SOX 302 in the AI Era: What Reasonable Care Looks Like When Your 10-K Talks About AI

Section 302 imposes personal certification duties on the CEO and CFO; the criminal penalty schedule that backs a false certification sits in Section 906 (18 U.S.C. § 1350)up to $1 million fine and 10 years in federal prison for a knowing violation, and up to $5 million and 20 years for a willful violation. That statute now reaches any 10-K language referencing AI. Here is what a documented reasonable care position looks like when the SEC is already prosecuting AI language.

In brief. SOX Section 302 requires principal executive and financial officers to certify periodic reports. Section 906 (18 U.S.C. § 1350) separately carries criminal penalties for false CEO/CFO certifications: up to $1 million and 10 years for a knowing violation, and up to $5 million and 20 years for a willful violation. When 10-K language includes AI, a versioned, four-eyes-approved, audit-trailed record of definitions used in disclosure is evidence of process. Compliance Glossary supplies that record.

Why SOX 302 lands on the CFO personally

Section 302 of the Sarbanes-Oxley Act (15 U.S.C. § 7241) requires the principal executive officer and principal financial officer, or persons performing similar functions, to certify annual and quarterly reports. Section 906 (18 U.S.C. § 1350) separately requires a CEO/CFO written statement for periodic reports containing financial statements and sets criminal penalties for false certifications: up to $1 million and 10 years for a knowing violation, and up to $5 million and 20 years for a willful violation.

The signature block on Form 10-Q and Form 10-K carries named officers. AI language in MD&A, risk factors, product descriptions, and revenue narratives can therefore become part of the disclosure-control record those officers rely on.

The AI disclosure problem

AI language is now common in MD&A, risk factors, capex narratives, and revenue-attribution discussion. Cornerstone Research / Stanford SCAC reported that AI-related securities class-action filings slightly increased to 16 filings in 2025, after 15 filings in 2024 (2025 Year in Review).

On April 9, 2025, the SEC and the U.S. Department of Justice filed parallel civil and criminal actions against Albert Saniger, the former CEO of Nate, Inc. The SEC alleged that he raised over $42 million from investors by making false and misleading statements about Nate's use of artificial intelligence (SEC Litigation Release No. 26282; DOJ release). Nate was a private-placement matter, not a 10-K Section 302 case. The lesson for public-company disclosure is narrower and still important: ambiguous AI claims need a controlled vocabulary and a review trail before they reach investor-facing materials.

The stakes, stated plainly

Section 302 creates the certification duty; Section 906 sets the criminal penalty schedule for false CEO/CFO certifications. An AI-related misstatement can also pull in disclosure-control review, auditor questions, SOX 404 remediation, and material-weakness analysis. The practical question for counsel and the audit committee is what the signing officer knew, what process supported the disclosure, and whether that process is documented.

What reasonable care looks like for AI language

Reasonable care is a process standard. For AI disclosure, it means showing that the company used definitions deliberately — not a single person's best recollection of what "AI-powered" meant last quarter, but a dated, reviewed, approved entry with a named approver and version history for each material term.

The terms that matter are specific: "AI-powered," "automated," "machine learning," "autonomous," "large language model," "high-risk AI system," "GPAI model," "substantial modification." When these appear in an investor deck, a press release, or a 10-K, they should mean the same thing they mean in internal policy and in the prior-quarter disclosure. If they drift, that drift becomes the fact pattern in an enforcement case.

Where Compliance Glossary fits, honestly

Compliance Glossary does not replace ICFR, SOX 404 testing, or disclosure controls and procedures. What it provides is a concrete, auditable artifact: a versioned, approved, audit-trailed set of canonical definitions for the terms that appear in MD&A, financial statements, footnotes, and AI-related disclosures. In a restatement, investigation, or audit committee review, the ability to point at a four-eyes-approved entry with version history is evidence of process. It is not a formal legal defense by itself.

The economics

For current pricing, see the Atlassian Marketplace.

Sources checked

Sources checked 2026-06-22: 15 U.S.C. § 7241 / SOX Section 302, 18 U.S.C. § 1350 / SOX Section 906, SEC Saniger litigation release, DOJ Saniger release, Cornerstone Research / Stanford SCAC 2025 Year in Review, and the European Commission AI Act timeline.

Frequently asked questions

What are the personal penalties under SOX 302?

Section 302 requires the principal executive officer and principal financial officer, or persons performing similar functions, to certify annual and quarterly reports. Section 906 (18 U.S.C. 1350) separately requires CEO/CFO certification statements and sets criminal penalties for false certifications: up to $1 million and 10 years for a knowing violation, and up to $5 million and 20 years for a willful violation.

Does Compliance Glossary replace ICFR or disclosure controls?

No. Compliance Glossary is not a substitute for ICFR, SOX 404 testing, or disclosure controls. It is a versioned, approved, audit-trailed record of the canonical definitions that appear in MD&A, financial statements, footnotes, and AI-related disclosures. That record supports a reasonable care position rather than replacing the control framework itself.

Why does AI language in a 10-K raise SOX 302 risk?

The SEC and DOJ have charged individual executives in AI-related cases (SEC v. Saniger, filed Apr. 9, 2025). Cornerstone Research / Stanford SCAC reported 16 AI-related securities class-action filings in 2025, slightly up from 15 in 2024. Those sources do not convert every AI statement into a SOX case, but they show that AI claims are an enforcement- and litigation-sensitive disclosure category.

How does a governed glossary support the disclosure-control record?

A four-eyes approved entry with version history, timestamps, and named approvers is concrete evidence of process. When counsel asks what steps were taken before signing a disclosure referencing AI, pointing to a dated, reviewed definition for terms like high-risk AI system, GPAI model, or AI-powered is a documented control artifact rather than a recollection. It is not a formal legal defense by itself.

Put a reasonable care artifact behind your next SOX 302 signature

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading