AI can make annual report work faster and, used well, better. But unreleased report content is often unpublished price sensitive information, so it can't go into a consumer chatbot. What to use AI for, what to keep human, and how to set up a private, API-based pipeline with a team workflow around it.
In this article
Key takeaways
- AI makes annual report work faster: first drafts from approved inputs, peer benchmarking and cross-section consistency checks can take hours instead of days.
- Quality can improve too, because AI is good at the checks people skip under deadline pressure, such as matching numbers across the MD&A, BRSR and financial statements.
- The first reader of an annual report is increasingly software. NBER research found companies with more machine downloads of their filings make them more machine-readable, so clear, consistent, well-structured writing now serves both audiences.
- AI can't own verification. People must check every figure against the audited source, handle client feedback and sign off every statement.
- Unreleased annual report content is often UPSI under SEBI's PIT Regulations. Pasting it into a consumer chatbot is hard to square with the legitimate-purpose, confidentiality and digital-database obligations that come with sharing UPSI.
- Paid APIs and enterprise plans from OpenAI, Anthropic and Google don't train on customer data by default, and Azure, AWS Bedrock and Google Cloud keep prompts away from the model makers. An internal RAG tool built on them is far safer, but only with per-client separation, access controls and secured logs.
Most annual report teams are already using AI. The question is whether they're using it openly, inside a process the client knows about, or quietly, in a browser tab nobody has approved. The second is where the risk lives.
Our view is simple. Agencies should use AI, and companies should let them. It makes the work faster, it can make the work better, and the audience for annual reports is changing in a way that rewards it. But it needs two hard limits: people own every number and every word, and confidential, unreleased content never goes into a consumer chatbot.
The short answer
Use AI for speed and for checking. Keep people on verification, judgement and feedback. And run anything confidential through a private, contract-covered setup (an enterprise plan, a paid API, or a model hosted in your own cloud account), never through a personal ChatGPT, Claude or Gemini account.
Why agencies and companies should be open to AI
It's faster, and annual reports are a deadline business
A large annual report is a four to five month project that ends in a crunch. Numbers arrive late, sections get rewritten after layout, and thousands of changes land between audited results and dispatch. Much of that time goes on work AI handles well:
- First drafts from approved inputs. A segment review drafted from the business head's interview notes, last year's section and the approved KPI sheet, ready for a writer to rework.
- Benchmarking. Reading thirty peer reports for how they handle capitals, risk or the BRSR, and summarising what the best ones do. These reports are public, so there's no confidentiality issue.
- Interview summaries. Turning a 90-minute recorded conversation with the CFO into a structured set of themes and quotes to verify.
- Format work. Alt text, captions, glossary entries, and first-pass translations for regional-language editions, all of which still need a human check.
None of this replaces the writer. It removes the blank page and the drudgery, so the writer's time goes on argument and clarity.
Quality can go up, not just speed
The checks that slip in the last fortnight are exactly the ones AI is good at. Does revenue in the chairman's message match the MD&A and the financial statements? Is it "net debt" on page 40 and "net borrowings" on page 212? Does every BRSR indicator the narrative mentions match the principle-wise table? Are the same five strategic priorities named the same way everywhere?
A model that reads the whole draft in one pass will flag inconsistencies that a tired proofreader on the fourth round won't. It can also check readability, find undefined abbreviations and hold the draft against the house style guide. Every flag still needs a person to decide what's right, but the net effect is a cleaner report.
Your next reader is probably a machine
Here's the part companies resist most, and shouldn't. More and more of the first reading of an annual report is done by software: analysts' models, data providers, ESG raters, and investors who ask an AI assistant to summarise the report before deciding whether to open it.
This isn't new, only faster. A 2020 NBER study of more than 400,000 US filings found that companies whose filings were downloaded more by machines went on to make them more machine-readable, and even avoided words that algorithms read as negative. Companies are already writing for software, whether they say so or not.
So the "it reads like AI wrote it" worry is aimed at the wrong thing. What matters is whether the content is accurate, clear and consistent, because that's what both a human reader and a machine reader reward. Plain sentences, defined terms, numbers in the text that match the tables, and a logical structure help an analyst's model as much as they help a shareholder. A report written that way, with AI's help or without it, will be summarised correctly. A vague one will be summarised vaguely.
What AI must not do
AI drafts and checks. People decide. In an annual report, that line matters more than in almost any other document, because every page carries the company's name and many carry legal weight.
| Task | AI's role | Who owns it |
|---|---|---|
| Narrative first drafts | Drafts from approved inputs | Writer rewrites; management approves |
| Numbers and KPIs | Flags mismatches across sections | Finance verifies every figure against the audited source |
| Client and board feedback | None beyond logging changes | Account lead reads, interprets and responds |
| Statutory and legal statements | Formatting and cross-references only | Company secretary and legal |
| Materiality and judgement calls | Can list options | Management and the board |
| Chairman's and CEO's messages | Can structure notes | Written and approved in the leader's own voice |
| Final proof and sign-off | Can run consistency checks | A named person signs off every page |
Two rows deserve emphasis. Numbers: language models still make up figures with total confidence, and a single wrong number in an annual report is a correction, a filing and a credibility problem. Every number must be checked against the audited source by a person, no matter how it was produced. Feedback: when a CFO writes "this doesn't sound like us" or a board member questions a claim, the response needs context, judgement and a relationship. Feeding client feedback into a chatbot and pasting back what it says is how agencies lose clients.
