symbology.online COMPARATIVE SYNTHESIS 

Adobe Inc
Risk Factors synthesis.

Adobe Inc.'s quarterly disclosures for FY 2026 reveal a material financial adjustment, as the company recorded a goodwill impairment charge specifically tied to its Publishing & Advertising reporting unit. This write-down indicates potential changes in performance expectations or strategic shifts within that segment since the last annual report baseline. These financial developments emerged alongside updates detailing ongoing operational efforts to enhance data resilience through internal migration processes.

FY2025 → FY2026 L2 Comparitive Synthesis
  symbology.online l2 SYNTHESIS 

Adobe Inc - Risk Factors synthesis.

Fiscal Year Developments Since Annual Baseline

The disclosures across the quarterly filings indicate that while the core risks related to AI disruption, global regulatory complexity, and cybersecurity vulnerabilities remain consistent with the annual baseline, material financial and operational developments have emerged during the fiscal year.

Financial Adjustments and Impairment Charges

A significant development recorded in Q2 FY 2026 was a direct financial impact tied to strategic business units. The company disclosed recording a goodwill impairment charge related specifically to the Publishing & Advertising reporting unit. This indicates potential write-downs stemming from performance expectations or changes within that segment, a matter not present in the initial annual report disclosure.

Operational Resilience and Infrastructure Updates

While the baseline filings consistently highlighted the vulnerability of relying on single data centers and third-party providers for critical systems, Q2 FY 2026 provided an update regarding mitigation efforts. The company disclosed engaging in data migration processes among its various data centers and third-party hosted environments. This reflects ongoing operational planning aimed at improving resilience against system failures, even as the inherent dependency on external factors remains a primary weakness.

Risk Trend Reinforcement

Throughout the year, the filings consistently reinforced the acceleration of key risks:

  • AI Disruption: The competitive landscape continues to intensify, with Q2 FY 2026 emphasizing that there is "no assurance" that new AI innovations will be successfully adopted or monetizable, compounding the pressure on the company to continually invest in proprietary datasets and models.
  • Regulatory Scrutiny: Regulatory activity remains a growing concern, with filings noting an overall trend of expanding global laws (e.g., GDPR, CCPA) and confirming that obligations under frameworks like the EU AI Act will continue to be implemented in phases through 2030.

Side-by-side against the previous Risk Factors.

  FY2026 → FY2026 Text Diffs 

escalated If our goodwill or intangible assets become impaired, then we could be required to record a significant charge to earnings. The company disclosed that it recorded a goodwill impairment charge in the second quarter of fiscal 2026 related to its Publishing & Advertising reporting unit.

FY 2026 Q1 10-Q
Removed
Filed Mar 25, 2026

If our goodwill or intangible assets become impaired, then we could be required to record a significant charge to earnings. We test goodwill for impairment at least annually. We review our goodwill and intangible assets for impairment when events or changes in circumstances indicate the carrying value may not be recoverable, including declines in stock price, market capitalization or reduced future cash flow estimates and slower growth rates in our industry. Depending on the results of our review, we may be required to record a significant charge to earnings in our consolidated financial statements during the period in which any impairment of our goodwill or intangible assets was determined, negatively impacting our results of operations. 46

FY 2026 Q2 10-Q
Added
Filed Jun 15, 2026

If our goodwill or intangible assets become impaired, then we could be required to record a significant charge to earnings. We test goodwill for impairment at least annually. We review our goodwill and intangible assets for impairment when events or changes in circumstances indicate the carrying value may not be recoverable, including declines in stock price, market capitalization or reduced future cash flow estimates and slower growth rates in our industry. In the second quarter of fiscal 2026, we recorded a goodwill impairment charge related to our Publishing & Advertising reporting unit. We may be required to record additional charges to earnings in our consolidated financial statements during the period in which any impairment of our goodwill or intangible assets is determined, negatively impacting our results of operations. For additional information regarding our goodwill impairment, see Part I, Item 1, Note 7 of our notes to condensed consolidated financial statements. 48

de-emphasised Risks Related to the Operation of Our Business The entire disclosure regarding reliance on third-party service providers and technologies has been removed from the current filing. This section previously detailed operational risks associated with critical systems, including cloud infrastructure, generative AI, large language models, encryption technology, and company communication channels.

