Item 1A. Risk Factors
Item 1A. Risk Factors.
Investing in our common stock involves a high degree of risk. You should carefully consider the risks and uncertainties described below, together with all of the other information in this Annual Report on Form 10-K, including the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations” and our consolidated financial statements and related notes, before deciding to invest in our common stock. Our business, results of operations, financial condition, and prospects could also be harmed by risks and uncertainties not currently known to us or that we currently do not believe to be material. If any of the risks actually occur, our business, results of operations, financial condition and prospects could be harmed. In that event, the market price of our common stock could decline, and you could lose part or all of your investment.
17
Table of Contents
Risks Related to Our Business and Our Financial Condition
Our ability to continue as a going concern depends on, among other factors, our financial condition and operating performance, which are subject to prevailing economic and competitive conditions and certain financial, business and other factors beyond our control.
Based on our liquidity position at December 31, 2025 and our current forecast of operating results and cash flows, absent any other action, management determined that there is substantial doubt about our ability to continue as a going concern over the twelve months following the filing of this Annual Report on Form 10-K, principally driven by the maturity of our Convertible Notes, along with historical negative cash flows and recurring losses. In past fiscal quarters, based on our liquidity position at the end of such fiscal quarter and our then-current forecast of operating results and cash flows, management has determined that there has been a substantial doubt about our ability to continue as a going concern over the twelve months following such determination. Our ability to continue as a going concern is dependent on our ability to generate significant cash flows, obtain sufficient proceeds from any future offerings of securities, and/or obtain alternative financing prior to the maturity of the Convertible Notes. Any future determination that we may be unable to continue as a going concern may materially harm our business and reputation and may make it more difficult for us to obtain financing for the continuation of our operations, including through equity financings, incurring additional debt or otherwise, which in turn, may adversely impact our financial condition, results of operations and cash flows.
In the near term, to ensure we continue to meet our cash obligations as they come due, we continue to evaluate strategies to obtain funding for future operations. These strategies may include, but are not limited to, obtaining debt and equity financing, and repurchasing or repaying our Convertible Notes prior to their maturity in November 2026. In addition, we plan to further restructure our operations to grow revenues and decrease operating expenses, which include capturing past cost reduction and potential future cost synergies from our past acquisitions.
For example, in the fiscal years ended December 31, 2024 and December 31, 2025, we entered into a series of transactions to reduce our debt obligations, including equity financings, asset sales, the repayment of our senior secured term loan (the “Term Loan”) and the repurchase of certain of our Convertible Notes. As of December 31, 2025, approximately $45.6 million aggregate principal amount of the Convertible Notes remain outstanding, which will come due in November 2026.
The going concern assumption contemplates the realization of assets and satisfaction of liabilities in the normal course of business. We may not be able to access additional equity under acceptable terms, and may not be successful in future operational restructurings, earning any of our deferred purchase consideration, or at growing our revenue base, and our ability to execute on our operating plans may be materially adversely impacted. If we are unable to capture past cost reduction and potential future cost synergies from our past acquisitions, we would likely not have sufficient cash on hand or available liquidity to repay our Convertible Notes upon their maturity in November 2026, and our ability to execute on our operating plans may be materially adversely impacted. If we become unable to continue as a going concern, we may have to dispose of other or additional assets and might realize significantly less value than the values at which they are carried on our consolidated financial statements. These actions may cause stockholders to be further diluted or to lose all or part of their investment in our common stock. In addition, if we dispose of certain of our assets in order to generate additional liquidity, our revenue may be reduced and our business may become less diversified. If we cannot continue as a going concern, adjustments to the carrying values and classification of our assets and liabilities and the reported amounts of income and expenses could be required and could be material.
Our efforts to expand our aiWARE SaaS business may not be successful.
In order for us to grow our aiWARE SaaS business and achieve profitability, we must expand our revenue base by expanding our customer base and increasing our business with existing customers. We may not be able to succeed with respect to these efforts. Many factors may adversely affect our ability to grow the business for our aiWARE platform, including but not limited to:
• Failure to add market-specific applications to our aiWARE platform with sufficient levels of capability to provide compelling benefits to users in our target vertical markets;
• Failure to add AI models with sufficient levels of capability or trainability into our platform, difficulties integrating AI models and loss of access to, or increases in the cost of, AI models;
• Inability to expand the number of AI models in different classes that can operate in a network-isolated manner, which would limit the capabilities of aiWARE available in our FedRAMP environment or under private cloud, on-premises and hybrid deployment models;
18
Table of Contents
• Difficulties in adding technical capabilities to our platform and ensuring future compatibility of additional third party providers;
• Failure to articulate the perceived benefits of our solutions, or to generate broad customer acceptance of or interest in our solutions;
• Failure to source the amount of or types of content in the timeframe required to fulfill VDR customer demand; for example, we have in the past been unable to source the volume or specific type of content or data in the timeframes our VDR customers required;
• Introduction of competitive offerings by larger, better financed and more well-known companies;
• Introduction of new products or technologies that have performance and/or cost advantages over our aiWARE platform;
• Inability to integrate our solutions with products of other companies to pursue particular vertical markets, or the failure of such relationships to achieve their anticipated benefits;
• Long and complex sales cycles, particularly for customers in the Public Sector markets; and
• Challenges in operating our platform on secure government cloud platforms and complying with government security requirements.
If we fail to grow the business for our aiWARE platform, including our VDR product, our business, results of operations and financial condition will suffer.
The market for AI-based software applications is relatively new and unproven and may decline or experience limited growth. Concerns over the use of AI, including from regulators, the public and our customers, may hinder the adoption of AI technologies, which would adversely affect our ability to fully realize the potential of our Software Products & Services.
We use machine learning and AI, including generative AI and automated decision-making technologies, in our products and services. The market for AI-based software applications is still relatively new and evaluating the size and scope of the market is subject to a number of risks and uncertainties. We believe that our future success will depend in large part on the growth of this market. The utilization of our platform and solutions by customers is also still relatively new, and customers may not recognize the need for, or benefits of, our platform and solutions, which may prompt them to cease use of our platform and solutions or decide to adopt alternative products and services to satisfy their cognitive computing, search and analytics requirements. Our ability to access and extend our position in the markets that our platform and solutions are designed to address depends upon a number of factors, including the cost, performance and perceived value of our platform and solutions, as well as regulatory scrutiny over our products and technologies. As AI technologies become increasingly incorporated into various mainstream products and offerings and these technologies advance and develop legal and regulatory scrutiny of AI technologies, potentially including our products, has and will likely continue to increase. For additional information about the legal and regulatory risks related to our use of AI technologies in our Software Products & Services, see the below Risk Factor titled “Recent and proposed regulation of AI technologies, including facial recognition technology, the processing of biometric data, and automated decision-making and machine learning technologies, increase our compliance costs and otherwise make it harder for us to conduct our business, require us to change our business practices, and may lead to regulatory investigations or actions, litigation, reputational harm, and otherwise have a material adverse effect on our business.”
In addition, the development and use of AI technologies presents risks and challenges that could hinder its further development, adoption and use in the markets that we serve. For example, due to potential inaccuracies or flaws in the inputs, outputs or logic of AI technologies, the model could result in decisions that bias certain individuals (or classes of individuals) and adversely impact their rights, employment and ability to obtain certain pricing, products, services or benefits. If we enable or offer AI solutions that produce biased or inaccurate outputs and analyses, or that are perceived as controversial due to human rights, privacy or other social issues, we may experience lower-than-expected demand for our products and services, or competitive, brand or reputational harm. Multiple states in the United States, as well as the European Union and other jurisdictions, have enacted or proposed legislation regulating the use of AI. These regulations include requirements for increased transparency, mandatory disclosures and the implementation of mitigating measures to address potential risks associated with AI technologies. Compliance with these laws may impose additional costs, operational adjustments, or restrictions on our use of AI, and noncompliance could result in regulatory penalties, reputational harm, or other adverse impacts. As this regulatory landscape continues to develop, new or more stringent requirements could emerge, further affecting our business operations and ability to leverage AI technologies effectively.
19
Table of Contents
Market opportunity estimates are subject to significant uncertainty and are based on assumptions and estimates, including our internal analysis and industry experience. Assessing the market for our solutions is particularly difficult for several reasons, including limited available information and rapid evolution of the market. If the market for AI-based software applications does not experience significant growth, or if demand for our platform or solutions does not increase in line with our projections, then our business, results of operations and financial condition will be adversely affected.
Certain of our operating results and financial metrics are difficult to predict and subject to volatility, including as a result of seasonality.
We experience quarterly variations in the timing of revenues from our Software Products & Services as a result of numerous factors, such as the timing of large projects, the length and complexity of our sales cycles and trends impacting our target vertical markets. In particular, our Talent Acquisition solutions have historically experienced seasonality in terms of when we enter into customer agreements for our products and services. Consistent with the hiring patterns of many of our customers, a higher percentage of related revenue is earned in the second half of each year. Within a given quarter, a significant portion of our agreements are often signed toward the end of the quarter. This seasonality is reflected to a lesser extent in our revenue due to the fact that we generally recognize subscription revenue over the term of the customer agreement. We expect this seasonality to continue, which may cause fluctuations in certain of our operating results and financial metrics, and thus, difficulties in predictability of our operating results.
We have had a history of losses and we may be unable to achieve or sustain profitability.
We experienced net losses of $111.7 million and $37.4 million in fiscal years 2025 and 2024, respectively. As of December 31, 2025, we had an accumulated deficit of $579.0 million. We expect to continue to expend substantial financial and other resources on, among other things:
• investments to expand and enhance our platform and technology infrastructure, make improvements to the scalability, availability and security of our aiWARE platform, and develop new products;
• sales and marketing, including expanding our direct sales organization and marketing programs, and expanding our programs directed at increasing our brand awareness among current and new customers;
• hiring additional employees;
• investment in our operations and infrastructure, both domestically and internationally; and
• general administrative expenses, including legal, accounting and other expenses.
These expenditures may not result in increased revenue or growth of our business. We may not be able to generate additional revenues sufficient to offset our expected cost increases and planned investments in our business and platform. As a result, we may incur significant losses for the foreseeable future, and may not be able to achieve and sustain profitability. If we fail to achieve and sustain profitability, then we may not be able to achieve our business plan, fund our business or continue as a going concern.
We may pursue the opportunistic acquisition of other companies, businesses or technologies, which could be expensive, divert our management’s attention, fail to achieve the expected benefits and/or expose us to other risks or difficulties.
As part of our growth strategy, we have acquired, and we may continue to acquire, businesses, services, technologies or intellectual property rights that we believe could complement, expand or enhance the features and functionality of our aiWARE platform and our technical capabilities, broaden our product and service offerings or offer growth opportunities for our business. This acquisition strategy may divert the attention of management and cause us to incur various expenses in identifying, investigating and pursuing suitable acquisitions, whether or not such acquisitions are consummated. Acquisitions could also result in dilutive issuances of equity securities, the incurrence of debt, contingent liabilities, amortization expenses, impairment of goodwill and/or purchased long-lived assets, and restructuring charges, any of which could adversely affect our operating results and financial condition. In addition, we may face risks or experience difficulties successfully integrating acquired businesses, such as Broadbean, with our operations. These risks include:
• effectively managing the combined business following the acquisition, including any international operations of the acquired business and integrating the acquired company’s accounting, human resources and other administrative systems, and coordination of product, engineering and sales and marketing functions;
• the potential loss of key employees and customers as a result of competing in the markets in which the acquired company operates;
20
Table of Contents
• cultural challenges associated with integrating employees from the acquired company into our organization, and retention of employees from the businesses we acquire; and
• achieving anticipated cross-selling opportunities and eliminating any redundant operations with respect to the acquired business.
