Do you know how your people are using AI? Why we need disclosure

Listen here

Post # 103

August 5, 2026

Claire Bodanis

Today, we published a data update from our research partner, Insig AI. It covers all FTSE 350 corporate documents from calendar year 2025 and looks at what’s changed about how companies are talking about AI since we published, in May last year, Your Precocious Intern: how to use generative AI responsibly in corporate reporting. Comparing the findings with those of the FRC’s recent qualitative study of the use of AI in corporate reporting, Claire reflects on why disclosure matters more than ever.

Last week, my lovely colleague Hilary Eastman and I were talking about the role of generative AI in corporate reporting; where it may be going, and how we should be advising clients about it. One particular comment has been going round in my head ever since. Hilary said: ‘I suspect we both end up in the same place in terms of what gen AI should be used for, but I come at it from an opportunity perspective, excited about the potential of what gen AI can do, whereas you come at it from a risk perspective, worrying about what can go wrong.’ 

She’s absolutely right – but why has it been playing on my mind? I realise it’s because I’ve never thought of myself as a cautious, risk-averse sort of person. In fact, I’ve rather prided myself on being someone who leaps on opportunities, gives things a go, jumps at chances – even if in doing so I am always (I hope!) tempered by common sense.

Don’t worry – this is not a navel-gazing blog about my inner psychological and philosophical tussles with AI – I’ll save that for our webinar discussions later in the year! The reason I mention it now is because these kinds of musings are going on in many people’s minds, affecting how they are and aren’t using generative AI in the workplace. And as yet, companies don’t seem to have much understanding of – or indeed control over – how their people are using it.

This matters, because, while generative AI tools have huge potential for good outcomes, they also have huge potential for bad ones. In the context of reporting, given what we know about how these tools work, the bad outcomes (as noted by investors in the research we published last year) relate to the accuracy of the information and the truthfulness of commentary.

Companies therefore ought to have a clear vision of how gen AI tools should be used to create value, and give their people guidance and training to ensure that they do, while mitigating the risks. Even if they don’t do that, companies should at least know what their people are doing with gen AI.

Which brings me to our data update (published today), and its relationship with the FRC’s study, published in July.

Our data update looked at what FTSE 350 companies are saying about AI in their corporate publications published in the 2025 calendar year; and we were looking particularly for any discussions of how it’s being used in reporting itself. This brings up to date our original quantitative research, which covered calendar years 2021-2024 inclusive. The FRC’s was a qualitative study, carried out by researchers at Lancaster University, and it asked people in FTSE 350 companies, through a survey and stakeholder interviews, how they are using AI tools in corporate reporting.

Taking the two sets of findings together, a gap appears between how companies seem to be using gen AI in reporting, and what’s being disclosed.

If you took our quantitative findings at face value – i.e. what reports are saying – you might conclude that hardly anyone is using generative AI in the reporting process itself. (After all, they’re not required to disclose it.) In 2024, the only mentions of generative AI in relation to reporting were two mentions related to creating imagery, which increased to four in 2025 for cover imagery, although only one was for the annual report itself. As for the use of generative AI in creating narrative, there was only one reference in the whole dataset (2021-2025) specifically about reporting – namely a statement by ZIGUP in the shareholder information section of their 2025 annual report that it had not been used.*

However, companies have started to refer to their use of generative AI for materials such as Board papers and ESG information, which are likely to feed into the reporting process and the annual report itself. And, anecdotally across the dataset, there are references to using gen AI for ‘content generation’, if not specifically for annual reports. Since they are specifying a couple of uses related to reporting without mentioning reporting itself, it’s not unreasonable to conclude they’re not using it in the latter case. 

But turn to the FRC research paper and we see a very different picture, one which suggests that generative AI is being used in reporting, even if it’s not being disclosed. Their survey generated 103 responses, and they held 39 interviews with senior IR and reporting people (with thanks to the many FW clients and friends who took part!).

The FRC’s overall conclusion was that ‘corporate reporting remains human-led amid growing adoption of artificial intelligence’; no doubt because ‘the premium that investors and other users of corporate reports place on authenticity, alongside accuracy and accountability, is prompting firms to take a cautious approach in high-judgement areas of reporting’. (Hurray.) Nonetheless they commented that:

…the trajectory of GenAI is notable. 39% of organisations report current use, with a further 31% piloting and 18% considering adoption within a year, this indicates GenAI may be in line to be as core to the reporting process as mature tools like ERP within a short space of time.

To my mind what was more significant – and worrying – was the discrepancy between what the survey revealed about usage and what senior people in interviews said about it (and yes, I hear these discrepancies did sometimes come from different people in the same company).

In fact, had I written that research paper, my headline would have come from the note buried about two thirds of the way down:

there may be a disconnect developing between actual use within an organisation and management or board awareness of that use.

This chimes with what one FTSE 100 company secretary told us when we did our own qualitative research in late 2024: ‘Would I be able hand on heart to say that none of my contributors had used gen AI to provide the bit they’ve sent in? I have no idea. 

Aside from the issues of accuracy and authenticity, not knowing how people are using gen AI strikes at the heart of other principles essential to the integrity of reporting, not least accountability and the validation of sources.

Eighteen months on, and with gen AI moving so quickly, I’d have thought more companies would be on the front foot, at least in terms of knowing what their teams are doing with gen AI and ensuring it’s creating value, even if they choose not to disclose it.

But since there’s clearly a significant gap – and a worrying one, considering the risks gen AI poses to accuracy and authenticity – perhaps it’s time to make an exception to my usual rule that the reporting disclosure tail should not wag the company dog.

After all, if companies had to disclose how they’re using gen AI in reporting, they’d make it their business to find out how it’s being used, and, no doubt, make sure it’s being used well.

And you never know – disclosure may be coming anyway, at least if you’re in the EU. On 10 June, the EU published its Code of Practice on Transparency of AI-generated Content, to ensure compliance with the AI Act transparency obligations. While it doesn’t refer to corporate reporting, that may not be far behind!

 

* ZIGUP’s disclosure statement in full:
ZIGUP has not used Generative AI for the purpose of providing content drafting for any section within this Annual Report and Accounts. Workflow tools such as Microsoft Co-Pilot have been used as part of normal productivity efficiencies such as meeting summaries and within photo-editing software for minor touch-ups. Tools are used by advisers for reviewing sentiment and confirming content compliance.