FY 2026 Q1 10-Q
Removed
Filed Mar 25, 2026

may reduce our margins. Breaches of our security measures and the accidental loss, inadvertent disclosure or unauthorized dissemination of proprietary information or sensitive, personal or confidential data about us, our employees, our customers or their end users, including the potential loss or disclosure of such information or data have in the past, and could in the future, expose us, our employees, our customers or other individuals affected to a risk of loss or misuse of this information. Further, our efforts to address these problems, including notifying affected third parties when appropriate, have in the past been, and may in the future be, unsuccessful or delayed, which could result in business interruptions, cessation of service, loss of existing or potential customers and reputational harm. Actual or perceived security vulnerabilities or incidents have resulted in, and may result in additional, claims or litigation and liability or fines, costly and time-intensive notice requirements, governmental inquiry or oversight or a loss of customer confidence, any of which have in the past and may in the future harm our business and damage our brand and reputation. Our customers may also adopt security measures to protect their computer systems and their instances of our software from attack and may suffer a cybersecurity breach on their own systems, unrelated to our systems. Even if such breach is unrelated to our security systems, solutions or programs, such breach could cause us reputational harm and require us to incur significant economic and operational consequences to adequately assess and respond to their breach, and to implement additional safeguards designed to protect against future breaches. While we maintain insurance to cover operational risks, such as cybersecurity risk and technology outages, our insurance may not be sufficient to cover all liability described herein. These risks will likely increase as we expand our hosted solutions, integrate our solutions and store and process more data. Moreover, delayed sales, lower margins or lost customers resulting from disruptions caused by cyberattacks, data breaches, overly burdensome preventive security measures or failure to fully meet information security control certification requirements could materially and adversely affect our financial results, stock price and reputation. If we are unable to develop, manage and maintain our sales channels, including our direct sales force, third-party distributors, and sales partners, or third-party relationships upon which we rely for critical business operations, our revenue and business may be adversely affected. We rely on our direct sales channel and a number of third-party distributors and sales partners to distribute our solutions. The successful management of these relationships is a complex, global process. We sell many solutions through our direct sales force. Risks associated with this sales channel include challenges related to hiring, retaining and motivating our direct sales force, and substantial amounts of ongoing training for sales representatives. Our business could be harmed if our direct sales expansion efforts do not generate the corresponding efficiencies and revenue we anticipated from such investment. In addition, the loss of key sales employees could impact our customer relationships and future ability to sell to certain accounts covered by such employees. Moreover, if our partner and distribution channels are not effective or if we stop or change our partner or distribution channels, we may lose sales opportunities, customers and revenue. We rely on third-party distribution platforms and are subject to changes in pricing structure, terms of service, privacy practices and other policies at the discretion of the platform provider. Any adverse changes to the terms with such third-party distribution platforms which we rely on to distribute our solutions may adversely affect our financial results. Additionally, our distribution channels may not continue to market or sell our solutions effectively and may favor solutions of other companies. If an agreement with one of our distributors or partners was terminated, any prolonged delay in securing a replacement distributor or partner could have a negative impact on our results of operations. We also face legal risk and potential reputational harm from the activities of these independent third parties including, but not limited to, export control violations, workplace conditions, corruption and anti-competitive behavior. We also rely on third-party service providers and technologies to deliver our solutions and business operations and to operate critical business systems, such as cloud-based infrastructure, data center facilities, generative AI, large language models, encryption and authentication technology, company email and other communication channels, and communications with customers. If such third parties are negatively affected, if we fail to effectively develop, manage and maintain our relationships with such third parties, or if we are unable to renew our agreements with them on favorable terms or at all, our expenses could significantly increase, and we and our customers may experience service interruptions. Any disruption or damage to, or failure of our systems generally, including the systems of our third-party platform providers, could result in interruptions in our services and harm our business. Further, interruptions in our services caused by us or our third-party service providers may cause us to issue credits or pay penalties, cause customers to make warranty or other claims against us or to terminate their subscriptions or contracts, and adversely affect our attrition rates and our ability to attract new customers, all of which may adversely affect our financial results. Our business and reputation would also be harmed if our customers and potential customers believe our services are unreliable. 41

FY 2026 Q2 10-Q
Added
Filed Jun 15, 2026

not keep pace with quickly evolving threats. The costs to prevent, eliminate, mitigate or remediate cybersecurity or other security problems and vulnerabilities are significant and may reduce our margins. Breaches of our security measures and the accidental loss, inadvertent disclosure or unauthorized dissemination of proprietary information or sensitive, personal or confidential data about us, our employees, our customers or their end users, including the potential loss or disclosure of such information or data have in the past, and could in the future, expose us, our employees, our customers or other individuals affected to a risk of loss or misuse of this information. Further, our efforts to address these problems, including notifying affected third parties when appropriate, have in the past been, and may in the future be, unsuccessful or delayed, which could result in business interruptions, cessation of service, loss of existing or potential customers and reputational harm. Actual or perceived security vulnerabilities or incidents have resulted in, and may result in additional, claims or litigation and liability or fines, costly and time-intensive notice requirements, governmental inquiry or oversight or a loss of customer confidence, any of which have in the past and may in the future harm our business and damage our brand and reputation. Our customers may also adopt security measures to protect their computer systems and their instances of our software from attack and may suffer a cybersecurity breach on their own systems, unrelated to our systems. Even if such breach is unrelated to our security systems, solutions or programs, such breach could cause us reputational harm and require us to incur significant economic and operational consequences to adequately assess and respond to their breach, and to implement additional safeguards designed to protect against future breaches. While we maintain insurance to cover operational risks, such as cybersecurity risk and technology outages, our insurance may not be sufficient to cover all liability described herein. These risks will likely increase as we expand our hosted solutions, integrate our solutions and store and process more data. Moreover, delayed sales, lower margins or lost customers resulting from disruptions caused by cyberattacks, data breaches, overly burdensome preventive security measures or failure to fully meet information security control certification requirements could materially and adversely affect our financial results, stock price and reputation. If we are unable to develop, manage and maintain our sales channels, including our direct sales force, third-party distributors, and sales partners, or third-party relationships upon which we rely for critical business operations, our revenue and business may be adversely affected. We rely on our direct sales channel and a number of third-party distributors and sales partners to distribute our solutions. The successful management of these relationships is a complex, global process. We sell many solutions through our direct sales force. Risks associated with this sales channel include challenges related to hiring, retaining and motivating our direct sales force, and substantial amounts of ongoing training for sales representatives. Our business could be harmed if our direct sales expansion efforts do not generate the corresponding efficiencies and revenue we anticipated from such investment. In addition, the loss of key sales employees could impact our customer relationships and future ability to sell to certain accounts covered by such employees. Moreover, if our partner and distribution channels are not effective or if we stop or change our partner or distribution channels, we may lose sales opportunities, customers and revenue. We rely on third-party distribution platforms and are subject to changes in pricing structure, terms of service, privacy practices and other policies at the discretion of the platform provider. Any adverse changes to the terms with such third-party distribution platforms which we rely on to distribute our solutions may adversely affect our financial results. Additionally, our distribution channels may not continue to market or sell our solutions effectively and may favor solutions of other companies. If an agreement with one of our distributors or partners was terminated, any prolonged delay in securing a replacement distributor or partner could have a negative impact on our results of operations. We also face legal risk and potential reputational harm from the activities of these independent third parties including, but not limited to, export control violations, workplace conditions, corruption and anti-competitive behavior.