We also may not achieve the anticipated benefits from the acquired business and may incur unanticipated costs and liabilities in connection with any such acquisitions. Additionally, if we are unable to complete an acquisition, we could lose market share to competitors who are able to make such an acquisition. Once an acquisition is closed, we may discover hidden costs, resource demands and potential liabilities that were not evident during the due diligence process, particularly when such process is undertaken on an accelerated timeline. Although we often utilize representation and warranty insurance and standard indemnity provisions in these acquisition transactions, if we are unable to successfully assert a claim, if a claim is not covered by insurance or if these hidden costs prove greater than expected, our operations as a whole may be adversely affected. In addition, a significant portion of the purchase price of companies we acquire may be allocated to acquired goodwill and other intangible assets, which must be assessed for impairment at least annually. If any of these results occurs, our business and financial results could be adversely affected.
Our international operations expose us to significant risks, and we intend to continue expanding international operations going forward.
As part of our growth strategy, we may expand our operations further internationally. As of December 31, 2025, we had operations in the United Kingdom, other parts of Europe, Israel, Australia and India, and we may, in the future, open offices and hire employees in additional locations outside of the United States to service existing global customers, reach new customers and gain access to additional technical talent. Operating in and expanding to new international markets requires significant resources and management attention and will subject us to uncertain regulatory, tax, economic and geopolitical risks. Because of our limited historical experience with expanded international operations, as well as developing and managing sales in international markets, our international expansion efforts may not be successful. In addition, we will face risks of doing business internationally that could adversely affect our business, including, but not limited to:
• managing and staffing international operations and the increased operating, travel, infrastructure and legal compliance costs associated with numerous international locations;
• establishing and managing additional instances of our aiWARE platform in other countries;
• adapting, localizing and pricing our products and services for specific countries and offering customer support in various languages;
• additional foreign tax requirements and obligations, and adverse tax consequences and tax rulings;
• economic conditions, international conflicts and political instability in some countries;
• compliance with local laws, regulations and customs in foreign jurisdictions, particularly in the areas of data privacy and personal privacy, employment and tax and export controls, economic sanctions and anti-corruption laws; and
• limited protection for intellectual property rights in some countries.
Our failure to manage any of these risks successfully could harm our existing international operations, interrupt our expansion plans and adversely affect our business, results of operations and financial condition.
Our business has been and may continue to be negatively affected by macroeconomic and geopolitical factors, including lingering economic disruption caused by international conflicts, financial instability, inflation and the responses by central banking authorities to control inflation, monetary supply shifts, the imposition of tariffs and other global trade disputes, and the threat of recession in the United States and around the world.
21
Table of Contents
Global economic and business activities continue to face widespread macroeconomic and geopolitical uncertainties, including lingering economic disruption caused by international conflicts, financial instability, inflation and the responses by central banking authorities to control inflation, monetary supply shifts, the imposition of tariffs and other global trade disputes, and the threat of recession in the United States and around the world. We continue to actively monitor the impact of these macroeconomic factors on our financial condition, liquidity, operations, suppliers, industry and workforce, and instituted certain cost saving measures during 2023 through 2025 as a result of these factors. The extent of the impact of these factors on our operational and financial performance, including our ability to execute our business strategies and initiatives in the expected time frame, will depend on future developments, and the impact on our customers, partners and employees, all of which are uncertain and cannot be predicted. These and other global economic conditions, including any new disruptions, have in the past and may in the future again negatively impact our business. For example, business operations at our Herzliya, Israel office location where we perform development work on our Talent Acquisition solutions, have been, and may continue to be, impacted by the Israel-Hamas and Iran conflicts. In addition, a small portion of our Israel-based employees, and a number of their family members, have been conscripted into military service. In addition, our Talent Acquisition solutions are sold to businesses that experience performance fluctuations based on factors including the demand for labor and the economic health of current and prospective employers. To the extent that economic uncertainty or attenuated economic conditions cause our current and potential customers to freeze or reduce their headcount, demand for our products and services has been, and may continue to be negatively affected. Adverse economic conditions have also caused and could continue to result in reductions in sales of our applications, longer sales cycles, reductions in contract duration and value, slower adoption of new technologies and increased price competition. In addition, economic recessions have historically resulted in overall reductions in spending on software and technology solutions as well as pressure from customers and potential customers for extended billing terms. If economic, political, or market conditions deteriorate, or if there is uncertainty around these conditions, our current and potential customers may elect to decrease their software and technology solutions budgets by deferring or reconsidering product purchases, which could limit our ability to grow our business and negatively affect our operating results. Any of these events would likely have an adverse effect on our business, operating results and financial position.
We depend on our executive officers and other key employees, and the loss of one or more of these executive officers or key employees or an inability to attract and retain highly skilled employees could adversely affect our business.
Our success depends largely upon the continued services of our President, Chief Executive Officer and Chairman of our Board, Ryan Steelberg, and our other executive officers and senior management. We rely on our leadership team in the areas of strategy and implementation, research and development, operations, security, marketing, sales, support and general and administrative functions. We do not currently have any employment agreements with our executive officers or senior management team that require them to continue to work for us for any specified period, and, therefore, they could terminate their employment with us at any time. The loss of Ryan Steelberg, or one or more of our executive officers or members of our management team, could adversely impact our business and operations and disrupt our relationships with our key customers.
Our future success also depends, in part, on our ability to continue to attract and retain highly skilled personnel. We believe that there is, and will continue to be, intense competition for highly skilled management, engineering, data science, sales, marketing and other personnel with experience in the businesses in which we operate. We must provide competitive compensation packages and a high-quality work environment to hire, retain and motivate employees. If we are unable to retain and motivate our existing employees and attract qualified personnel to fill key positions, we may be unable to manage our business effectively, including the development, marketing, sale and delivery of our products and services, which could adversely affect our business, results of operations and financial condition.
22
Table of Contents
Our ability to use our loss carryforwards may be limited.
As of December 31, 2025, we had U.S. federal, state and foreign loss carryforwards (“NOLs”) totaling approximately $195.1 million, $173.3 million and $40.0 million, respectively. The U.S. federal and state NOLs are projected to expire beginning in 2037 and 2030, respectively, unless previously utilized. The U.S. federal NOLs generated in tax years beginning on or after January 1, 2018 may be carried forward indefinitely, subject to an 80% taxable income limitation on the utilization of the NOLs. The foreign NOLs can be carried forward indefinitely. In addition, our U.S. federal NOLs may be subject to limitations under Section 382 of the Internal Revenue Code of 1986, as amended (the “Code”), if we have undergone or undergo an “ownership change,” generally defined as a greater than 50 percentage point change (by value) in our equity ownership by certain stockholders over a rolling three-year period. We may have experienced such ownership changes in the past and may experience ownership changes in the future as a result of shifts in our stock ownership, some of which are outside our control. Our NOLs may also be impaired or restricted under state law. For example, California enacted legislation that, with certain exceptions, suspends the ability to use California NOLs to offset California income and limits the ability to use California business tax credits to offset California taxes, for taxable years beginning on or after January 1, 2024, and before January 1, 2027. Such state tax law provisions could accelerate or permanently increase state taxes owed. There is also a risk that due to other future regulatory changes, such as suspensions on the use of NOLs in other jurisdictions, or other unforeseen reasons, our existing NOLs could expire or otherwise be unavailable to offset future income tax liabilities. If we earn taxable income, such limitations could result in increased future income tax liability and our future cash flows or results of operations could be adversely affected.
If we do not comply with transfer pricing, income tax, customs duties, VAT, and similar regulations, we may be subject to additional taxes, customs duties, interest, and penalties in material amounts, which could materially harm our financial condition and operating results.
As a multinational corporation operating in many countries, we are subject to transfer pricing, income tax, and other tax regulations designed to ensure that our intercompany transactions are consummated at prices that have not been manipulated to produce a desired tax result, that appropriate levels of income are reported as earned by our United States and local entities, and that we are taxed appropriately on such transactions. In addition, our operations are subject to regulations designed to ensure that appropriate levels of customs duties are assessed on the importation of our products.
If the United States Internal Revenue Service (the “IRS”) or the taxing authorities of any other jurisdiction were to successfully challenge our transfer pricing practices or our positions regarding the payment of income taxes, customs duties, value added taxes, withholding taxes, and sales and use and other taxes, we could become subject to higher taxes and may increase product prices in certain jurisdictions accordingly. The imposition of new taxes, even pass-through taxes such as VAT could result in increased product prices in certain jurisdictions. Any increases in prices could adversely affect product demand and therefore could have a negative impact on our business, financial condition, and operating results. From time to time, we are a party to various regulatory proceedings related to compliance with applicable tax regulations, including audits, examinations, and investigations.
In addition, any change in applicable tax laws, rules, treaties, or regulations, or their interpretation, could result in a higher effective tax rate on our worldwide earnings. For example, the Organization for Economic Co-operation and Development (“OECD”) has led in the development of the Two-Pillar framework, which involves the reallocation of taxing rights in respect of certain multinational enterprises above a fixed profit margin to the jurisdictions in which they carry on business (referred to as Pillar One), and imposes a minimum effective corporate tax rate (referred to as Pillar Two). A number of countries in which we conduct business have enacted, or are in the process of enacting, elements of the Pillar Two rules (with further provisions expected to be enacted in the future). The OECD has issued (and is expected to continue to issue further) administrative guidance providing transition and safe harbor rules in relation to the implementation of the Pillar Two proposal. For example, on January 5, 2026, the OECD published details of a proposed “side-by-side” arrangement providing for, among other things, additional safe harbors for multinational groups headquartered in certain qualifying jurisdictions. We continue to evaluate and assess the potential impact of the OECD framework on the Company. No assurances can be given that future legislative, regulatory, or judicial developments will not result in an increase in the amount of taxes payable by us. If any such developments occur, our business, financial condition, and operating results could be materially and adversely affected.
23
Table of Contents
Risks Related to the Development and Operation of Our aiWARE Platform and Other Products
If we are not able to enhance our existing products or introduce new products that achieve market acceptance and keep pace with technological developments, our business, results of operations and financial condition could be harmed.
Our ability to attract new customers and increase revenue from existing customers depends in part on our ability to enhance and improve our aiWARE platform and applications and introduce new products and features, including enhancements necessary to provide substantially all of the features and functionality of the platform within a private cloud or on-premises environment, as well as new applications to address additional customer use cases. The success of any enhancements or new products depends on several factors, including timely development completion, adequate quality testing, actual performance quality, market-accepted pricing levels and overall market acceptance and demand. Enhancements and new products that we develop may not be introduced in a timely or cost-effective manner, may contain defects, may have interoperability difficulties with our aiWARE platform, or may not achieve the market acceptance necessary to generate significant revenue. If we are unable to successfully enhance our aiWARE platform and applications to meet evolving customer requirements and develop new products and applications, or if our efforts to increase the usage of our aiWARE platform are more expensive than we expect, then our business, results of operations and financial condition could be harmed.