The confidentiality problem nobody talks about
Before an annual report is published, much of its content is confidential. Some of it is more than that. Under SEBI's Prohibition of Insider Trading (PIT) Regulations, information that isn't generally available and is likely to move the share price, such as financial results, is unpublished price sensitive information (UPSI). A draft annual report prepared before the results are out can contain plenty of it.
The PIT Regulations don't stop a company from sharing UPSI with its agency. Sharing with advisors and consultants for a legitimate purpose is allowed. But it comes with conditions: the board's policy defines what counts as a legitimate purpose, recipients are treated as insiders and must be given notice to keep the information confidential, and the company logs who received what in its structured digital database.
Now picture a writer pasting the draft MD&A into a personal chatbot account to tidy it up. The information has gone to a third party that isn't on the database, under consumer terms the company never agreed to. Whether that's a regulatory breach depends on the facts, but it's hard to square with the client's UPSI policy and almost certainly breaches the agency's confidentiality agreement.
Consumer terms matter here. On ChatGPT Free, Plus and Pro, conversations can be used to train OpenAI's models unless the user opts out. Since August 2025, consumer Claude users choose whether their chats are used for training, with five-year retention if they agree. Google says content sent to the free tier of the Gemini API can be used to improve its products and may be read by human reviewers. None of these is a place for an unpublished annual report.
Is an internal RAG tool on an AI company's API the answer?
Mostly yes, with three caveats that teams often miss.
Business products are covered by different terms. OpenAI's business and API data isn't used to train its models by default; API inputs and outputs are kept for up to 30 days for abuse monitoring, and zero data retention is available on approval. Anthropic's commercial terms bar training on customer content, and its consumer changes explicitly exclude the API, its business plans and access through Amazon Bedrock and Google Cloud. Google doesn't use paid Gemini API traffic to improve its products.
Going through a cloud provider adds another layer. On Microsoft's Azure, prompts and completions aren't available to OpenAI, aren't used to train models, and are processed in the geography you choose (unless you pick a "Global" or "Data zone" deployment). Amazon Bedrock doesn't share prompts or outputs with model providers either. For a company that already runs on one of these clouds, this is often the simplest route to something its IT and compliance teams will approve.
| Option | Trained on your content? | Retention | Fit for unreleased report content? |
|---|---|---|---|
| Consumer chatbot (free or individual paid plan) | Possibly, depending on plan and settings | Varies; up to five years where training is allowed | No |
| Business or enterprise chat plan | Not by default | Set by the plan and the admin | Yes, with a contract and admin controls |
| Paid API (OpenAI, Anthropic, Google) | Not by default | Up to 30 days for abuse monitoring; zero retention on approval | Yes, with a data processing agreement |
| Cloud-hosted models (Azure, AWS Bedrock, Google Vertex AI) | No | Under your cloud contract; region you choose | Yes, often the easiest to approve |
| Open-weight model on your own servers | No | Entirely yours | Yes, but costlier to run and usually less capable |
Now the caveats.
RAG doesn't keep data private by itself. Retrieval-augmented generation keeps your documents in your own store and pulls out the relevant passages when someone asks a question. Those passages are then sent to the language model with the question. The confidentiality comes from the model's terms, not from the RAG design, so the endpoint still has to be one of the business options above.
Agencies must separate clients. An agency holds several listed companies' UPSI in the same season. One shared index means one wrong query can surface another client's numbers. Each client needs its own store, and retrieval should respect the same access rights as the project folders: only the people on that account can query it.
The tool makes copies. A vector database, prompt logs and cached files are all copies of confidential content. Encrypt them, restrict access to them, and delete them on a schedule, for example once the report is published and the client's retention period ends.
Build the workflow before buying the tool
- Classify the content
Separate public information, confidential drafts and unpublished price-sensitive information.
- Approve the tools
Name the permitted enterprise accounts or API tools. Keep client work out of personal accounts.
- Agree the contract
Tell the client which providers process their data, under what terms, and obtain written agreement.
- Standardise the prompts
Use tested prompts tied to the house style guide for recurring tasks.
- Put people at review gates
Name the draft reviewer. Require a second person to check every number against its source.
- Keep a record
Log which tool touched which document so the work can be traced.
Human verification and final sign-off remain essential throughout.
The firms that use AI well rarely start with technology. They start with a short, written workflow that the whole team follows and the client has seen. It covers six things.