reworded Our existing and future debt obligations may adversely affect our financial condition and future financial results. The commercial paper program shifted from having no amounts outstanding to having $500 million outstanding as of May 29, 2026.

FY 2026 Q1 10-Q
Removed
Filed Mar 25, 2026

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of February 27, 2026, we had $6.15 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

FY 2026 Q2 10-Q
Added
Filed Jun 15, 2026

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of May 29, 2026, we had $6.15 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with $500 million outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

reworded Risks Related to the Operation of Our Business The risk disclosure was updated to specifically warn that the emergence of cyber-focused large language models may accelerate vulnerability exploitation and increase the frequency, speed, and severity of threats.

FY 2026 Q1 10-Q
Removed
Filed Mar 25, 2026

Our solutions collect, store, manage and otherwise process third-party data, including our customers' data and our own data. Such solutions as well as our technologies, systems and networks have been subject to, and may in the future be subject to, cyberattacks, computer viruses, ransomware or other malware, fraud, worms, social engineering, denial-of-service attacks, malicious software programs, insider threats and other cybersecurity incidents that have in the past, and may in the future, result in the unauthorized access, disclosure, acquisition, use, loss or destruction of sensitive personal or business data belonging to us, our employees and our customers. Some of our solutions include third-party open-source software, which may contain security vulnerabilities that may be exploited, potentially compromising our solutions. Increasing use of AI in our internal systems and solutions may create new attack methods. Cybersecurity incidents can be caused by human error from our workforce or that of our third-party service providers, by malicious third parties, acting alone or in groups, or by more sophisticated organizations, including nation-states and state-sponsored organizations. Such risks may be elevated in connection with geopolitical tensions, including the Russia-Ukraine war and the conflict in the Middle East, as well as malicious third parties utilizing emerging technologies, such as AI and machine learning. Certain unauthorized parties have in the past managed, and may in the future manage, to overcome our security measures and those of our third-party service providers to access and misuse systems and software by exploiting defects in design, configuration or manufacture, including bugs, vulnerabilities, change management errors and other problems that unexpectedly compromise the security or operation of a product or system. Further, unauthorized parties or authorized parties that exceed their authorized access may also gain physical access to our facilities and infiltrate our information systems or attempt to gain logical access to our solutions or information systems to access content and data and may result in computer viruses, worms, ransomware or other malware. Malicious third parties have in the past, and may in the future, fraudulently induce our employees or users of our solutions to disclose sensitive, personal or confidential information via illegal electronic spamming, phishing, social engineering or other tactics, and this risk is heightened in our current hybrid model working environment. Our solutions are incorporated into the supply chain of a large number of companies worldwide and, as a result, if our solutions experience a compromise, a large portion or, in some instances, all of our customers and their data for a given solution could be simultaneously affected. The potential liability and associated consequences we could suffer as a result of such a large scale event could be significant, and materially and adversely impact our business. Malicious actors may also engage in fraudulent or abusive activities through our solutions, including unauthorized use of accounts through stolen credentials, use of stolen credit cards or other payment vehicles, failure to pay for services accessed, or other activities that violate our terms of service. While we actively combat such fraudulent activities, we have experienced, and may in the future experience, impacts to our revenue and reputation from such activities. Maintaining the security of our solutions is a critical issue for us and our customers. We devote significant resources to address security vulnerabilities through various methods, including, but not limited to, engineering more secure products, enhancing security and reliability features in our products and systems, regularly reviewing our service providers' security controls, and continually assessing and improving, as appropriate, our incident response process. However, it is impossible to accurately predict the extent, frequency or impact cybersecurity issues may have on us, and our security measures do not provide full effective protection from all such events. There can be no assurance that we have the capability to detect all vulnerabilities or new attack methods and our internal security controls may not keep pace with quickly evolving threats. The costs to prevent, eliminate, mitigate or remediate cybersecurity or other security problems and vulnerabilities are significant and 40