Our competitors, partners or others may acquire third party technologies, including AI models, used in our aiWARE platform, which could result in them blocking us from using the technology in our aiWARE platform, offering it for free to the public or making it cost prohibitive for us to continue to incorporate their technologies in our aiWARE platform, or these third party technology providers may otherwise terminate their relationships with us, which could adversely affect the functionality of our aiWARE platform.
Our success depends in part on our ability to attract, incorporate and maintain high performing AI models on our aiWARE platform. If any third party acquires an AI model that is on our platform, they may preclude us from using it as a component of our platform or make it more expensive for us to utilize. In addition, a third-party AI model provider may terminate its relationship with us or may otherwise cease to make its AI models available to us. In either case, if that AI model has unique capabilities or a significant performance advantage over other models and we are unable to identify a suitable replacement model, the interruption could cause us to lose customers. It is also possible that a third-party acquirer of such technology could offer the AI models and technologies to the public as a free add-on capability, in which case certain of our customers would have less incentive to pay us for the use of our platform. If a key third party technology becomes unavailable to us or is impractical for us to continue to use, the functionality of our platform could be interrupted, and our expenses could increase as we search for an alternative technology. As a result, our business, results of operations and financial condition could be adversely affected through the loss of customers and/or from increased operating costs.
We rely on third parties to develop AI models for our platform and in some cases to integrate them with our platform.
A key element of our aiWARE platform is the ability to incorporate and integrate AI models developed by multiple third-party vendors, and we plan to continue to increase the number of third-party AI models incorporated into our aiWARE platform to enhance the performance and power of our platform. As we work to add new AI models to our platform, we may encounter difficulties in identifying additional high-quality AI models (particularly high performing, specialized models), entering into agreements for their inclusion in our ecosystem on acceptable terms or at all and/or in coordinating and integrating their technologies into our system. We may incur additional costs to modify and adjust existing functionalities of our platform to accommodate multiple classes of AI models, without the assurance that such costs can be recouped by the additional revenues generated by the new capabilities. As aiWARE becomes more complex and as we release enhancements to our platform that require changes to AI models, we may not be able to integrate third-party AI models in a seamless or timely manner due to a number of factors, including incompatible software, lack of cooperation from developers, insufficient internal technical resources, platform security constraints, and the inability to secure the necessary licenses or legal authorizations required. In addition, we have established a self-service development environment in which such third-party developers integrate their AI models onto our platform, and we will be dependent in part upon their ability to do so effectively and quickly. We may not have full control over the quality and performance of third-party providers, and therefore, any unexpected deficiencies or problems arising from these third-party providers may cause significant interruptions in the operation of our platform. The failure of third party developers to integrate their AI models seamlessly into our platform and/or provide reliable, scalable services may impact the reliability of our platform and harm our reputation and business, results of operations and financial condition.
24
Table of Contents
If we are not able to develop a strong brand for our aiWARE platform and other products and increase market awareness of our company, platform and other products, then our business, results of operations and financial condition may be adversely affected.
We believe that the success of our platform will depend in part on our ability to develop a strong brand identity for our “Veritone”, “aiWARE” and other service marks, and to increase the market awareness of our platform and its capabilities. We are still in the early development stage of our business and, as such, our brand is not yet well established. The successful promotion of our brand will depend largely on our continued marketing efforts and our ability to ensure that our technology provides the expected benefits to our customers. We also believe that it is important for us to be thought leaders in the AI-based cognitive computing market. Our brand promotion and thought leadership activities may not be successful or produce increased revenue. In addition, independent industry analysts often provide reviews of our platform and of competing products and services, which may significantly influence the perception of our aiWARE platform in the marketplace. If these reviews are negative or not as positive as reviews of our competitors’ products and services, then our brand may be harmed.
The promotion of our brand also requires us to make substantial expenditures, and we anticipate that these expenditures will increase as our industry becomes more competitive and as we seek to expand into new markets. These higher expenditures may not result in any increased revenue or in revenue that is sufficient to offset the higher expense levels. If we do not successfully maintain and enhance our brand, then our business may not grow, we may see our pricing power reduced relative to competitors and we may lose customers, all of which would adversely affect our business, results of operations and financial condition.
The security or operation of our platform, networks, computer systems or data, or those of third parties with whom we work, have in the past, and may in the future, be breached or otherwise compromised, and any such breach or other compromise could have a material adverse effect on our business and reputation.
In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclosure, make accessible, protect, secure, dispose of, transmit, and share (collectively, “process”) personal data and other sensitive information, including proprietary and confidential business data, trade secrets, intellectual property, sensitive third-party data, business plans, transactions, financial information, customer data and biometric data (collectively, sensitive data). Certain data privacy and security obligations require us to implement and maintain specific security measures or industry-standard or reasonable security measures designed to protect our information technology systems and sensitive data. In particular, some of the data processed and stored in our platform, networks, and computer systems by government customers contain highly sensitive data protected under government regulations, and we are obligated to comply with stringent requirements related to the security of such data, such as the FedRAMP and Criminal Justice Information Services (“CJIS”) security requirements.
Individuals or entities have in the past and may in the future attempt to penetrate our network, computer system or platform security, or that of our third-party hosting and storage providers and other third parties with whom we work, and could gain access to our sensitive data, including customer data. Some actors now engage and are expected to continue to engage in cyber-attacks, including without limitation, nation-state actors for geopolitical reasons and in conjunction with military conflicts and defense activities. During times of war and other major conflicts, we, the third parties with whom we work, and our customers may be vulnerable to a heightened risk of these attacks, including retaliatory cyber-attacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell and distribute our services. For example, we have operations and third parties with whom we work to support our business located in unstable regions and regions experiencing (or expected to experience) geopolitical or other conflicts, including in the Middle East, where businesses have experienced an increase in cyberattacks in relation to the Israel-Hamas and Iran conflicts.
25
Table of Contents
In addition, we and the third parties with whom we work are subject to a variety of evolving threats, including but not limited to, computer malware (including as a result of advanced persistent threat intrusions), malicious code (such as viruses and worms), computer hacking, fraudulent use attempts, phishing and other social engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake), denial-of-service attacks, credential stuffing attacks, credential harvesting, personnel misconduct or error, ransomware attacks, supply-chain attacks and disruptions, adware, attacks enhanced or facilitated by AI, and other similar threats, all of which have become more prevalent in our industry. In particular, severe ransomware attacks are becoming increasingly prevalent and can lead to significant interruptions in our operations, loss of sensitive data and income, reputational harm, and diversion of funds. Extortion payments may alleviate the negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to, for example, applicable laws or regulations prohibiting such payments. It may be difficult and/or costly to detect, investigate, mitigate, contain, and remediate a security incident. Our efforts to do so may not be successful. Actions taken by us or the third parties with whom we work to detect, investigate, mitigate, contain, and remediate a security incident could result in outages, data losses, and disruptions of our business. Threat actors may also gain access to other networks and systems after a compromise of our networks and systems. For example, threat actors may use an initial compromise of one part of our environment to gain access to other parts of our environment, or leverage a compromise of our networks or systems to gain access to the networks or systems of third parties with whom we work, such as through phishing or supply chain attacks. Our data and information systems or those of third parties with whom we work have in the past, and may in the future, also fail for reasons other than malicious activity, including but not limited to, software bugs, configuration errors, server malfunctions, software or hardware failures, service outages, loss of data or other information technology assets, telecommunications failures, earthquakes, fires, and floods.
Remote work has increased risks to our platform, network, computer systems, and data, as our employees utilize network connections, computers and devices outside our premises or network, including working at home, while in transit and in public locations. Additionally, future or past business transactions (such as acquisitions or integrations) could expose us to additional cybersecurity risks and vulnerabilities, as our platform, network, or computer systems could be negatively affected by vulnerabilities present in acquired or integrated entities’ systems and technologies. Furthermore, we may discover security issues that were not found during due diligence, and it may be difficult to integrate companies into our information technology environment and security program.
These and other threats, attacks, disruptions, outages, or accidents involving us or the third parties with whom we work have in the past, and may in the future, result in the unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure, access, unavailability or misappropriation of our sensitive data, including of our customers and their employees or third parties, and/or damage to our or the third parties with whom we work’s platform, network, or computer systems. For instance, in the second quarter of 2024, we were made aware of an article posted by a security researcher which identified a temporary vulnerability with respect to two Azure environments related to a limited number of government customers. The vulnerability was remediated as of June 30, 2024, and we notified our potentially affected customers. Our investigation into and response to the matter and this issue has concluded and has not resulted in the loss of any of our customers.
While we have implemented security measures designed to protect against security incidents, there can be no assurance that these measures will be effective. We take steps designed to detect, mitigate and remediate vulnerabilities in our information systems (such as our hardware and/or software, including that of third parties with whom we work). However, we have not in the past been, and may not in the future be, able to detect and remediate all vulnerabilities including on a timely basis. As a result, such vulnerabilities have in the past and could in the future be exploited but may not be detected until after a security incident has occurred. Further, we have in the past experienced (and may in the future experience) delays in developing and deploying remedial measures and patches designed to address identified vulnerabilities. Even if we have issued or otherwise made patches or information for vulnerabilities in our software applications, products or services, our customers may be unwilling or unable to deploy such patches and use such information effectively and in a timely manner. These vulnerabilities could be exploited and result in a security incident.
26
Table of Contents
We may expend significant resources or modify our business activities to try to protect against security incidents. Applicable data privacy and security obligations require us, or we may voluntarily choose, to notify relevant stakeholders, including affected individuals, customers, regulators, and investors, of security incidents or vulnerabilities, or to take other actions, such as providing credit monitoring and identity theft protection services. Such disclosures and related actions are costly, and the disclosure or the failure to comply with such applicable requirements could lead to adverse consequences. An actual or perceived security breach of our platform, network or computer systems, or those of our technology service providers or third party vendors, could result in material adverse consequences such as the loss of business, financial losses, reputational damage, negative publicity, government enforcement actions (for example, regulatory investigations, orders, fines, penalties, audits, and inspections), additional reporting requirements and/or oversight, litigation (including class claims), indemnity obligations, damages for contract breach, civil and criminal penalties (including for violation of applicable laws, regulations or contractual obligations), restrictions on processing sensitive data (including personal data), diversion of management attention, interruptions in our operations (including availability of data), significant costs, fees and other monetary payments for remediation, and other harms.
Some of our contracts do not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our data privacy and security obligations. We cannot be sure that our insurance coverage will be adequate or sufficient to protect us from or to mitigate liabilities arising out of our privacy and security practices, that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims.
If we (or a third party with whom we work) fail or are perceived to have failed to maintain the reliability, security and availability of our platform, network, or computer systems, or if customers believe that our platform does not provide adequate security for the storage of sensitive data or its transmission over the Internet, we may lose existing customers and we may not be able to attract new customers, negatively impacting our ability to grow and operate our business. If we (or a third party with whom we work) experience security breaches or cyber-attacks or fail to comply with security requirements related to our secure government cloud environment, we may lose our ability to obtain or maintain a FedRAMP certification, which could result in the loss of business from customers in the government market. Any of the foregoing could have a material adverse effect on our business, results of operations and financial position and negatively impact our ability to grow and operate our business.
