{"url_path":"/sec/aitx/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-09","source_url":"https://www.sec.gov/Archives/edgar/data/1498148/0001493152-26-027796-index.html","accession_number":"0001493152-26-027796","cik":"0001498148","ticker":"AITX","issuer_name":"Artificial Intelligence Technology Solutions Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1498148/0001493152-26-027796-index.html","primary_entity_key":"0001498148","primary_entity_name":"Artificial Intelligence Technology Solutions Inc."},"word_count":397,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nRisk\nManagement and Strategy\n\n \n\nSecuring\nour business information, intellectual property, customer and employee data and technology systems is essential for the continuity of\nour business, meeting applicable regulatory requirements and maintaining the trust of our stockholders. Cybersecurity is an important\nand integrated part of our enterprise risk management function that identifies, monitors and mitigates business, operational and legal\nrisks.\n\n \n\nTo\nhelp protect us from a major cybersecurity incident that could have a material impact on operations or our financial results, the Company\nis in the process of continually implementing policies, programs and controls, including technology investments that focus on cybersecurity\nincident prevention, identification and mitigation. The steps we expect to take to reduce our vulnerability to cyberattacks and to mitigate\nimpacts from cybersecurity incidents include but are not limited to: penetration testing by a third-party vendor, agent-based security\nscanning that runs continuously, establishing information security policies and standards, implementing information protection processes\nand technologies, monitoring our information technology systems for cybersecurity threats and implementing cybersecurity training. The\nCompany has reached SOC 2 Type 2 status which shows the Company’s compliance with best industry practices. The SOC 2 Report has\nbecome a benchmark standard, and now an often-specified requirement, in the software procurement process. Established by the American\nInstitute of Certified Public Accountants (AICPA), criteria and reporting principles are outlined as a means for organizations to create\na documented framework of policies and procedures to prove how they manage and secure data in the cloud and ensure protection of customer\nprivacy and ensure internal communications are suitably handled. This achievement reflects the Company’s stated goals of best-in-class\ndata protection and internal processes. In addition, we annually purchase a cybersecurity risk insurance policy that would help defray\nthe costs associated with a covered cybersecurity incident if it occurred.\n\n \n\n-17-\n\n[Table of Contents](#toc_001)\n\n \n\nGovernance\n\n \n\nOur\nCEO and management are actively engaged in overseeing and reviewing our strategic direction and objectives, taking into account, among\nother considerations, our risk profile and related exposures, including oversight of risks from cybersecurity threats. As part of this\noversight, the Company will update the CEO and Board of Directors periodically, and at least annually, on our cybersecurity program,\nincluding with respect to particular cybersecurity threats, cybersecurity incidents, new developments in our risk profile, the status\nof projects to strengthen our cybersecurity systems, assessments of our cybersecurity program, and the emerging threat landscape."}