FY 2026 Q2 10-Q
Added
Filed Jun 15, 2026

Our solutions collect, store, manage and otherwise process third-party data, including our customers' data and our own data. Such solutions as well as our technologies, systems and networks have been subject to, and may in the future be subject to, cyberattacks, computer viruses, ransomware or other malware, fraud, worms, social engineering, denial-of-service attacks, malicious software programs, insider threats and other cybersecurity incidents that have in the past, and may in the future, result in the unauthorized access, disclosure, acquisition, use, loss or destruction of sensitive personal or business data belonging to us, our employees and our customers. Some of our solutions include third-party open-source software, which may contain security vulnerabilities that may be exploited, potentially compromising our solutions. Increasing use of AI in our internal systems and solutions may create new attack methods. Cybersecurity incidents can be caused by human error from our workforce or that of our third-party service providers, by malicious third parties, acting alone or in groups, or by more sophisticated organizations, including nation-states and state-sponsored organizations. Such risks may be elevated in connection with geopolitical tensions, including the Russia-Ukraine war and the conflict in the Middle East, as well as malicious third parties utilizing emerging technologies, such as AI and machine learning. Certain unauthorized parties have in the past managed, and may in the future manage, to overcome our security measures and those of our third-party service providers to access and misuse systems and software by exploiting defects in design, configuration or manufacture, including bugs, vulnerabilities, change management errors and other problems that unexpectedly compromise the security or operation of a product or system. Further, unauthorized parties or authorized parties that exceed their authorized access may also gain physical access to our facilities and infiltrate our information systems or attempt to gain logical access to our solutions or information systems to access content and data and may result in computer viruses, worms, ransomware or other malware. Malicious third parties have in the past, and may in the future, fraudulently induce our employees or users of our solutions to disclose sensitive, personal or confidential information via illegal electronic spamming, phishing, social engineering or other tactics, and this risk is heightened in our current hybrid model working environment. Our solutions are incorporated into the supply chain of a large number of companies worldwide and, as a result, if our solutions experience a compromise, a large portion or, in some instances, all of our customers and their data for a given solution could be simultaneously affected. The potential liability and associated consequences we could suffer as a result of such a large scale event could be significant, and materially and adversely impact our business. Malicious actors may also engage in fraudulent or abusive activities through our solutions, including unauthorized use of accounts through stolen credentials, use of stolen credit cards or other payment vehicles, failure to pay for services accessed, or other activities that violate our terms of service. While we actively combat such fraudulent activities, we have experienced, and may in the future experience, impacts to our revenue and reputation from such activities. Maintaining the security of our solutions is a critical issue for us and our customers. We devote significant resources to address security vulnerabilities through various methods, including, but not limited to, engineering more secure products, enhancing security and reliability features in our products and systems, regularly reviewing our service providers' security controls, and continually assessing and improving, as appropriate, our incident response process. However, it is impossible to accurately predict the extent, frequency or impact cybersecurity issues may have on us, and our security measures do not provide full effective protection from all such events. The emergence of cyber-focused large language models may continue to accelerate the exploitation of vulnerabilities, and increase the frequency, speed and severity of threats. There can be no assurance that we have the capability to detect all vulnerabilities or new attack methods and our internal security controls may 42

  FY2025 → FY2026 Text Diffs 

escalated ITEM 1A. RISK FACTORS The current filing adds a concluding statement clarifying that all risk factor disclosures are based on management's beliefs about potential future adverse effects and are not representations of whether such factors have occurred in the past.

FY 2025 10-K
Removed
Filed Jan 15, 2026

Table of Contents ITEM 1A. RISK FACTORS As previously discussed, our actual results could differ materially from our forward-looking statements. Below we discuss some of the factors that could cause these differences. The occurrence of these and many other factors described in this report, and factors that we do not presently know or that we currently believe to be immaterial, could materially and adversely affect our operations, performance and financial condition. Many factors affect more than one category and the factors are not in order of significance or probability of occurrence because they have been grouped by categories.

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

ITEM 1A. RISK FACTORS As previously discussed, our actual results could differ materially from our forward-looking statements. Below we discuss some of the factors that could cause these differences. The occurrence of these and many other factors described in this report, and factors that we do not presently know or that we currently believe to be immaterial, could materially and adversely affect our operations, performance and financial condition. Many factors affect more than one category and the factors are not in order of significance or probability of occurrence because they have been grouped by categories. Disclosures in this section are based on our beliefs and opinions regarding factors that could materially and adversely affect us in the future and are not representations as to whether such factors have or have not occurred in the past.

de-emphasised Risks Related to the Operation of Our Business The current period significantly shortens the discussion of potential consequences, omitting detailed risks such as litigation and fines from security incidents, unsuccessful notification efforts to third parties, and customer systems suffering unrelated breaches. The disclosure ends abruptly after stating that the costs associated with mitigating vulnerabilities are significant.

