{"url_path":"/sec/chai/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY.**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1649009/0001493152-26-023908-index.html","accession_number":"0001493152-26-023908","cik":"0001649009","ticker":"CHAI","issuer_name":"Core AI Holdings, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1649009/0001493152-26-023908-index.html","primary_entity_key":"0001649009","primary_entity_name":"Core AI Holdings, Inc."},"word_count":541,"has_tables":true,"body_markdown":"**Item\n16K. CYBERSECURITY.**\n\n \n\n**Cybersecurity\nRisk management and strategy**\n\n \n\nOur\ncybersecurity risk management program aims to fully identify threats, to present and evaluate them transparently, to mitigate, and manage\nthem proactively. We have developed and implemented a cybersecurity risk management process intended to protect the confidentiality,\nintegrity, and availability of our critical systems and information.\n\n \n\n70\n\n \n\n \n\nOur\ncybersecurity risk management process guides us in making cybersecurity risk-informed decisions and provides the basis for evaluating\nand monitoring the cybersecurity risk profile of the Company. This process provides a shared understanding and promotes a consistent\napproach to cybersecurity risk management within the Company in line with our information security policy and includes a cybersecurity\nincident response plan.\n\n \n\nAs\npart of our cybersecurity risk management program, we review industry best practices, including the NIST (National Institute of Standards\nand Technology) Cybersecurity Framework and ISO (International Organization for Standardization) 27001 to manage information security.\nWe periodically conduct ongoing internal and external vulnerability analyses, including simulated attack as well as external testing\nvia a third-party to evaluate the effectiveness of our cybersecurity process and controls.\n\n \n\nIn\nan effort to minimize third-party risk, we have established a process to assess the security practices of third-party vendors and service\nproviders and related risks. Our process includes a security assessment informed by vendor questionnaires and contractual security requirements\nrelated to data privacy for certain vendors.\n\n \n\nThe\nSOC is responsible for investigating all security incidents and alerts including determining the threat type, incident scope and incident\nseverity. Where appropriate, major incidents are escalated according to cybersecurity incident process.\n\n \n\nEmployee\nawareness and training are essential to our ability as a company to thwart cyber-attacks. We continuously raise employees’ risk\nawareness with mandatory, regular online training for all employees and complimentary awareness campaigns.\n\n \n\nIn\n2025, we did not identify any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have\nmaterially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial\ncondition. Despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurance that we have not experienced\nan undetected cybersecurity incident. For more information about these risks, please see *Item 3. Key Information – D. Risk Factors.*\n\n \n\n**Cybersecurity\nGovernance**\n\n \n\nOur\nboard of directors has overall oversight responsibility for our risk management strategy, and delegates information security and related\nrisk management oversight to the Audit Committee. Members of the audit committee receive regular updates from management regarding cybersecurity\nrelated matters. This includes existing and new cybersecurity risks, how management is addressing, managing and/or mitigating those risks,\ncybersecurity and data privacy incidents (if relevant), and the status of key information security initiatives.\n\n \n\nOur\nmanagement and our cybersecurity and risks council overseas regular review of cybersecurity risk management activities, is responsible\nfor the management of our cyber risk exposure and monitoring the effectiveness of the cybersecurity program, including but not limited\nto, our cybersecurity tools and controls, and is responsible for establishing and reviewing our risk tolerance for our cyber risk framework.\n\n \n\nThe\ncybersecurity and risks council includes the Chief Executive Officer, the Chief Financial Officer and cybersecurity specialists. Those employees have decades of experience\nin cybersecurity and operations, cybersecurity education, and certifications from various organizations.\n\n \n\n71\n\n \n\n \n\n**PART\nIII**"}