The reliability and continuous availability of our platform and services is critical to our success. However, software such as ours can contain errors, defects, security vulnerabilities or software bugs that are difficult to detect and correct, particularly when such vulnerabilities are first introduced or when new versions or enhancements of our product are released. Additionally, even if we are able to develop a patch or other fix to address such vulnerabilities, such fix may be difficult to push out to our customers or otherwise be delayed. Furthermore, our business depends upon the appropriate and successful implementation of our platform and services by our customers. If our customers fail to use our platform or services according to our specifications, our customers may suffer a security incident on their own systems or other adverse consequences. Moreover, we employ a shared responsibility model where our customers are responsible for using, configuring and otherwise implementing security measures related to our platform in a manner that meets applicable cybersecurity standards, complies with laws and addresses their information security risk. As part of this shared responsibility security model, we make certain security features such as single sign-on available to our customers that can be implemented at our customers’ discretion, or identify security areas or measures for which our customers are responsible. In certain cases where our customers choose not to implement, or incorrectly implement, those features or measures, misuse our services, or otherwise experience their own vulnerabilities, policy violations, credential exposure or security incidents, even if we are not the cause of a resulting customer security issue or incident, our customer relationships, reputation, and revenue may be adversely impacted. Even if such an incident is unrelated to our security practices, it could result in our incurring significant economic and operational costs in investigating, remediating, and implementing additional measures to further protect our customers from their own vulnerabilities, and could result in reputational harm.
In addition to experiencing a security incident, third parties may gather, collect, or infer sensitive data about us from public sources, data brokers, or other means that reveal competitively sensitive details about our organization and could be used to undermine our competitive advantage or market position. Additionally, our sensitive data or sensitive information of our customers could be leaked, disclosed, or revealed as a result of or in connection with our employees’, personnel’s, or vendors’ use of generative AI technologies.
27
Table of Contents
Interruptions or performance problems associated with our technology and infrastructure, or that of the third parties with whom we work, including AWS and Azure, may adversely affect our business and operating results.
Our business success depends in part on the ability of customers to access our Software Products & Services and Managed Services at any time and within an acceptable amount of time. We have experienced, and may in the future experience, disruptions, outages and other performance problems due to a variety of factors, including infrastructure changes, introductions of new applications and functionality, software errors and defects, capacity constraints due to an increasing number of users accessing our platform or initiating large volumes of processing simultaneously, or security related incidents. In addition, we rely on third parties, including AWS and Azure, to operate critical business systems and process sensitive data in a variety of contexts, including for hosting, storage and other critical services, required to operate our Software Products & Services and Managed Services. Our ability to monitor these third parties’ information security practices is limited, and these third parties may not have adequate information security measures in place. As such, we are vulnerable to service interruptions, delays and outages experienced or caused by these third parties, and we have experienced (and may in the future experience) adverse consequences when certain third parties with whom we work have experienced a security incident or other service interruption, delay or outage. While we believe we are entitled to damages if certain of the third parties with whom we work fail to satisfy their privacy or security-related obligations to us, any award may be insufficient to cover our damages, or we may be unable to recover such award. Because we also incorporate diverse software and hosted services from many third parties with whom we work, we may encounter difficulties and delays in integrating and synthesizing these applications and programs, which may cause downtimes or other performance problems. It may become increasingly difficult to maintain and improve the performance of our platform, especially during peak usage times and as our platform becomes more complex or usage increases. Additionally, our reliance on third parties could introduce new cybersecurity risks and vulnerabilities, including supply-chain attacks. Such supply-chain attacks have increased in frequency and severity, and we cannot guarantee that third parties’ infrastructure in our supply chain or supply chains of the third parties with whom we work have not been compromised.
Certain of our customer contracts include service level obligations, including system uptime commitments and/or required response times in the case of technical issues. If our Software Products & Services and Managed Services are unavailable or if our users are unable to access them within a reasonable amount of time or at all, we may be in breach of our contractual obligations, we may be required to issue credits or refunds to customers, and/or our customers may be entitled to terminate their contracts with us.
AWS and Azure provide us with hosting, computing and storage services pursuant to agreements that may be canceled under certain circumstances. If any of our agreements with AWS or Azure is terminated, we could experience interruptions on our platform and in our ability to make our platform available to customers, as well as delays and additional expenses in arranging alternative cloud infrastructure services.
Any of the above circumstances or events may harm our reputation, cause customers to stop using our platform, impair our ability to increase revenue from existing customers, impair our ability to grow our customer base, subject us to financial penalties and liabilities under our service level agreements and otherwise harm our business, results of operations and financial condition.
28
Table of Contents
Risks Related to our Indebtedness and Liquidity
We have $45.6 million principal amount of Convertible Notes outstanding with a scheduled maturity date of November 15, 2026. If we decide not to refinance the Convertible Notes prior to their maturity date or are unable to do so, repurchasing or repaying the Convertible Notes prior to or at maturity may require a significant amount of cash in 2026, and we may not have sufficient cash flow from our operations to pay our debt obligations.
As of December 31, 2025, we had $45.6 million aggregate principal amount of Convertible Notes outstanding with a scheduled maturity date of November 15, 2026. If we are unable to refinance the Convertible Notes or elect to repurchase or repay them prior to or at maturity, we will need a significant amount of cash in 2026. In addition, our ability to make scheduled payments of the remaining principal amount of our Convertible Notes at maturity, or to repurchase and/or refinance the Convertible Notes, depends on our future performance, which is subject to economic, financial, competitive and other factors beyond our control. Our business may not generate cash flow from operations sufficient to repay or refinance our debt and also make necessary capital expenditures. If we are unable to generate such cash flow, we have in the past been, and may again in the future be, required to adopt one or more alternatives, such as selling assets, restructuring our debt or obtaining additional equity capital which may be on terms that are onerous or highly dilutive to our stockholders. Our ability to engage in corporate transactions, raise additional capital or refinance our indebtedness will depend on the capital markets and our financial condition at such time. We may not be able to engage in any of these activities at all or on desirable terms, which could result in a default on our debt obligations.
We may require additional capital to grow our business or repay or refinance our Convertible Notes maturing in November 2026, and this capital might not be available to us on acceptable terms, if at all.
If we are not able to achieve cost savings from our planned cost reduction measures, we will need additional liquidity to continue our operations for the foreseeable future, including over the next twelve months. We may also require additional capital to repay or refinance our Convertible Notes as they come due.
We have in the past and may again in the future engage in equity and/or debt financings to secure any needed additional funds. For example, during the fiscal year ended December 31, 2025, we raised aggregate net proceeds of approximately $154.7 million through the issuance and sale of our common stock and pre-funded warrants, which proceeds we used to repurchase outstanding debt. We established a $35.0 million “at-the-market” equity offering program in November 2024, which we utilized to offer and sell shares of our common stock from time to time for an aggregate of $35.0 million in gross proceeds. We fully utilized and terminated the ATM program in 2025.
Further, if we decide to enter into any new debt arrangements to refinance our Convertible Notes or otherwise, any borrowings could make us more vulnerable to a downturn in our operating results, a downturn in economic conditions, or increases in interest rates on borrowings that are subject to interest rate fluctuations.
Our ability to raise additional capital depends on a variety of factors, including our financial condition, market conditions, and investor demand, and any future capital-raising efforts may involve significant risks. If we raise additional funds through future issuances of equity or convertible debt securities, our stockholders could suffer significant dilution, and any new equity securities we issue could have rights, preferences and privileges superior to those of holders of our common stock. If we do so, existing stockholders will experience dilution in the voting power of their common stock and earnings per share could be negatively impacted. The extent to which we will be able and willing to use issuances of equity or convertible debt securities for acquisitions and other strategic initiatives will depend on the market value of our common stock and the willingness of potential third parties to accept any such securities as full or partial consideration. Any future debt or equity financing activities could also result in higher costs of capital with elevated or increased interest rates and could include restrictive covenants on our operations, including covenants restricting our ability to incur debt, pay distributions or repurchase our equity, sell assets, and acquire businesses, among other restrictions.
Failure to secure sufficient capital when needed could have a material adverse effect on our business, financial condition and results of operations, including materially limiting our ability to grow.
29
Table of Contents
Risks Related to Target Markets, Competition, and Customers
The success of our business depends on our ability to expand into new vertical markets and attract new customers in a cost-effective manner.
To grow our business, we plan to drive greater awareness and adoption of our aiWARE platform, applications and services from enterprises across new vertical markets, including the Public Sector markets. We intend to continue to invest in sales and marketing, as well as in technological development, to meet evolving customer needs in these and other markets. We may not be successful in gaining new customers in any or all of these markets. Some markets may present unique and unexpected challenges and difficulties. For example, for us to offer our Software Products & Services to certain government customers, we are required to operate our aiWARE platform in a secure government cloud environment, and in some cases, in a private cloud environment or an on-premises environment, in order to meet these customers’ requirements and to enable them to maintain compliance with applicable regulations that govern the use, storage and transfer of certain government data. However, due to the secure nature of these environments, at this time, not all of the functionalities, features and cognitive processing capabilities of our aiWARE platform are available in these environments, which may limit or reduce the performance of our services. Furthermore, we may incur additional costs to modify our current platform to conform to customers’ or cloud providers’ requirements, and we may not be able to generate sufficient revenue to offset these costs. We are also required to comply with certain regulations required by government customers, such as FedRAMP and CJIS, which require us to incur significant costs, devote management time and modify our current platform and operations. If we are unable to comply with those regulations effectively and in a cost-effective manner, our financial results could be adversely affected.
As part of our strategy to penetrate new vertical markets, we will incur marketing expenses before we are able to recognize any revenue in such markets, and these expenses may not result in increased revenue or brand awareness. We have made in the past, and may make in the future, significant expenditures and investments in new marketing campaigns, and these investments may not lead to the cost-effective acquisition of additional customers. If we are unable to maintain effective marketing programs, then our ability to attract new customers or enter new vertical markets could be adversely affected.
We generate significant revenue from a limited number of key customers which may cause our revenues for future periods to be less predictable.
We generate a significant portion of our revenue from a limited number of key customers. For Managed Services, our two largest customers, Westwood One, Inc. and iHeart Media and Entertainment, Inc., accounted for approximately 12% and 11%, respectively, of our total Managed Services revenues in fiscal year 2025. Some of these customers do not have long-term contracts with us. In the event that these customers decide to terminate their contracts with us, reduce their budget for our services, or develop a competing solution, and we are unable to obtain additional customers or increase our revenue from existing customers to offset the reduction of these revenues, we could experience a material adverse effect on our business, financial condition and reported revenue and results of operation.
We have previously experienced declines in our net revenues due to the loss of key customers. For example, Amazon, historically our largest customer, reduced its hiring consumption starting in the third and fourth quarters of fiscal year 2022. Amazon has decreased from generating 25% of net revenues in fiscal year 2022 to less than 1% and 4% of our net revenues in fiscal years 2024 and 2025, respectively.
Because of the concentrated nature of our customer base, any delay, reduction, cancellation or discontinuation of services by our larger customers has materially affected and may in the future materially affect our revenue and results of operations. In addition, the recent declines in revenue from one of these customers across our lines of business may cause us to face more volatility in our revenue in future periods and more difficulty in predicting our revenue for future periods. We may be unable to grow revenues with new or remaining customers or offset the discontinuation of purchases by customers we have experienced declines in revenue with purchases by new or existing customers. Furthermore, if we are unable to replace lost revenue from key customers, we may continue to experience decreased sales, which could have a material adverse impact on our results of operations and financial condition. If any of our remaining key customers decide to terminate or decline to renew their contracts with us, or renew on less favorable terms, and if we are unable to gain additional customers or increase our revenue from other existing customers to offset the reduction of revenues, our business, results of operations and financial condition will be harmed.