FY 2025 10-K
Removed
Filed Jan 15, 2026

Our solutions collect, store, manage and otherwise process third-party data, including our customers' data and our own data. Such solutions as well as our technologies, systems and networks have been subject to, and may in the future be subject to, cyberattacks, computer viruses, ransomware or other malware, fraud, worms, social engineering, denial-of-service attacks, malicious software programs, insider threats and other cybersecurity incidents that have in the past, and may in the future, result in the unauthorized access, disclosure, acquisition, use, loss or destruction of sensitive personal or business data belonging to us, our employees and our customers. Some of our solutions include third-party open-source software, which may contain security vulnerabilities that may be exploited, potentially compromising our solutions. Increasing use of AI in our internal systems and solutions may create new attack methods. Cybersecurity incidents can be caused by human error from our workforce or that of our third-party service providers, by malicious third parties, acting alone or in groups, or by more sophisticated organizations, including nation-states and state-sponsored organizations. Such risks may be elevated in connection with geopolitical tensions, including the Russia-Ukraine war and the conflict in the Middle East, as well as malicious third parties utilizing emerging technologies, such as AI and machine learning. Certain unauthorized parties have in the past managed, and may in the future manage, to overcome our security measures and those of our third-party service providers to access and misuse systems and software by exploiting defects in design, configuration or manufacture, including bugs, vulnerabilities, change management errors and other problems that unexpectedly compromise the security or operation of a product or system. Further, unauthorized parties or authorized parties that exceed their authorized access may also gain physical access to our facilities and infiltrate our information systems or attempt to gain logical access to our solutions or information systems to access content and data and may result in computer viruses, worms, ransomware or other malware. Malicious third parties have in the past, and may in the future, fraudulently induce our employees or users of our solutions to disclose sensitive, personal or confidential information via illegal electronic spamming, phishing, social engineering or other tactics, and this risk is heightened in our current hybrid model working environment. Our solutions are incorporated into the supply chain of a large number of companies worldwide and, as a result, if our solutions experience a compromise, a large portion or, in some instances, all of our customers and their data for a given solution could be simultaneously affected. The potential liability and associated consequences we could suffer as a result of such a large scale event could be significant, and materially and adversely impact our business. Malicious actors may also engage in fraudulent or abusive activities through our solutions, including unauthorized use of accounts through stolen credentials, use of stolen credit cards or other payment vehicles, failure to pay for services accessed, or other activities that violate our terms of service. While we actively combat such fraudulent activities, we have experienced, and may in the future experience, impacts to our revenue and reputation from such activities. Maintaining the security of our solutions is a critical issue for us and our customers. We devote significant resources to address security vulnerabilities through various methods, including, but not limited to, engineering more secure products, enhancing security and reliability features in our products and systems, regularly reviewing our service providers' security controls, and continually assessing and improving, as appropriate, our incident response process. However, it is impossible to accurately predict the extent, frequency or impact cybersecurity issues may have on us, and our security measures do not provide full effective protection from all such events. There can be no assurance that we have the capability to detect all vulnerabilities or new attack methods and our internal security controls may not keep pace with quickly evolving threats. The costs to prevent, eliminate, mitigate or remediate cybersecurity or other security problems and vulnerabilities are significant and may reduce our margins. Breaches of our security measures and the accidental loss, inadvertent disclosure or unauthorized dissemination of proprietary information or sensitive, personal or confidential data about us, our employees, our customers or their end users, including the potential loss or disclosure of such information or data have in the past, and could in the future, expose us, our employees, our customers or other individuals affected to a risk of loss or misuse of this information. Further, our efforts to address these problems, including notifying affected third parties when appropriate, have in the past been, and may in the future be, unsuccessful or delayed, which could result in business interruptions, cessation of service, loss of existing or potential customers and reputational harm. Actual or perceived security vulnerabilities or incidents have resulted in, and may result in additional, claims or litigation and liability or fines, costly and time-intensive notice requirements, governmental inquiry or oversight or a loss of customer confidence, any of which have in the past and may in the future harm our business and damage our brand and reputation. Our customers may also adopt security measures to protect their computer systems and their instances of our software from attack and may suffer a cybersecurity breach on their own systems, unrelated to our 21

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

Our solutions collect, store, manage and otherwise process third-party data, including our customers' data and our own data. Such solutions as well as our technologies, systems and networks have been subject to, and may in the future be subject to, cyberattacks, computer viruses, ransomware or other malware, fraud, worms, social engineering, denial-of-service attacks, malicious software programs, insider threats and other cybersecurity incidents that have in the past, and may in the future, result in the unauthorized access, disclosure, acquisition, use, loss or destruction of sensitive personal or business data belonging to us, our employees and our customers. Some of our solutions include third-party open-source software, which may contain security vulnerabilities that may be exploited, potentially compromising our solutions. Increasing use of AI in our internal systems and solutions may create new attack methods. Cybersecurity incidents can be caused by human error from our workforce or that of our third-party service providers, by malicious third parties, acting alone or in groups, or by more sophisticated organizations, including nation-states and state-sponsored organizations. Such risks may be elevated in connection with geopolitical tensions, including the Russia-Ukraine war and the conflict in the Middle East, as well as malicious third parties utilizing emerging technologies, such as AI and machine learning. Certain unauthorized parties have in the past managed, and may in the future manage, to overcome our security measures and those of our third-party service providers to access and misuse systems and software by exploiting defects in design, configuration or manufacture, including bugs, vulnerabilities, change management errors and other problems that unexpectedly compromise the security or operation of a product or system. Further, unauthorized parties or authorized parties that exceed their authorized access may also gain physical access to our facilities and infiltrate our information systems or attempt to gain logical access to our solutions or information systems to access content and data and may result in computer viruses, worms, ransomware or other malware. Malicious third parties have in the past, and may in the future, fraudulently induce our employees or users of our solutions to disclose sensitive, personal or confidential information via illegal electronic spamming, phishing, social engineering or other tactics, and this risk is heightened in our current hybrid model working environment. Our solutions are incorporated into the supply chain of a large number of companies worldwide and, as a result, if our solutions experience a compromise, a large portion or, in some instances, all of our customers and their data for a given solution could be simultaneously affected. The potential liability and associated consequences we could suffer as a result of such a large scale event could be significant, and materially and adversely impact our business. Malicious actors may also engage in fraudulent or abusive activities through our solutions, including unauthorized use of accounts through stolen credentials, use of stolen credit cards or other payment vehicles, failure to pay for services accessed, or other activities that violate our terms of service. While we actively combat such fraudulent activities, we have experienced, and may in the future experience, impacts to our revenue and reputation from such activities. Maintaining the security of our solutions is a critical issue for us and our customers. We devote significant resources to address security vulnerabilities through various methods, including, but not limited to, engineering more secure products, enhancing security and reliability features in our products and systems, regularly reviewing our service providers' security controls, and continually assessing and improving, as appropriate, our incident response process. However, it is impossible to accurately predict the extent, frequency or impact cybersecurity issues may have on us, and our security measures do not provide full effective protection from all such events. There can be no assurance that we have the capability to detect all vulnerabilities or new attack methods and our internal security controls may not keep pace with quickly evolving threats. The costs to prevent, eliminate, mitigate or remediate cybersecurity or other security problems and vulnerabilities are significant and 40

