Risk exposure broadened materially across five distinct themes — technology/AI, supply chain, regulatory compliance, cybersecurity, and market concentration — with nearly every change representing an escalation from theoretical to demonstrated or newly concrete harm. AI competitive risk is the sharpest single escalation: failure to deliver AI-capable solutions now carries explicit risk of customer defection, compounded by new AI-specific liability vectors (bias, data leakage, IP ownership). Regulatory and tax headwinds also intensified, with the EU AI Act, Cyber Resilience Act, expanded trade controls, and new U.S. tax legislation (One Big Beautiful Bill Act) all adding compliance cost and operational constraint.
7 company-specific
· 8 common-mode
Revised
ERP implementation shifted from prospective risk to realized disruption. Company now discloses actual impacts on order processing and invoicing, not just potential risks.
Initiatives to improve our cost structure, business processes, and systems may not achieve the expected benefits and could negatively impact our reputation, business, operating results, financial…
Revised
New disclosure that higher compensation costs may not be offset by innovation or sales; added shareholder approval risk for equity awards; removed sales force productivity language.
If we are unable to attract and retain qualified personnel, our business, operating results, financial condition and cash flows could be harmed. Our success depends on our ability to hire and retain…
Revised
Added AI vendor partnerships as critical to innovation; expanded risk scope to include partner service delivery failures and innovation impact.
If we are unable to maintain and develop relationships with strategic partners, our ability to innovate may be diminished and our revenues may be harmed. Our growth strategy relies on developing and…
Revised
New disclosure of U.S. public sector revenue concentration (10-11% of net revenues) and explicit risk of prolonged government shutdowns causing program cancellations and payment delays.
Reduced U.S. government demand could materially harm our business, operating results, financial condition and cash flows. The U.S. government is an important customer for us, but its demand is…
Revised
Escalated cloud provider concentration risk. Prior year mentioned "systemic risks" and observability failures; this year emphasizes "heightened systemic risks" and "significant disruption" impacting "multiple aspects" of operations—a material worsening of dependency exposure.
If a data center or other third-party who relies on our products experiences a disruption in service or a loss of data, such disruption could be attributed to the quality of our products. Our…
Revised
Added explicit expectation that infringement claims will "continue to increase" and shifted from "injunction" to broader "non-monetary relief," escalating severity.
We may be found to infringe on intellectual property rights of others. We compete in markets in which intellectual property infringement claims arise in the normal course of business. Third parties…
Revised
Debt reduced from $3.3B to $2.5B, but new explicit language on default consequences (bankruptcy/liquidation risk) materially escalates severity disclosure.
There are risks associated with our outstanding and future indebtedness. As of April 24, 2026, we had $2.5 billion aggregate principal amount of outstanding indebtedness for our senior notes that…
Also disclosed — common-mode (AI regulatory compliance ×2, Geopolitical macro uncertainty, Generative AI competition disruption, Tariffs trade policy, AI cybersecurity escalation, Export controls china restrictions, Global tax reform pillar two)
Geopolitical macro uncertainty
Revised
Added concrete examples of realized supply chain harm: inflationary pressure, margin impact, and Middle East conflict disrupting customer fulfillment. Escalates from theoretical to demonstrated risk.
Risks Related to Our Products and Services Any disruption to our supply chain could materially harm our business, operating results, financial condition and cash flows. We rely on third parties to…
Generative AI competition disruption
Revised
GenAI risk escalated from speculative to concrete competitive threat. New language emphasizes critical need to adapt products and go-to-market strategies, with explicit risk of customer defection to competitors if company fails to deliver AI-capable solutions across hybrid/multi-cloud environments.
Our business may be negatively impacted by technological trends in our market or our inability to keep pace with rapid industry, technological, and market changes. The growth in our industry and the…
AI regulatory compliance
Revised
Added specific risks: AI bias/inaccuracy causing customer trust loss, cybersecurity threats, third-party vendor management, IP ownership over AI-generated content, and inadvertent data leakage into public AI models.
Issues related to the development and use of artificial intelligence (AI), could lead to legal or regulatory action, damage our reputation, or otherwise materially harm our business. As a technology…
AI regulatory compliance
Revised
New substantive disclosures: third-party cloud provider data residency risks, intensified global regulatory enforcement trend, EU Cyber Resilience Act, Network and Information Systems Directive 2, and EU AI Act with high-risk system obligations. These represent newly articulated compliance risks and costs.
Failure to comply with new and existing laws and regulations related to privacy, data protection, AI and information security could cause harm to our reputation, result in liability (including…
Tariffs trade policy
Revised
Added concrete example of inflationary pressure and supply chain constraints in fiscal 2026 affecting margins. Escalates from generic risk to demonstrated adverse impact.
Our gross margins may fluctuate. Our gross margins are influenced by a variety of factors, including macroeconomic volatility, competitive pricing, customer price sensitivity, component and product…
AI cybersecurity escalation
Revised
Added specific AI threat escalation, phishing/spear-phishing/exfiltration attack types, SEC disclosure rules, and third-party breach liability exposure—substantively heightening cybersecurity risk profile.
If a material cybersecurity or other security breach impacts our services, systems, supply chain, or end-user customer systems, or if stored data is improperly accessed, our business could suffer…
Export controls china restrictions
Revised
Expanded scope: added customs regulations, international laws, China/semiconductor controls, and explicit mention of increased operating costs and market restrictions.
Any violation of U.S. or international customs or export control laws and other laws affecting the countries in which our products and services may be sold, distributed, or delivered could have a…
Global tax reform pillar two
Revised
New disclosure of One Big Beautiful Bill Act (July 2025) with specific tax law changes affecting R&D expensing and international tax framework. Consolidation of BEPS/Pillar Two/Amount B risks into single cohesive disclosure suggests heightened concern.
We could be subject to additional income tax liabilities. Our effective tax rate is influenced by a variety of factors, many of which are outside of our control, including fluctuations in our…