30
Table of Contents
Technological advances may significantly disrupt the labor market and weaken demand for human capital at a rapid rate.
The success of our Talent Acquisition solutions is dependent on our customers’ demands for talent. As technology continues to evolve, more tasks currently performed by people may be replaced by automation, robotics, machine learning, artificial intelligence and other technological advances outside of our control. This trend poses a risk to the talent acquisition industry as a whole, particularly in lower-skill job categories that may be more susceptible to such replacement.
Significant segments of the market for talent acquisition software and services may have hiring needs and service preferences that are subject to greater volatility than the overall economy.
The target customer segment for our Talent Acquisition solutions spans a wide range of company characteristics, including company size, geography, and industry, among other factors. Hiring activity may vary significantly among businesses with different characteristics and we have historically experienced volatility in our financial results related to our Talent Acquisition solutions. Smaller businesses, for example, typically have less persistent hiring needs and may experience greater volatility in their need for talent acquisition software and services and preferences among providers of such services. Along with a relatively short sales cycle, smaller businesses may be more likely to change platforms based on short-term differences in perceived price, value, service level, or other factors. Difficulty in acquiring and/or retaining these businesses as customers may adversely affect our operating results.
Our sales efforts related to our Software Products & Services involve considerable time and expense and our sales cycle is often long and unpredictable.
Our results of operations may fluctuate, in part, because of the length and unpredictability of our sales cycle, particularly in our Public Sector markets. As part of our sales efforts, we invest considerable time and expense evaluating the specific organizational needs of our potential customers and educating these potential customers about the technical capabilities and value of our Software Products & Services. Potential customers often require evaluation licenses at no charge or for nominal fees to evaluate our solutions before making a purchase decision. Sales to government customers may also be subject to lengthy and complex procurement processes, including technology and security assessments, budget approvals and competitive bidding requirements. Due to these factors, our sales cycle often lasts several months or more for some customers. Our sales efforts typically require a significant investment of human resources expense and time, including efforts by sales engineers, solution architects, product development and senior management, and we may not be successful in making a sale to a potential customer. If our sales efforts to a potential customer do not result in sufficient revenue to justify our investments, our business, financial condition, and results of operations could be adversely affected.
Risks Related to Intellectual Property
We face risks arising from our digital content and data licensing services, including potential liability resulting from claims by third parties for infringement or violation of copyrights, publicity or other rights, as well as indemnification claims by rights holders and customers.
We manage and license digital content on behalf of leading rights holders in the film, television, sports and advertising industries. We enter into agreements with rights holders under which they grant us the right to distribute and license their content to third parties, including to LLM developers for the purpose of development, training, operation, and use of machine learning and artificial intelligence activities and technologies, including, building, training, testing, and tuning models, subject to certain restrictions and requirements, such as limitations on the type and/or duration of use and requirements to obtain clearances and consents from third parties related to the content. Under these agreements, the rights holders generally represent and warrant that they have the right to license the content to us and that the authorized use of the content will not infringe any third-party copyrights and agree to indemnify us for claims arising from breach of such representations and warranties. However, we, and/or our customers to which we sublicense the content, are generally responsible for obtaining all required clearances, permissions and consents with respect to any specific person, place, property or subject matter depicted in the content, each of which may be subject to trademarks, rights of publicity, property rights or other rights belonging to third parties, and we generally agree to indemnify the right holders with respect to claims arising from any failure to do so. In many cases, our agreements with rights holders also require that we include specific terms, conditions, covenants and obligations in our agreements with our customers.
31
Table of Contents
In our license agreements with customers, we represent and warrant that we have the right to sublicense the content to them and that their authorized use of the content will not infringe any third-party copyrights, and we agree to indemnify our customers for claims arising from breach of such representations and warranties. However, our customers are generally responsible for obtaining all necessary clearances, permissions and consents from third parties, unless we have expressly agreed to provide clearance services with respect to the content, and our customers generally agree to indemnify us for claims arising from their failure to do so. If we or our customers fail to obtain all clearances, permissions and consents from third parties required for the customers’ use of licensed content, or if our customers otherwise use content in a manner not authorized by the terms of our agreements with the rights holders, then third parties may bring claims against us and the rights holders, and the rights holders may seek indemnification from us related to such claims. In some cases, we may not be entitled to a supporting indemnification by our customers, or we may not be successful in enforcing our rights to indemnification by our customers. In addition, third parties may bring claims against us and our customers for copyright infringement, and we may be required to indemnify our customers for such claims. Similarly, we may not be entitled to indemnification by the rights holders, or we may not be able to enforce our rights to indemnification by the rights holders.
We may incur significant liabilities and costs in the event of claims for infringement or violation of copyrights, publicity or other rights, and/or indemnification claims by third-party rights holders and customers. Regardless of their merit and outcome, intellectual property and indemnification claims are time consuming, expensive to litigate or settle and cause significant diversion of management attention and could severely harm our financial condition and reputation and adversely affect our business.
We maintain insurance policies to cover potential intellectual property disputes. However, if an intellectual property claim or related indemnification claim, or a series of claims, is brought against us in excess of our insurance coverage or for uninsured liabilities, our business could suffer. In addition, we may not be able to maintain insurance coverage at a reasonable cost or in sufficient amounts or scope to protect us against all losses.
We may be sued by third parties for alleged infringement of their proprietary rights, which could adversely affect our business, results of operations and financial condition.
There has been considerable patent and other intellectual property development activity in the AI industry, which has resulted in litigation based on allegations of infringement or other violations of intellectual property rights. Our future success depends, in part, on not infringing the intellectual property rights of others. In the future, we may receive claims from third parties, including our competitors, alleging that our platform and underlying technology infringe or violate such third party’s intellectual property rights, and we may be found to be infringing upon such rights. We may be unaware of the intellectual property rights of others that may cover some or all of our technology. In addition, in operating our platform, we rely significantly on software provided by third parties, including without limitation, generative AI models and applications, and we may become subject to similar infringement claims related to such third-party software. We may not have adequate indemnities from, or we may not be successful in enforcing our rights to indemnification by, such third party software providers.
Any such claims or litigation could cause us to incur significant expenses and, if successfully asserted against us, could require that we pay substantial damages or ongoing royalty payments, prevent us from offering some portion of our platform, or require that we comply with other unfavorable terms. We may also be obligated to indemnify our customers or business partners in connection with any such litigation and to obtain licenses or modify our platform, which could further exhaust our resources. Patent infringement, trademark infringement, trade secret misappropriation and other intellectual property claims and proceedings brought against us, whether successful or not, could harm our brand, business, results of operations and financial condition. Litigation is inherently uncertain, and any judgment or injunctive relief entered against us or any adverse settlement could negatively affect our business, results of operations and financial condition. In addition, litigation can involve significant management time and attention and be expensive, regardless of the outcome.
32
Table of Contents
We could incur substantial costs in protecting or defending our intellectual property rights, and any failure to protect our intellectual property could adversely affect our business, results of operations and financial condition.
Our success depends, in part, on our ability to protect our brand and the proprietary methods and technologies that we develop under patent and other intellectual property laws of the United States and foreign jurisdictions so that we can prevent others from using our inventions and proprietary information. As of December 31, 2025, in the United States, we have 39 issued patents, which expire between 2029 and 2042, and have 10 patent applications pending for examination. As of such date, we also had 12 issued patents and 4 patent applications pending for examination in foreign jurisdictions (including international PCT applications), all of which are based on counterpart U.S. patent applications pursued by us. We may not be issued any additional patents and any patents that have been issued or that may be issued in the future may not provide significant protection for our intellectual property. In addition, we have registered, or have applied for registration of, numerous trademarks, including Veritone and aiWARE, in the United States and in several foreign jurisdictions. If we fail to protect our intellectual property rights adequately, our competitors might gain access to our technology and our business, results of operations and financial condition may be adversely affected.
The particular forms of intellectual property protection that we seek, or our business decisions about when to file patent applications and trademark applications, may not be adequate to protect our business. We could be required to spend significant resources to monitor and protect our intellectual property rights. Litigation may be necessary in the future to enforce our intellectual property rights, determine the validity and scope of our proprietary rights or those of others, or defend against claims of infringement or invalidity. Such litigation could be costly, time-consuming and distracting to management, result in a diversion of significant resources, lead to the narrowing or invalidation of portions of our intellectual property and have an adverse effect on our business, results of operations and financial condition.
We also rely, in part, on confidentiality agreements with our business partners, employees, consultants, advisors, customers and others in our efforts to protect our proprietary technology, processes and methods. These agreements may not effectively prevent disclosure of our confidential information, and it may be possible for unauthorized parties to copy our software or other proprietary technology or information, or to develop similar software independently without our having an adequate remedy for unauthorized use or disclosure of our confidential information. In addition, others may independently discover our trade secrets and proprietary information, and in these cases, we would not be able to assert any trade secret rights against those parties. Costly and time-consuming litigation could be necessary to enforce and determine the scope of our proprietary rights, and the failure to obtain or maintain trade secret protection could adversely affect our competitive business position.
In addition, the laws of some countries do not protect intellectual property and other proprietary rights to the same extent as the laws of the United States. To the extent we expand our international activities, our exposure to unauthorized copying, transfer and use of our proprietary technology or information may increase.
Our means of protecting our intellectual property and proprietary rights may not be adequate or our competitors could independently develop similar technology. If we fail to meaningfully protect our intellectual property and proprietary rights, our business, results of operations and financial condition could be adversely affected.
33
Table of Contents
Our use of open source software could negatively affect our ability to sell our products and subject us to possible litigation.
Our Software Products & Services, including our aiWARE platform, incorporate select open source software, and we expect to continue to incorporate open source software in our Software Products & Services in the future. Few of the licenses applicable to open source software have been interpreted by courts, and there is a risk that these licenses could be construed in a manner that could impose unanticipated conditions or restrictions on our ability to commercialize our products and platform. Moreover, although we have implemented policies designed to regulate the use and incorporation of open source software into our Software Products & Services, we cannot be certain that we have not incorporated open source software in our Software Products & Services in a manner that is inconsistent with such policies. There is a risk that our use of third-party open source software could impose certain requirements on our ability to commercialize our products, including requirements that we offer our products that incorporate the open source software for no cost, that we make available source code for modifications or derivative works we create based upon, incorporating or using the open source software and that we license such modifications or derivative works under the terms of applicable open source licenses. If an author or other third party that distributes such open source software were to allege that we had not complied with the conditions of one or more of these licenses, we could be required to incur significant legal expenses defending against such allegations and could be subject to significant damages, enjoined from generating revenue from customers using products that contained the open source software and required to comply with onerous open source license conditions or restrictions. In any of these events, we and our customers could be required to seek licenses from third parties to continue offering our Software Products & Services and we could be required to make proprietary portions of our source code freely available or to re-engineer the implicated products or discontinue offering the implicated products to customers in the event re-engineering cannot be accomplished on a timely basis. In addition, the use of third-party open source software typically exposes us to greater risks than the use of third-party commercial software because open source licensors generally do not provide warranties or controls on the functionality or origin of the software. Use of open source software may also present additional security risks because the public availability of such software may make it easier for hackers and other third parties to determine how to compromise our platform. Any of the foregoing could harm our business and could help our competitors develop products and services that are similar to or better than ours. Any of the foregoing could require us to devote additional research and development resources to re-engineer our products, could result in customer dissatisfaction and may adversely affect our business, results of operations and financial condition.