reworded Risks Related to Our Ability to Grow Our Business The description of AI competition has expanded to include "AI-enabled workflows" that operate across third-party platforms or domain-specific solutions, and the risk related to third parties interfering with models is broadened to also cover competitors' ability to make, use, or sell their own AI solutions. Furthermore, the text now specifies that AI integration is transforming how digital work is performed or automated.

FY 2025 10-K
Removed
Filed Jan 15, 2026

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our business and financial results to suffer materially. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new and enhance existing solutions to retain customers and attract new customers. Developing new solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other solutions. If we fail to anticipate or identify technological, creative, productivity or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, artificial intelligence ("AI"), including generative and agentic, enables users of all skill levels to create and provide new ways of marketing, creating and editing content and interacting with documents. While we continue to release new AI solutions and to focus on enhancing the AI capabilities of our solutions and incorporating AI across existing solutions, there can be no assurance that our new or enhanced solutions and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our solutions. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be materially harmed. We participate in rapidly evolving and intensely competitive markets, and, if we do not compete effectively, our business and financial results could materially suffer. The markets for our solutions are rapidly evolving and intensely competitive. We expect competition to continue to intensify. Our numerous competitors include companies of various sizes and both public and private companies, including large, global companies and smaller companies with more specialized focuses, new entrants, and AI or cloud-native companies. Our competitors include companies with significant sales and research and development resources, broad brand awareness, long operating histories or access to large customer bases. Our competitors may deploy technical, marketing and financial resources more easily and effectively. Our competitors may develop or acquire additional products, services or solutions that are similar to ours or that achieve greater or faster acceptance. Our competitors may undertake faster and more far-reaching and successful development efforts or marketing campaigns, may adopt more aggressive pricing policies or may more effectively appeal to customers. As a result, current and potential customers may select the products, services or solutions of our competitors. New industry standards, evolving distribution and sales models, limited barriers to entry, short product life cycles, customer price sensitivity, global economic conditions and the frequent entry of new solutions or competitors may increase downward pressure on pricing and gross margins and adversely affect our renewal, upsell and cross-sell rates as well as our ability to attract new customers. In addition, we expect to face more competition as AI continues to advance and be integrated into the markets in which we compete and to change the software industry. Our competitors or other third parties may develop AI solutions more rapidly or successfully, including but not limited to different data training strategies or proprietary access to data and, as a result, other AI solutions may achieve greater and faster adoption. For example, we face increasing competition from companies offering generative and agentic AI solutions, including but not limited to prompt-based and multi-modal creation and editing, document productivity and understanding, ad distribution and creation, and purpose-built AI agents. Other companies have in the past, and may in the future prevent, limit or interfere with our ability to use third-party models in our solutions. If we are not able to provide solutions that compete effectively, we could experience reduced sales, which could materially and adversely impact our business and financial results. For additional information regarding our competition and the risks arising out of the competitive environment in which we operate, see the section titled "Competition" contained in Part I, Item 1 of this report.

