
A recent executive survey revealed AI errors have reached boards or external audiences.
getty
Control failures disclosed by responsible parties are rare and eye-opening.
That’s precisely what pops in Workiva’s 2026 Midyear Executive Benchmark Survey which stunningly revealed that 26% of senior leaders reported that an internal AI audit caught an error after it reached the board or, more dangerously, external audiences.
Even more troubling findings compounded that data flaw admissions. In the same survey, 84% of executives said they would be at least somewhat confident in AI output appearing in an annual report without human review. Yet only 11% said their organization’s data quality is sufficient for AI use.
Such complacency won’t fare well with antsy AI-era investors and regulators.
Workiva found that nearly all (96%) institutional investors indicated that AI governance oversight policies factor into investment decisions, including 62% who called it “very important.” Since there is currently no standardized framework for AI governance disclosure, investors must deduce a company’s stance by scouring 10-K risk factors, footnotes and earnings calls transcripts.
There’s little about data governance. A Conference Board and ESGAUGE analysis of found that while 72% of S&P 500 firms flagged at least one material AI risk last year, only 2% cited inaccurate outputs. Not surprisingly, 89% of the survey investors percent expressed concerned about AI accuracy in disclosures, with 47% responding that they watch closely for signs of AI generated errors.
That’s a risk-laden reporting mess disengaged boards and c-suites need to fix.
Danger, Danger
The sharpest division in the Workiva survey results surfaces by rank. Executives were surprisingly very confident in unreviewed AI output at 39%. The confidence of the professionals who handle the underlying data trailed at 29%.
Steve Soter, Workiva vice president and industry principal treats practitioner caution as competence rather than pessimism. As the people closest to the work grow accustomed to AI, they develop a better understanding of its risks, and “one of the factors that indicate rising maturity is the ability to ask better questions.”
That leaves the board, the eventual disclosure decision makers, dangerously and distantly holding the least-informed confidence. Asked what single, immediate structural change he would recommend to audit committees, Soter did not hedge.
“Stop accepting general assurances about AI and start requiring evidence. That means asking management, ‘where is AI being used in financial reporting and disclosure, and what documentation exists to show the output was reviewed and validated?’ Whether the audit committee asks this question, external auditors will certainly be asking, if they haven’t already. If management can’t answer how they are getting comfortable with AI in financial reporting, and prove it with evidence, the committee has found a gap that needs to be closed.”
Drowning Drops
AI data governance ups concerns for CEOs and CFOs, the executives who personally sign and certify that quarterly and annual financial reports are fairly presented and that they have established and evaluated disclosure controls and procedures. That mandate did not envision the “black box” risk of AI reliance.
“The rules haven’t changed, but evidence is more critical and more complex than ever before,” Soter argued. Organizations with review checkpoints, validation steps and documentation requirements related to AI-assisted workflows tend to catch errors with well-designed and effective controls.
“If management says AI-assisted work was appropriately reviewed, they need to be able to demonstrate that review with documentation. That means being able to trace where the data came from, how the model used it and that a qualified person evaluated the result before it went out the door,” he explained.
Even with well-governed reporting processes, Soter noted, generic large language models “can produce polished, inaccurate outputs that give an illusion of quality.”
“The most dangerous errors aren’t the ones that are obviously wrong,” Soter warned. “They’re the ones that look right, sound authoritative, and nobody thinks to question. If there’s no way to follow an AI output back to the data that produced it, you may not even know [there’s] a problem.” Especially when the AI outputs reach the boardroom or beyond.
Three Steps
Soter offered three actions AI-reliant boards can and should expect from c-suites:
1. Trace, then certify. Identify every place AI touches financial reporting and disclosure, then determine whether each output can be traced back to source data. The test is whether a CFO can sit across from an investor, auditor or regulator and explain exactly how a number was produced. Any process that fails is unacceptable.
2. Convert assurance into evidence. Replace management’s verbal comfort with documentation showing what was reviewed, by whom, and against some standard. Review checkpoints, validation steps and retention requirements are what separate an isolated error caught downstream from a pattern that will scream design failure and trigger unwanted disclosures and potential restatements.
3. Close investor signal gaps. Institutional investors now weigh AI governance heavily, even absent a standard disclosure framework. Decide deliberately and decisively what risk factors, homogenized footnotes and curated earnings call commentary convey. Omissions and corporate-speak erode stakeholder confidence.
Leadership’s (in)action that follows will reveal much. Worse it can open preventable exposure for inaccurate disclosure, lax governance and bad decisions.
What’s really artificial?