Risks Related to Regulatory Compliance
Recent and proposed regulation of AI technologies, including facial recognition technology, the processing of biometric data, and automated decision-making and machine learning technologies, increase our compliance costs and otherwise make it harder for us to conduct our business, require us to change our business practices and may lead to regulatory investigations or actions, litigation, reputational harm or otherwise have a material adverse effect on our business.
Certain of our Software Products & Services, particularly our IDEMs suite of product solutions for law enforcement agencies, utilize facial recognition technology. Facial recognition technology has been the subject of increasing concern and criticism, including over the potential for the technology to misidentify individuals as criminal suspects, and to be used in ways that infringe on individual rights. Numerous legislative proposals have been introduced to ban or restrict the use of the technology by certain governmental agencies, and several U.S. cities, including San Francisco, California, Oakland, California and Somerville, Massachusetts, have enacted such bans. Although some jurisdictions are re-evaluating the breadth of such bans, where any ban or restriction on the use of facial recognition technologies by governmental agencies have been or may be enacted, potential government customers for our IDEMs solution may be prohibited from or restricted in using the technology. If such bans or restrictions are enacted in a significant number of jurisdictions, it would have a material adverse effect on the market for software solutions that utilize facial recognition technology, including our IDEMs solution.
34
Table of Contents
Certain of our products may support facial recognition functionality. Laws have been enacted or introduced in a number of jurisdictions that regulate the processing of biometric data, including facial templates and images in facial recognition systems, by non-governmental actors. For example, the Illinois Biometric Information Privacy Act (“BIPA”) regulates the collection, use, safeguarding, and storage of biometric information. BIPA contains a private right of action that provides for substantial penalties and statutory damages and have generated significant class action activity; the cost of litigating and settling any claims that we have violated the BIPA or similar laws could be significant. As another example, certain comprehensive U.S. state consumer privacy laws require covered businesses to obtain affirmative consumer consent before processing biometric data and other sensitive data and impose additional compliance obligations on the processing of such data. Additionally, under the GDPR, use of biometric data for the purpose of uniquely identifying a natural person constitutes the processing of a special category of personal data, to which heightened standards, requirements and regulatory and individual scrutiny apply. Under the GDPR, the processing of biometric data for such purposes is prohibited unless one of a very limited and specific set of conditions is satisfied (such as explicit consent of the data subject). Effective compliance in this area (including using certain of our products) can be highly challenging, and we are reliant on our customers to ensure that applicable obligations are satisfied when they use our products to identify someone. We may be unable to provide certain of our products in certain jurisdictions, in particular in Europe, where provision of such technologies in compliance with the GDPR is highly challenging. Such laws may limit the demand for our aiWARE platform for non-governmental use cases that utilize facial recognition technology, which could adversely impact our ability to grow our business in those areas.
In addition, we use machine learning and AI, including generative AI and automated decision making technologies, in certain of our products and services. The development and use of AI technologies present various privacy and security risks that may impact our business. AI technologies are subject to privacy and data security laws, as well as increasing regulation, scrutiny and oversight. Further, countries and states are applying their data and consumer protection laws to AI technologies, and particularly generative AI and interactive chatbots. For example, under the comprehensive legal framework governing the use of artificial intelligence in the European Union (the “EU AI Act”). The EU AI Act imposes onerous obligations related to the development, deployment and use of AI technology-related systems. In particular, the EU AI Act designates certain AI technologies, including AI systems used in an employment-related context (such as in relation to recruitment, placement of targeted job advertisements, and decision-making concerning promotion, termination and task allocation), as ‘high risk’ and subject to numerous onerous compliance obligations, including various transparency, conformity and risk assessment, monitoring and human oversight requirements; the EU AI Act also imposes a prohibition on the use of ‘real-time’ biometric identification systems in publicly accessible spaces by law enforcement authorities or on their behalf unless very limited exceptions apply. Certain of our products and services may fall within one or more of these categories. Under the EU AI Act, non-compliant companies may be subject to administrative fines of up to 35 million Euros or 7% of a company’s total worldwide annual turnover for the preceding financial year, whichever is the higher. The EU AI Act has a phased implementation process. As such, obligations for prohibited AI systems became enforceable in February 2025, while the regulatory framework for high-risk AI systems is scheduled to take effect in August 2026. Moreover, in the United Kingdom, the government has confirmed its position that existing regulators are to implement certain specific principles (safety, security and robustness; transparency and explainability; fairness; accountability and governance; contestability and redress), within those regulators’ existing remits, to guide and inform the responsible development and use of AI technologies within their relevant sectors / competencies. Additionally, several U.S. jurisdictions have enacted measures related to the use of AI in products and services for their potentially discriminatory effects. For example, Colorado passed its comprehensive AI Act, and New York City passed a law to regulate the use of automated employment decision tools by employers and employment agencies. Certain of these laws may be materially unfavorable to our interests and/or inconsistent with our existing operations, policies, practices or plans (or may be interpreted as such). We expect other jurisdictions will adopt similar laws. Furthermore, the U.S. federal government has signaled an intent to develop a unified AI regulatory framework that would preempt U.S. state AI laws and regulations. Attempts by the U.S. federal government to preempt state AI regulation may be subject to constitutional challenges, and uncertainty regarding AI regulatory authority could further complicate our compliance efforts and increase related costs.
Additionally, certain privacy laws extend rights to consumers (such as the right to delete certain personal data) and regulate automated decision making, which may be incompatible with our use of AI technologies. These obligations may make it harder for us to conduct our business using AI technologies, lead to regulatory fines or penalties, require us to change our business practices, retrain our AI technologies, or prevent or limit our use of AI technologies. For example, the FTC has required other companies to turn over (or disgorge) valuable insights or trainings generated through the use of AI technologies where they allege the company has violated privacy and consumer protection laws. If we cannot use AI technologies or that use is restricted, our business may be less efficient, or we may be at a competitive disadvantage.
35
Table of Contents
Moreover, AI technologies may create flawed, incomplete, or inaccurate outputs, some of which may appear correct. This may happen if the inputs that the model relied on were inaccurate, incomplete or flawed (including if a bad actor “poisons” the AI technology with bad inputs or logic), or if the logic of the AI technology is flawed (a so-called “hallucination”). We may use AI technologies’ outputs to make certain decisions. Due to these potential inaccuracies or flaws, the model could be biased and could lead us to make decisions that could bias certain individuals (or classes of individuals), and adversely impact their rights, employment, and ability to obtain certain pricing, products, services, or benefits. For example, our platform uses (and allows our customers to use) AI technologies for recruitment, screening, and other employment-related tasks, and if such AI-based outputs or decisions are deemed to be biased, we could face adverse consequences, including exposure to reputational and competitive harm, customer loss, and legal liability, including under consumer protection statutes.
Furthermore, any sensitive data (including confidential, competitive, proprietary, or personal data) that we input into a third-party generative AI technology could be leaked or disclosed to others, including if sensitive data is used to train the third party’s AI technologies. Additionally, where an AI technology ingests personal data and makes connections using such data, those technologies may reveal other personal or sensitive data generated by the model.
Given that AI, automated decision making and machine learning technologies are core to our business, any increased regulation over these technologies, including the EU AI Act, could make it harder for us to conduct our business, significantly complicate our compliance efforts, increase legal risk and compliance costs for us, the third parties with whom we work, and our customers, increase our cost of doing business, impede or prevent our growth plans (including into Europe), require us to change our business operations at significant cost (such as retaining or rebuilding our AI models), and reduce demand for our products.
We and the third parties with whom we work are subject to stringent and evolving U.S. and foreign laws, regulations, and rules, contractual obligations, industry standards, policies and other obligations related to data privacy and security. These legal and other obligations have in the past, and could in the future, require us to make changes to our business, impose additional costs on us and reduce the demand for our software products and solutions. Our (or the third parties with whom we work) actual or perceived failure to comply with such obligations could also lead to regulatory investigations or actions; litigation (including class claims) and mass arbitration demands; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; and other adverse business consequences.
In the ordinary course of business, we process sensitive data. Our customers also utilize our Software Products & Services and Managed Services to process sensitive data, which may contain personal data that is subject to data protection and privacy laws in various jurisdictions.
Our data processing activities subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements and other obligations relating to data privacy and security.
In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), and other similar laws (e.g., wiretapping laws). Numerous U.S. states have enacted comprehensive privacy laws that impose certain obligations on covered businesses, including providing specific disclosures in privacy notices and affording residents with certain rights concerning their personal data. As applicable, such rights may include the right to access, correct, or delete certain personal data, and to opt-out of certain data processing activities, such as targeted advertising, profiling, and automated decision-making. The exercise of these rights may impact our business and ability to provide our products and services. Certain states also impose stricter requirements for processing certain personal data, including sensitive data, such as conducting data privacy impact assessments. These state laws allow for statutory fines for noncompliance. For example, the California Consumer Privacy Act of 2018 (“CCPA”) applies to personal data of consumers, business representatives, and employees who are California residents, and requires businesses to provide specific disclosures in privacy notices and honor requests of such individuals to exercise certain privacy rights. The CCPA provides for fines and allows private litigants affected by certain data breaches to recover significant statutory damages. These developments may further complicate compliance efforts, and increase legal risk and compliance costs for us, the third parties with whom we work, and our customers. Similar laws are being considered in several other states, as well as at the federal and local levels, and we expect more states to pass similar laws in the future.
36
Table of Contents
As we expand into new jurisdictions or markets outside the United States, we may become subject to an increasing number of laws, regulations, and industry standards governing data privacy and security. For example, we have entered into agreements and are actively pursuing opportunities to provide our Software Products & Services and Managed Services to customers in Europe, which involve processing of personal data, and the GDPR impose strict requirements for processing personal data. Under the GDPR, companies may face temporary or definitive bans on data processing and other corrective actions; fines of up to 20 million Euros under the EU GDPR, 17.5 million pounds sterling under the UK GDPR, or, in each case, 4% of annual global revenue, whichever is greater; or private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests.