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our business and financial results to suffer materially. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new and enhance existing solutions to retain customers and attract new customers. Developing new solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other solutions. If we fail to anticipate or identify technological, creative, productivity or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, artificial intelligence ("AI"), including generative and agentic, enables users of all skill levels to create and provide new ways of marketing, creating and editing content and interacting with documents. While we continue to release new AI solutions and to focus on enhancing the AI capabilities of our solutions and incorporating AI across existing solutions, there can be no assurance that our new or enhanced solutions and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our solutions. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be materially harmed. We participate in rapidly evolving and intensely competitive markets, and, if we do not compete effectively, our business and financial results could materially suffer. The markets for our solutions are rapidly evolving and intensely competitive. We expect competition to continue to intensify. Our numerous competitors include companies of various sizes and both public and private companies, including large, global companies and smaller companies with more specialized focuses, new entrants, and AI or cloud-native companies. Our competitors include companies with significant sales and research and development resources, broad brand awareness, long operating histories or access to large customer bases. Our competitors may deploy technical, marketing and financial resources more easily and effectively. Our competitors may develop or acquire additional products, services or solutions that are similar to ours or that achieve greater or faster acceptance. Our competitors may undertake faster and more far-reaching and successful development efforts or marketing campaigns, may adopt more aggressive or different pricing strategies or may more effectively appeal to customers. As a result, current and potential customers may select the products, services or solutions of our competitors. New industry standards, evolving distribution and sales models, limited barriers to entry, short product life cycles, customer price sensitivity, global economic conditions and the frequent entry of new solutions or competitors may increase downward pressure on pricing and gross margins and adversely affect our renewal, upsell and cross-sell rates as well as our ability to attract new customers. In addition, we expect to face more competition as AI continues to rapidly evolve and be integrated into the markets in which we compete, changing the software industry and transforming how digital work is performed or automated and how, and the extent to which, our solutions are accessed and used. Our competitors and other third parties may use AI, different data training strategies or proprietary access to data, among others, to develop competing solutions more rapidly or successfully, leading to greater and faster adoption. We face increasing competition from companies offering generative and agentic AI solutions, including but not limited to prompt-based and multi-modal creation and editing, document productivity and understanding, ad distribution and creation, and purpose-built AI agents and AI-enabled workflows, some of which are embedded within or operating across third-party AI platforms or domain-specific solutions. Other companies have in the past, and may in the future prevent, limit or interfere with our ability to use third-party models in our solutions or make, use or sell our own AI solutions. If we are not able to provide solutions that compete effectively, we could experience reduced sales, which could materially and adversely impact our business and financial results. For additional information regarding our competition and the risks arising out of the competitive environment in which we operate, see the section titled "Competition" contained in Part I, Item 1 of our Annual Report on Form 10-K.

reworded Our existing and future debt obligations may adversely affect our financial condition and future financial results. The disclosure remains substantively unchanged; the only modification is the reporting date, which updated from November 28, 2025, to February 27, 2026.

FY 2025 10-K
Removed
Filed Jan 15, 2026

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of November 28, 2025, we had $6.15 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of February 27, 2026, we had $6.15 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

reworded •other events, such as significant litigation, regulatory investigations or actions, and negative media or social media coverage. The description of adverse conditions was updated to replace "political or market" with "market or geopolitical," specifically adding the inclusion of armed conflicts and wars as examples of these risks.

FY 2025 10-K
Removed
Filed Jan 15, 2026

•adverse economic, political or market conditions; and 28 •other events, such as significant litigation, regulatory investigations or actions, and negative media or social media coverage. In addition, the market for technology stocks or the stock market in general has experienced, and may in the future experience, extreme fluctuations, which has caused, and may in the future cause, our stock price to decline for reasons unrelated to our financial performance. Volatility in our stock price has increased, and may continue to increase, our susceptibility to securities class action litigation, which could result in substantial costs and divert management's attention and resources, which may adversely affect our business.

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

•adverse economic, market or geopolitical conditions, including armed conflicts and wars; and •other events, such as significant litigation, regulatory investigations or actions, and negative media or social media coverage. In addition, the market for technology stocks or the stock market in general has experienced, and may in the future experience, extreme fluctuations, which has caused, and may in the future cause, our stock price to decline for reasons unrelated to our financial performance. Volatility in our stock price has increased, and may continue to increase, our susceptibility to securities class action litigation, which could result in substantial costs and divert management's attention and resources, which may adversely affect our business.

reworded Risks Related to the Operation of Our Business The cybersecurity risk disclosure was substantially expanded to specify that breaches could involve the accidental loss or unauthorized dissemination of proprietary, sensitive, personal, or confidential data; furthermore, the current period added risks related to potential claims, litigation, and fines stemming from security vulnerabilities, as well as the possibility of customers suffering separate cybersecurity breaches on their own systems.