- Classify the content. Public (peer reports, published filings), confidential (drafts, strategy), and UPSI (unpublished results and anything price-sensitive). Each class gets a list of tools it may enter.
- Approve the tools. Name the specific enterprise accounts or API-based tools the team may use, and ban personal accounts for client work. A ban without an approved alternative just drives the use underground.
- Put it in the contract. Tell clients how AI is used, which providers process their data and under what terms, and get their written agreement. Some will want to approve the provider; that's reasonable.
- Write the prompts down. A shared library of tested prompts for the recurring tasks, tied to the house style guide, gives consistent output and stops everyone improvising.
- Set review gates. Name who checks AI-assisted drafts, and require a second person on every number. Mark AI-assisted sections in the working file so reviewers know where to look harder.
- Keep a log. Record which tool touched which document. If the client's compliance team ever asks, the answer takes minutes, not weeks.
Notice what isn't on the list: using AI for everything. Feedback calls, creative direction, management interviews and the final read stay human, because that's where the agency's judgement is, and judgement is what the client is paying for.
What companies should ask their agency
If you're hiring an annual report agency this season, add these questions to the brief:
- Do you use AI on client work, and for which tasks?
- Which tools and providers, under which plans? Do any of them train on our content?
- Where is our data processed and stored, and for how long?
- Is our content kept separate from other clients' in any AI tool you use?
- Who checks AI-assisted drafts, and who signs off the numbers?
- Will you sign a confidentiality undertaking that covers AI tools, so we can record you correctly in our structured digital database?
An agency that answers these clearly is one you can trust with AI. An agency that says it doesn't use AI at all is either behind or not telling you.
Our own approach
We use AI ourselves. It helps us research, draft and check. People review every piece and approve every word before it's published, and we only work from published information. It's the same principle we'd recommend to any agency: let the machine do the reading and the first draft, and let people do the judging.
Companies that insist on no AI at all will pay more and wait longer for reports that aren't better. Companies that allow it without rules will eventually see a draft where it shouldn't be. The sensible position sits between the two: open to AI, strict about where the data goes, and clear that a person signs off every page.
Frequently asked questions
Should annual report agencies use AI for content?
Yes, for the right tasks. AI is useful for first drafts written from approved inputs, peer benchmarking from published reports, summarising interviews, and checking that numbers and terms are consistent across sections. People should still verify every figure against the audited source, handle client feedback, and approve every word before it goes to the client.
Is it safe to put unreleased annual report content into ChatGPT or Claude?
Not into consumer versions. On ChatGPT Free, Plus and Pro, conversations can be used for training unless the user opts out, and consumer Claude users choose whether their chats are used. Unreleased annual report content often includes unpublished price sensitive information, so it should only go into tools covered by a business contract that rules out training, such as enterprise plans or the paid API.
Is unreleased annual report content UPSI?
Often, yes. SEBI's Prohibition of Insider Trading Regulations treat information such as financial results that isn't generally available and is likely to affect the share price as unpublished price sensitive information. A draft annual report prepared before results are public can contain it. Sharing UPSI is only allowed for legitimate purposes, recipients become insiders who must be told to keep it confidential, and the company records who received it in a structured digital database.
Does an internal RAG tool keep annual report data confidential?
It helps, but it isn't enough on its own. RAG keeps your documents in your own store, but the passages it retrieves are still sent to the language model with every question. Confidentiality depends on that model's terms: use a paid API or cloud-hosted model that doesn't train on your data, keep each client's documents in a separate index, restrict who can query what, and secure or delete the logs.
Which is safer for confidential documents: the OpenAI or Anthropic API, or Azure, AWS and Google Cloud?
Both can work. The OpenAI and Anthropic APIs don't train on customer data by default and keep inputs for up to 30 days for abuse monitoring, with zero data retention available on approval. Azure, AWS Bedrock and Google Cloud's Vertex AI run the models inside the cloud provider, so prompts aren't shared with the model maker, and you can choose where processing happens. Many companies that already use one of these clouds find that the simplest route.
What should AI not be used for in an annual report?
Final numbers and their sign-off, interpreting and responding to client or board feedback, statutory and legal statements, judgement calls such as materiality, and the leadership voice in the chairman's and CEO's messages. AI can help prepare these, but people must own them.
Sources
- How to Talk When a Machine is Listening?: Corporate Disclosure in the Age of AI (Working Paper 27950) — NBER
- Information Sharing Under SEBI's Insider Trading Rules — Mondaq (S&R Associates)
- SEBI (Prohibition of Insider Trading) Regulations: an overview — ICSI
- Enterprise privacy at OpenAI — OpenAI
- What if I want to keep my history on but disable model training? — OpenAI Help Center
- Updates to Consumer Terms and Privacy Policy — Anthropic
- Gemini API Additional Terms of Service — Google
- Data, privacy, and security for Foundry Models sold by Azure — Microsoft
- Security, privacy, and responsible AI: Amazon Bedrock — AWS