In the ordinary course of business, we transfer personal data from Europe and other jurisdictions to the United States or other countries. Europe and other jurisdictions have enacted laws limiting the transfer of personal data to other countries or requiring data to be localized. In particular, the European Economic Area (“EEA”) and the United Kingdom (“UK”) have significantly restricted the transfer of personal data to the United States and other countries whose privacy laws they generally believe are inadequate. Other jurisdictions may adopt or have already adopted similarly stringent data localization and cross-border data transfer laws. Certain jurisdictions, including the EEA and the UK, have adopted adequacy decisions or similar frameworks in respect of specific countries or transfer regimes, which permit cross-border transfers of personal data without the need for additional transfer safeguards where applicable. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EEA standard contractual clauses, the UK’s International Data Transfer Agreement / Addendum, and the EU-U.S. Data Privacy Framework and the UK extension thereto (which allows for transfers to relevant U.S.-based organizations who self-certify compliance and participate in the Framework), these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States. If there is no lawful manner for us to transfer personal data from the EEA and the UK or other jurisdictions to the United States, or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of our operations, the need to relocate part of or all of our business or data processing activities to other jurisdictions at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against our processing or transferring of personal data necessary to operate our business. Furthermore, companies that transfer personal data out of the EEA and UK to other jurisdictions, particularly to the United States, are subject to increased scrutiny from regulators, individual litigants, and activist groups. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers of personal data out of Europe for allegedly violating the GDPR’s cross-border data transfer limitations. Additionally, the U.S. Department of Justice issued a rule entitled the Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons, which places additional restriction on certain data transactions involving countries of concern (e.g., China, Russia, Iran) and covered persons (i.e., individuals and entities who are designated as such by the U.S. Attorney General or considered “foreign persons” and are majority owned by, organized under the laws of, a primary resident in, or a contractor of, a covered person or country of concern, as applicable) that may impact certain business activities such as vendor engagements, sale or sharing of data, employment of certain individuals, and investor agreements. Violations of the rule could lead to significant civil and criminal fines and penalties. The rule applies regardless of whether data is anonymized, key-coded, pseudonymized, de-identified or encrypted, and may impact our ability to engage in certain transactions or agreements.
Additionally, under various privacy laws and other obligations, we may be required to obtain certain consents to process personal data. For example, some of our data processing practices have been and may in the future be subject to challenges or lawsuits under data privacy and communications laws, including for example wiretapping laws, if we share consumer information with third parties through various methods, including chatbot and session replay providers, cookies, or via third-party marketing pixels, as has occurred. These practices may be subject to increased challenges by class action plaintiffs. Our inability or failure to obtain consent for these practices could result in adverse consequences, including class action litigation and mass arbitration demands.
37
Table of Contents
In addition to data privacy and security laws, we are also subject to contractual obligations related to data privacy and security, and our efforts to comply with such obligations may not be successful. For example, certain privacy laws, such as the GDPR and the CCPA, require our customers to impose specific contractual restrictions on their service providers. Additionally, some of our customer contracts require us to host personal data locally. We also publish privacy policies, marketing materials, whitepapers and other statements, such as statements related to compliance with certain certifications or self-regulatory principles, regarding data privacy, security and artificial intelligence. Regulators in the United States are increasingly scrutinizing these statements, and if these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, misleading or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators or other adverse consequences.
The regulatory framework relating to data privacy and security (and consumers’ data privacy expectations) is quickly changing, becoming increasingly stringent, and creating uncertainty. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or conflict among jurisdictions, or which may be interpreted and applied in a manner inconsistent with our existing privacy and data management practices. Preparing for and complying with these obligations requires us to devote significant resources, which may necessitate changes to our services, information technologies, systems, and practices and to those of any third parties with whom we work. In addition, these obligations may require us to change our business model. Our business model materially depends on our ability to process personal data on behalf of our customers, including sensitive and highly regulated types of data such as biometric information, so we are particularly exposed to the risks associated with the rapidly changing legal landscape. For example, we may be at heightened risk of regulatory scrutiny, and any changes in the regulatory framework could require us to fundamentally change our business model.
We may at times fail (or be perceived to have failed) in our efforts to comply with our data privacy and security obligations. Moreover, despite our efforts, our personnel or third parties with whom we work may fail to comply with such obligations, which could negatively impact our business operations. If we or the third parties with whom we work fail, or are perceived to have failed, to address or comply with applicable data privacy and security obligations, we could face significant consequences, including but not limited to: government enforcement actions (e.g., investigations, fines, penalties, audits and/or inspections); litigation (including class action claims) and mass arbitration demands; contractual liability; additional reporting requirements and/or oversight and demands that we modify or cease existing business practices (including bans on processing personal data or orders to destroy or not use personal data). In addition, the costs of compliance with, and other burdens imposed by, such laws, regulations and industry standards may adversely affect our customers’ ability or desire to collect, use, process and store personal data using our software solutions, which could reduce overall demand for them. Even the perception of privacy and data security concerns, whether or not valid, may inhibit market acceptance of our software solutions in certain markets. Furthermore, privacy and data security concerns may cause our customers’ customers, vendors, employees and other industry participants to resist providing the personal data necessary to allow our customers to use our products and services effectively. Additionally, plaintiffs have become increasingly more active in bringing privacy-related claims against companies, including class claims and mass arbitration demands. Some of these claims allow for the recovery of statutory damages on a per violation basis, and, if viable, carry the potential for monumental statutory damages, depending on the volume of data and the number of violations. Any of these events could have a material adverse effect on our reputation, business and operating results or financial condition, including but not limited to: loss of customers; interruptions or stoppages of data collection needed to train our algorithms; inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; adverse publicity or substantial changes to our business model or operations.
Our employees and personnel use generative AI and/or automated decision-making technologies to perform their work, and the disclosure and use of personal data in AI technologies is subject to various privacy laws and other privacy obligations. Governments have passed and are likely to pass additional laws and regulations regulating AI and/or automated decision-making technologies. Our use of this technology could result in additional compliance costs, regulatory investigations and actions, and lawsuits. If we are unable to use AI and/or automated decision-making technologies, it could make our business less efficient and result in competitive disadvantages. For additional information about the risks related to our use of AI technologies, including those that involve processing biometric data, see the Risk Factor titled “Recent and proposed regulation of AI technologies, including facial recognition technology, the processing of biometric data, and automated decision-making and machine learning technologies, increase our compliance costs and otherwise make it harder for us to conduct our business, require us to change our business practices, and may lead to regulatory investigations or actions, litigation, reputational harm, and otherwise have a material adverse effect on our business.”
38
Table of Contents
Finally, governments and regulators in certain jurisdictions, including Europe, are increasingly seeking to regulate the use, transfer and other processing of non-personal data, an area which has typically been the subject of very limited or no specific regulation. For example, we may become subject to certain parts of the European Union’s Data Act, which imposes certain data and cloud service interoperability and switching obligations to enable users to switch between service providers without undue delay or cost, as well as certain requirements concerning cross-border international transfers of, and governmental access to, non-personal data outside the EEA. Depending on how these laws are interpreted, we may have to adapt our business practices, contractual arrangements and products to comply with such obligations.
Tax authorities in the United States and in foreign jurisdictions may successfully assert that we, including our acquired companies, should have collected, or in the future should collect, sales, use, value added, or similar taxes, and we could be subject to substantial liabilities with respect to past or future transactions, which could adversely affect our results of operations.
We conduct operations in multiple tax jurisdictions throughout the United States. In many of these jurisdictions, non-income-based taxes, such as sales and use taxes, are assessed on our operations. We assess the taxability of our sales based on the product type, customer, and jurisdiction where the sales are made and accrue a liability on the balance sheet accordingly. In the event these jurisdictions challenge our positions, such jurisdictions may assert tax assessments, penalties and/or interest against us, which could adversely affect our business, results of operations and financial condition.
In addition, we conduct operations outside of the United States, including in Israel and parts of Europe. These foreign jurisdictions have complex tax laws and regulations, and we may be subject to future uncertainties as a result of historical tax positions taken by us or our acquired companies. While we believe we have taken proper tax positions, as reflected in our financial statements herein, foreign tax authorities may challenge certain tax positions we or our acquired companies have taken historically, or may take in the future. While we believe we have properly accrued for estimated tax obligations in the jurisdictions where we have filing obligations, we cannot be certain the tax authorities will agree with our tax positions. As a result, our tax positions may be challenged in the future, and subject to local-, state- and country-specific audits and inquiries, the outcomes of which could differ materially from our estimates. Incurring any such tax liabilities (including related penalties and interest) could materially adversely affect our business and financial condition.
Risk Related to Our Internal Use of Artificial Intelligence Technologies
We use AI, including generative AI, and machine learning technologies, including third-party generative AI technologies, to support various internal business functions such as software development, content creation, customer support, sales and marketing and operational decision-making. While these AI technologies may enhance the productivity and efficiency of our employees, such productivity gains are not guaranteed, and their use may present risks that could adversely affect our business, financial condition, and results of operations.
Data Security, Privacy and Confidentiality. The use of AI technologies by our employees, contractors, and vendors creates the risk that regulated or sensitive information, such as proprietary information, confidential business data, customer information, personal information or trade secrets may be inadvertently disclosed to third-party providers of AI technologies, which may “train” on that data. AI technologies may “train” on, or retain and learn from, inputs in ways that are not fully transparent, potentially compromising our intellectual property protections or comprising the unauthorized disclosure of sensitive information. Such events could expose us to adverse consequences, including regulatory scrutiny, contractual liability, competitive harm, or reputational damage.
Accuracy and Reliability. AI technologies may produce outputs that are inaccurate, incomplete, biased, or otherwise unreliable, and which may appear correct. If our personnel rely on AI-generated content or analysis without adequate verification, this could result in errors in our decision-making, including making decisions that could bias certain individuals (or classes of individuals) and adversely impact their rights, employment, and ability to obtain certain pricing, products, services, or benefits, as well as errors in our product development, customer communications, or regulatory filings, which could harm our business operations, customer relationships, reputation or expose us to legal liability.
39
Table of Contents
Governance and Compliance. We have established certain policies and guidelines related to the permissible use of AI technologies within our organization. However, we cannot guarantee that all personnel will comply with these policies and guidelines, and any failure to do so could result in violations of applicable laws, contractual obligations, or our own standards for responsible AI use. The regulatory environment for AI is evolving rapidly across multiple jurisdictions, including the European Union's AI Act and various U.S. state laws, and we expect other jurisdictions will adopt similar laws. Furthermore, AI technologies are subject to existing regulatory regimes, such as privacy, data security, and consumer protection laws, including those related to automated decision making. These obligations may be subject to differing applications and interpretations, which may be inconsistent or conflict among jurisdictions. Compliance with these requirements may impose additional costs, legal risks, or operational constraints on us, and our efforts to comply may not be successful.
Cybersecurity. AI technologies may introduce new cybersecurity vulnerabilities into our products or our IT systems, or may be used by threat actors to enable attacks, such as by developing more sophisticated tradecraft. The integration of AI technologies into our operations may increase our vulnerability to cyber-related attacks or the complexity of maintaining adequate security controls.
Reputational Risk. As a company that develops and sells AI solutions, our internal use of AI technologies may be subject to heightened scrutiny. Any perceived misuse, failures, or incidents related to our internal AI practices could disproportionately harm our reputation, erode customer trust, and negatively impact demand for our products and services.
We cannot predict all of the risks associated with our use of AI technologies, and the failure to foresee or effectively manage these risks could have a material adverse effect on our business, results of operations, and financial condition. For information about the legal and regulatory risks related to our use of AI technologies in our Software Products & Services, see the Risk Factor titled “Recent and proposed regulation of AI technologies, including facial recognition technology, the processing of biometric data, and automated decision-making and machine learning technologies, increase our compliance costs and otherwise make it harder for us to conduct our business, require us to change our business practices, and may lead to regulatory investigations or actions, litigation, reputational harm, and otherwise have a material adverse effect on our business.”
Risks Related to the Ownership of Our Securities and Our Public Company Operations
Our common stock price has been extremely volatile and could continue to fluctuate widely in price, which could result in substantial losses for investors.
