Presenter notes visible — press P to hide before sharing this screen
Press P for presenter notes
Ring Energy Prepared for Ring Energy, Inc.

AI governance — an outside view.

We ran the search your next investor, insurer or major customer is going to run. This is what came back.

Motion Consulting Group · a Kelly Services company · July 2026

Open here

Do not narrate the cover. Let them look at their own logo for a beat, then say the one line: we ran the search your next investor is going to run. Then move.

What is visible from outside

Eight things an outsider looks for.

This measures what is publicly findable — not what exists inside the company. "Not found" means an outsider could not locate it, which is exactly where an investor or insurer stands.

01 AI or automation named in public filings Across the FY2025 10-K, the April 2026 proxy, sustainability reports, careers pages and press releases Not found
02 AI named in 10-K risk factors The risk factor "Risks Relating to Technology and Cybersecurity" is present and detailed — it addresses digital dependence, not AI specifically Not found
03 Cybersecurity governance disclosure — Item 1C NIST-framework based, a named Director of IT & Cybersecurity, a Management Cybersecurity Committee, Audit Committee oversight, third-party assessors Visible — and strong
04 A published technology, data or AI policy Seven governance documents are published; none located that addresses AI or data use Not found
05 Named accountability for AI Cyber accountability is named and specific. The equivalent for AI was not located. Partial
06 AI or data capability visible in hiring Three roles open at time of review — land, lease records and HSE. None technology-specific. Not found
07 Third-party AI exposure acknowledged Vendors, service providers and purchasers are named as digitally dependent in the risk factor; no AI-specific vendor language located Partial
08 Peer disclosure comparison We could not locate a published AI governance policy at any oil and gas company — including Shell, BP, Chevron, ExxonMobil, ConocoPhillips, Equinor, Baker Hughes and SLB. Note: SEC.gov blocked automated access, so peer filings were not read directly. Nobody has one
1Visible
3Partial
4Not found
The honest frame

Say plainly that this measures what is PUBLICLY FINDABLE, not what they do internally. If the IT director says 'we have that, it is just not published' — that is the win. Write it down and move on warmly. Do not defend the finding.

What it means

You have already built this once.

The most useful finding is not an absence. It is that Ring's cybersecurity governance is genuinely well constructed — NIST-based, a named director with the credentials to hold it, a standing management committee, board oversight through Audit, outside assessors engaged.

That is the same apparatus AI governance requires. The framework simply has not been extended to it yet — and on that point, the sector is wide open. We could not find a published AI governance policy at any oil and gas company, majors included.

What an investor sees

A Russell 3000 constituent since June, with rising institutional visibility, whose filings do not yet address a category their other holdings have started disclosing.

What an insurer sees

Excellent cyber posture, clearly documented. No documented answer yet on AI — increasingly a separate question at renewal.

What a customer's procurement team sees

A vendor with a strong security answer and no AI answer, at a moment when both questions are starting to appear on the same form.

The whole pitch is here

This is the slide that decides the meeting. Lead with the compliment and mean it: their cyber governance is genuinely well built. NIST, a named director, a standing committee, board oversight. Then the turn: that is the same apparatus AI needs, and nobody in the industry has extended it yet.

What is happening in your sector

Where operators are finding real returns.

Named operators, measured outcomes. Included because it is useful to you whether or not we ever work together.

Give this away

No ask on this slide. Devon is the closest analogue — Delaware Basin, artificial lift, first-party numbers from an earnings call. Chord is rod lift, which is their equipment. If they only take one thing from the meeting, let it be this slide.

What we would do

Small, specific, and yours to keep.

Not a transformation programme — the same shape as the cyber work already in place, extended one category across.

1

An inventory

Where AI is already in use — in your systems, and in your vendors' systems operating on your data. Most companies find more than they expected.

2

A written posture

One document: what is permitted, what requires review, who signs. Modelled on the cybersecurity programme you already run.

3

A board-ready readout

The answer to the question, in the form the Audit Committee already receives cyber reporting.

The unusual part: we searched for a published AI governance policy at every major in this industry and did not find one. A one-page position, adopted now, would put Ring ahead of operators many times its size — not by spending more, but by writing it down first.

Twenty minutes is enough to know whether this is worth anything to you. Richard Taubin · Motion Consulting Group, a Kelly Services company.

How we verified all of this → — every source, the method, and what we could not confirm.

The ask is twenty minutes

Not a programme, not a proposal. Land the first-mover point: no major in this industry has published an AI policy, so a one-page position puts them ahead of companies many times their size. Then stop talking.