voluntary and required disclosures

The May 2024 staff statement encourages companies using Form 8-K voluntarily for an incident that is pending a materiality decision, or has been found immaterial, to use another item such as Item 8.01. If that incident later becomes material, the company should file an Item 1.05 Form 8-K within four business days of the later determination and satisfy Item 1.05's content requirements.

Build the evidence index so a reviewer can distinguish materiality pending or determined immaterial from determined material. Keep changes in status with dates and approvers instead of overwriting the earlier state.

Aggregation belongs in the workpaper too. The final rule's definition of cybersecurity incident includes a series of related unauthorized occurrences. Your process should identify related events across applications and subsidiaries, plus providers and time. A group of small unauthorized LLM calls may carry a different investor impact once the company sees the shared actor and data class, or the control failure.

One screen should show the incident IDs and linkage rationale. Supporting tabs retain raw events and investigator notes, plus the grouping approver.

Tie annual Item 106 statements to operating evidence

Regulation S-K Item 106 requires registrants to describe their processes, if any, for assessing and identifying material risks from cybersecurity threats, along with managing those risks. It also covers material effects or reasonably likely material effects, plus board oversight and management's role and expertise.

Build a disclosure-support matrix for each sentence in the annual draft. Link the statement to policies and operating procedures, committee charters and management reports, board minutes and risk assessments, incident exercises and third-party monitoring, plus open issues. Sample the operation described in the filing. If the filing says cybersecurity risk is integrated into enterprise risk management, select a cyber issue and trace it into the enterprise register and reporting cycle, plus the risk decision and board material.

AI-related cyber exposure may appear in that evidence when it is material to the registrant's process or risk. Preserve the approved route inventory and provider dependencies, plus response plans and unresolved bypasses. AI data lineage for audit can help connect a selected request to the affected business data without expanding the SEC rule into an AI governance mandate.

Preserve source records and independent review

An evidence package needs an index and data dictionary, a retention rule and access record, plus custody history. Restrict alteration and deletion while monitoring collection gaps. Test an old record's retrieval and verify its integrity. Tamper-evident audit logs for AI covers a separate write path for request decisions.

Keep the control owner and investigator, materiality decision maker and disclosure approver, plus the auditor distinct in the index. Internal audit should select samples from the frozen populations and retain failures. The incident team can explain context without curating away denials and missing identity, or direct-provider traffic.

Run a tabletop with a timed packet. Give legal a selected event showing a supplied user identity and approved application, restricted data classification and blocked provider destination, plus the policy version. Then introduce a bypass call found in provider billing. Measure how long the team takes to establish discovery and scope, business impact and related events, plus the decision authority. Retain the raw exports and corrections, not merely the polished after-action deck.

DeepInspect

DeepInspect is a stateless proxy that sits between authenticated users or agents and LLMs, enforcing identity-bound policy on HTTP AI traffic and producing per-decision audit records. It evaluates application-supplied identity and workflow context, applies destination and content policy, inspects the response, and writes a signed, tamper-evident record with the policy version and timestamp.

Those records can support an incident population and chronology, plus route reconciliation and selected-event reconstruction for traffic that crosses the proxy. DeepInspect leaves incident classification and materiality, SEC filing decisions and annual disclosure, identity proofing and business impact analysis, plus independent audit with the registrant's assigned owners. Local inference and direct browser use, opaque vendor activity and bypass traffic require separate controls and evidence. Book a demo today.

Frequently asked questions

Does the SEC cyber rule impose AI-specific audit logs?

The cited rules address material cybersecurity incidents and cybersecurity risk management and strategy, plus governance disclosures. AI request records can support those processes when an AI-related event falls inside their scope, but the rules prescribe no prompt log or AI gateway.

What AI evidence can support a materiality review?

For routed authenticated HTTP traffic, records can show the supplied principal and application, destination and content classification, policy version and decision, plus timestamp and response disposition. Business and legal impacts, financial and operational impacts, plus customer and regulatory impacts require records from their assigned owners.

Should every AI policy denial enter the incident register?

The company's incident-response criteria govern intake and escalation. Preserve enough telemetry to detect patterns and route events under those criteria. A denied request may be a prevented policy event or evidence of a broader campaign, including one occurrence in a related series.

Can the company wait four business days after discovery?

The general Form 8-K deadline is four business days after the registrant determines the incident is material. The registrant must make that determination without unreasonable delay after discovery. Preserve both timestamps and the work performed between them.

Where does an HTTP gateway stop providing evidence?

Its evidence stops at the traffic that traverses it. Local inference and direct browser sessions, embedded vendor AI and bypass calls need records from their actual systems. IAM owns identity proofing, while application owners bind authenticated identity and workflow context to each routed call.