The market price of our common stock has been, and we expect will continue to be, subject to extreme fluctuations over short periods of time. For example, the closing price of our common stock has ranged from a low of $1.22 to a high of $8.39 during the 12-month period ended April 10, 2026. Prior to that, from the completion of our initial public offering (“IPO”) on May 12, 2017 through April 10, 2025, the closing price of our common stock has ranged from a low of $1.49 to a high of $65.91.
These fluctuations may be due to various factors, many of which are beyond our control, including:
• the volume and timing of our revenues and quarterly variations in our results of operations or those of others in our industry;
• announcement of new contracts with customers or termination of contracts with customers;
• announcement of acquisitions of other companies or businesses, or other significant strategic transactions;
• announcement of equity or debt financing transactions;
• the introduction of new services, content or features by us or others in our industry;
• •media exposure of our products or of those of others in our industry;
• sales of our common stock;
• speculative trading practices of certain market participants;
• changes in earnings estimates or recommendations by securities analysts; and
• general economic and market conditions and other factors, including factors unrelated to our operating performance or the operating performance of our competitors.
40
Table of Contents
In recent years, the stock markets generally have experienced extreme price and volume fluctuations that have often been unrelated or disproportionate to the operating performance of the listed companies. Broad market and industry factors may significantly affect the market price of our common stock, regardless of our actual operating performance. These fluctuations have been, and may continue to be, even more pronounced in the trading market for our common stock.
In addition, in the past, class action litigation has often been instituted against companies whose securities have experienced periods of volatility in market price. Securities litigation brought against us following volatility in our stock price, regardless of the merit or ultimate results of such litigation, could result in substantial costs, which would hurt our financial condition and operating results and divert management’s attention and resources from our business.
We have identified material weaknesses in our internal control over financial reporting. If we are unable to develop and maintain effective internal control over financial reporting, we may not be able to accurately report our financial results in a timely manner, which may adversely affect investor confidence in us, materially and adversely affect our business and operating results and expose us to potential litigation.
As a public company, we are required to include in this report an assessment of the effectiveness of our internal control over financial reporting as of the end of our fiscal year, including a statement as to whether or not our internal control over financial reporting is effective. This assessment must include disclosure of any material weaknesses in our internal control over financial reporting identified by management. A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis.
During the preparation of our Form 10-K for the year ended December 31, 2025, management identified a material weakness in internal control over financial reporting relating to revenue recognition, specifically as it relates to the determination of the appropriate accounting for non-routine revenue transactions. This material weakness was not remediated as of December 31, 2025.
During the preparation of our Quarterly Report on Form 10-Q for the quarter ended June 30, 2024, management identified a material weakness in internal control over financial reporting relating to a lack of an effective information and communication process that identified and assessed the source of and controls necessary to ensure the reliability of information used in financial reporting and for providing information required for effective activity level controls. This material weakness could have resulted in a material misstatement to our consolidated financial statements that would not be prevented or detected on a timely basis. This material weakness was not remediated as of December 31, 2025
During the preparation of our Annual Report on Form 10-K for the fiscal years ended December 31, 2023 and 2022, management identified the following material weaknesses in internal control over financial reporting, which have not been remediated as of December 31, 2025:
• Management identified a material weakness in internal control over financial reporting relating to the consolidation process and review of financial statements specifically pertaining to the Company’s design of controls to determine proper accounting for certain foreign exchange transactions and translation between Veritone, Inc. and certain foreign subsidiaries. This material weakness did not result in any identified material misstatements to the financial statements. However, this material weakness could have resulted in a material misstatement to our annual or interim condensed consolidated financial statements that would not be prevented or detected and corrected on a timely basis.
• Management identified a material weakness in internal control over financial reporting relating to information technology general controls (“ITGCs”) in the areas of user access and change-management over certain information technology (“IT”) systems that support our financial reporting processes. Our business process automated and manual controls that are dependent on the affected ITGCs were also deemed ineffective because they could have been adversely impacted. These control deficiencies were a result of user access and change management processes over certain IT systems.
Related to the findings above, management concluded that during the year ended December 31, 2023, we did not maintain appropriately designed entity-level controls impacting the control environment or monitoring controls to prevent or detect material misstatements to the consolidated financial statements. Specifically, these deficiencies were attributed to (i) a lack of a sufficient number of qualified resources to perform control activities and (ii) insufficient risk assessment and monitoring activities as a result of untimely or ineffective identification of internal control risks to properly design, test, implement and assess effective internal controls over financial reporting.
41
Table of Contents
Any failure to develop or maintain effective controls, or any difficulties encountered in their implementation or improvement, could harm our results of operations or cause us to fail to meet our reporting obligations and may result in a restatement of our financial statements for prior periods. Ineffective internal control over financial reporting could also cause investors to lose confidence in our reported financial and other information and our stock price may decline as a result. We could also lose access to sources of capital or liquidity. In addition, if we are unable to continue to meet these requirements, we may not be able to remain listed on NASDAQ. Though we are taking steps to remediate the existing material weaknesses, we cannot be assured that the measures we have taken to date, or any measures we may take in the future, will be sufficient to remediate the material weakness or avoid potential future material weaknesses.
As a result of the material weaknesses described above and other related matters raised or that may in the future be identified, we also face potential for adverse regulatory consequences, including investigations, penalties or suspensions by the SEC or NASDAQ, litigation or other disputes which may include, among others, claims invoking the federal and state securities laws, contractual claims or other claims arising from the restatement and material weakness in our internal control over financial reporting and the preparation of our consolidated financial statements. As of the date of this filing, we have no knowledge of any such regulatory consequences, litigation, claim or dispute. However, we can provide no assurance that such regulatory consequences, litigation, claim or dispute will not arise in the future. Any such regulatory consequences, litigation, claim or dispute, whether successful or not, could subject us to additional costs, divert the attention of our management, or impair our reputation. Each of these consequences could have a material adverse effect on our business, results of operations and financial condition.
We are a “smaller reporting company” and “non-accelerated filer” under the U.S. federal securities laws, and the reduced reporting requirements applicable to smaller reporting companies and non-accelerated filers could make our common stock less attractive to investors.
We are a “smaller reporting company.” For as long as we continue to be a smaller reporting company, we may take advantage of exemptions from various reporting requirements that are applicable to other public companies that are not smaller reporting companies, including reduced disclosure obligations regarding executive compensation in our periodic reports and proxy statements. Investors may not find our common stock attractive because we rely on these reduced disclosure requirements. In addition, we qualify as a non-accelerated filer. For as long as we continue to be a non-accelerated filer, we will not be required to have our independent registered public accounting firm attest to the effectiveness of our internal control over financial reporting. If some investors find our common stock less attractive as a result, there may be a less active trading market for our common stock and our stock price may be more volatile.
Our anti-takeover provisions could prevent or delay a change in control of our company, even if such change in control would be beneficial to our stockholders.
Provisions of our amended and restated certificate of incorporation and amended and restated bylaws as well as provisions of Delaware law could discourage, delay or prevent a merger, acquisition or other change in control of our company, even if such change in control would be beneficial to our stockholders. These include:
• authorizing the issuance of “blank check” preferred stock that could be issued by our Board to increase the number of outstanding shares and thwart a takeover attempt;
• a provision for a classified board of directors so that not all members of our Board are elected at one time;
• the removal of directors only for cause;
• no provision for the use of cumulative voting for the election of directors;
• limiting the ability of stockholders to call special meetings;
• requiring all stockholder actions to be taken at a meeting of our stockholders (i.e., no provision for stockholder action by written consent); and
• establishing advance notice requirements for nominations for election to the Board or for proposing matters that can be acted upon by stockholders at stockholder meetings.
In addition, the Delaware General Corporation Law prohibits us, except under specified circumstances, from engaging in any mergers, significant sales of stock or assets or business combinations with any stockholder or group of stockholders who owns at least 15% of our common stock.
42
Table of Contents
Additionally, certain provisions in the indenture governing our Convertible Notes may make it more difficult or expensive for a third party to acquire us. For example, the indenture will generally require us to repurchase the Convertible Notes for cash upon the occurrence of a fundamental change of us and, in certain circumstances, to increase the conversion rate for a holder that converts its Convertible Notes in connection with a make-whole fundamental change. A takeover of us may trigger the requirement that we repurchase the Convertible Notes and/or increase the conversion rate, which could make it more costly for a potential acquiror to engage in such takeover. Such additional costs may have the effect of delaying or preventing a takeover of us that would otherwise be beneficial to stockholders.
Our amended and restated certificate of incorporation designates the Court of Chancery of the State of Delaware as the sole and exclusive forum for certain types of actions and proceedings that may be initiated by our stockholders, which could limit our stockholders’ ability to obtain a favorable judicial forum for disputes with us or our directors, officers or other employees.
Our amended and restated certificate of incorporation provides that, unless we consent in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware shall be the sole and exclusive forum for:
• any derivative action or proceeding brought on our behalf;
• any action asserting a claim of breach of a fiduciary duty owed by any of our directors, officers or other employees to us or to our stockholders;
• any action asserting a claim against us arising pursuant to any provision of the Delaware General Corporation Law, our amended and restated certificate of incorporation or our amended and restated bylaws; or
• any action asserting a claim against us governed by the internal affairs doctrine.
Any person or entity purchasing or otherwise acquiring any interest in shares of our capital stock shall be deemed to have notice of and consented to this provision of our amended and restated certificate of incorporation. This choice-of-forum provision may limit a stockholder’s ability to bring a claim in a judicial forum that it finds favorable or convenient for disputes with us or our directors, officers or other employees, which may discourage such lawsuits against us and our directors, officers and other employees. Alternatively, if a court were to find these provisions of our amended and restated certificate of incorporation inapplicable to, or unenforceable in respect of, one or more of the specified types of actions or proceedings, we may incur additional costs associated with resolving such matters in other jurisdictions, which could adversely affect our business, financial condition or results of operations.
Conversion or exercise of outstanding equity-linked securities may dilute the ownership interest of our stockholders or may otherwise depress the price of our common stock.
We have a substantial number of shares of our common stock reserved for issuance upon the exercise of stock options, settlement of restricted stock units, exercise of warrants, including pre-funded warrants, and upon conversion of our Convertible Notes. The exercise or conversion of some or all of these securities may dilute the ownership interests of our stockholders. Upon conversion of our Convertible Notes, we have the option to pay or deliver, as the case may be, cash, shares of our common stock, or a combination of cash and shares of our common stock. If we elect to settle our conversion obligation in shares of our common stock or a combination of cash and shares of our common stock, any sales in the public market of our common stock issuable upon such conversion could adversely affect prevailing market prices of our common stock. In addition, the existence of the Convertible Notes may encourage short selling by market participants because the conversion of the Convertible Notes could be used to satisfy short positions, or anticipated conversion of the Convertible Notes into shares of our common stock could depress the price of our common stock.
If securities or industry analysts do not publish research or publish inaccurate or unfavorable research about our business, our stock price and trading volume could decline.
The trading market for our common stock will rely in part on the research and reports that securities or industry analysts publish about us and our business. If one or more of the analysts who cover us downgrades our common stock or issues other unfavorable commentary or research the price of our common stock may decline. If one or more analysts ceases coverage of our company or fails to publish reports on us regularly, demand for our stock could decrease, which in turn could cause the trading price or trading volume of our common stock to decline and could result in the loss of all or part of your investment in us.