FY 2025 10-K
Removed
Filed Jan 15, 2026

systems. Even if such breach is unrelated to our security systems, solutions or programs, such breach could cause us reputational harm and require us to incur significant economic and operational consequences to adequately assess and respond to their breach, and to implement additional safeguards designed to protect against future breaches. While we maintain insurance to cover operational risks, such as cybersecurity risk and technology outages, our insurance may not be sufficient to cover all liability described herein. These risks will likely increase as we expand our hosted solutions, integrate our solutions and store and process more data. Moreover, delayed sales, lower margins or lost customers resulting from disruptions caused by cyberattacks, data breaches, overly burdensome preventive security measures or failure to fully meet information security control certification requirements could materially and adversely affect our financial results, stock price and reputation. If we are unable to develop, manage and maintain our sales channels, including our direct sales force, third-party distributors, and sales partners, or third-party relationships upon which we rely for critical business operations, our revenue and business may be adversely affected. We rely on our direct sales channel and a number of third-party distributors and sales partners to distribute our solutions. The successful management of these relationships is a complex, global process. We sell many solutions through our direct sales force. Risks associated with this sales channel include challenges related to hiring, retaining and motivating our direct sales force, and substantial amounts of ongoing training for sales representatives. Our business could be harmed if our direct sales expansion efforts do not generate the corresponding efficiencies and revenue we anticipated from such investment. In addition, the loss of key sales employees could impact our customer relationships and future ability to sell to certain accounts covered by such employees. Moreover, if our partner and distribution channels are not effective or if we stop or change our partner or distribution channels, we may lose sales opportunities, customers and revenue. We rely on third-party distribution platforms and are subject to changes in pricing structure, terms of service, privacy practices and other policies at the discretion of the platform provider. Any adverse changes to the terms with such third-party distribution platforms which we rely on to distribute our solutions may adversely affect our financial results. Additionally, our distribution channels may not continue to market or sell our solutions effectively and may favor solutions of other companies. If an agreement with one of our distributors or partners was terminated, any prolonged delay in securing a replacement distributor or partner could have a negative impact on our results of operations. We also face legal risk and potential reputational harm from the activities of these independent third parties including, but not limited to, export control violations, workplace conditions, corruption and anti-competitive behavior. We also rely on third-party service providers and technologies to deliver our solutions and business operations and to operate critical business systems, such as cloud-based infrastructure, data center facilities, generative AI, large language models, encryption and authentication technology, company email and other communication channels, and communications with customers. If such third parties are negatively affected, if we fail to effectively develop, manage and maintain our relationships with such third parties, or if we are unable to renew our agreements with them on favorable terms or at all, our expenses could significantly increase, and we and our customers may experience service interruptions. Any disruption or damage to, or failure of our systems generally, including the systems of our third-party platform providers, could result in interruptions in our services and harm our business. Further, interruptions in our services caused by us or our third-party service providers may cause us to issue credits or pay penalties, cause customers to make warranty or other claims against us or to terminate their subscriptions or contracts, and adversely affect our attrition rates and our ability to attract new customers, all of which may adversely affect our financial results. Our business and reputation would also be harmed if our customers and potential customers believe our services are unreliable. We face various risks associated with operating as a multinational corporation, and global adverse economic and geopolitical conditions may harm our business and financial condition. We derive a large portion of our total revenue from, and have significant operations, outside of the United States. As a multinational corporation, we are subject to a number of risks, including from global adverse economic and geopolitical conditions, that are uncertain and beyond our control and that make forecasting financial results and decisions about future investments difficult, such as: •inflation and actions taken by central banks to counter inflation, including increasing interest rates; •international and regional economic, political and labor conditions, including any instability or security concerns abroad, such as uncertainty caused by economic sanctions, downturns and recessions, trade disputes, tariffs, armed conflicts and wars, and epidemics and pandemics like COVID-19; 22 •tax laws in the United States as well as other countries and jurisdictions; •increased financial accounting and reporting burdens and complexities; •changes in, or impositions of, legislative or regulatory requirements in the United States and other countries, including antitrust and competition regulations, consumer protection laws, or other government actions;

FY 2026 Q1 10-Q
Added
Filed Mar 25, 2026

may reduce our margins. Breaches of our security measures and the accidental loss, inadvertent disclosure or unauthorized dissemination of proprietary information or sensitive, personal or confidential data about us, our employees, our customers or their end users, including the potential loss or disclosure of such information or data have in the past, and could in the future, expose us, our employees, our customers or other individuals affected to a risk of loss or misuse of this information. Further, our efforts to address these problems, including notifying affected third parties when appropriate, have in the past been, and may in the future be, unsuccessful or delayed, which could result in business interruptions, cessation of service, loss of existing or potential customers and reputational harm. Actual or perceived security vulnerabilities or incidents have resulted in, and may result in additional, claims or litigation and liability or fines, costly and time-intensive notice requirements, governmental inquiry or oversight or a loss of customer confidence, any of which have in the past and may in the future harm our business and damage our brand and reputation. Our customers may also adopt security measures to protect their computer systems and their instances of our software from attack and may suffer a cybersecurity breach on their own systems, unrelated to our systems. Even if such breach is unrelated to our security systems, solutions or programs, such breach could cause us reputational harm and require us to incur significant economic and operational consequences to adequately assess and respond to their breach, and to implement additional safeguards designed to protect against future breaches. While we maintain insurance to cover operational risks, such as cybersecurity risk and technology outages, our insurance may not be sufficient to cover all liability described herein. These risks will likely increase as we expand our hosted solutions, integrate our solutions and store and process more data. Moreover, delayed sales, lower margins or lost customers resulting from disruptions caused by cyberattacks, data breaches, overly burdensome preventive security measures or failure to fully meet information security control certification requirements could materially and adversely affect our financial results, stock price and reputation. If we are unable to develop, manage and maintain our sales channels, including our direct sales force, third-party distributors, and sales partners, or third-party relationships upon which we rely for critical business operations, our revenue and business may be adversely affected. We rely on our direct sales channel and a number of third-party distributors and sales partners to distribute our solutions. The successful management of these relationships is a complex, global process. We sell many solutions through our direct sales force. Risks associated with this sales channel include challenges related to hiring, retaining and motivating our direct sales force, and substantial amounts of ongoing training for sales representatives. Our business could be harmed if our direct sales expansion efforts do not generate the corresponding efficiencies and revenue we anticipated from such investment. In addition, the loss of key sales employees could impact our customer relationships and future ability to sell to certain accounts covered by such employees. Moreover, if our partner and distribution channels are not effective or if we stop or change our partner or distribution channels, we may lose sales opportunities, customers and revenue. We rely on third-party distribution platforms and are subject to changes in pricing structure, terms of service, privacy practices and other policies at the discretion of the platform provider. Any adverse changes to the terms with such third-party distribution platforms which we rely on to distribute our solutions may adversely affect our financial results. Additionally, our distribution channels may not continue to market or sell our solutions effectively and may favor solutions of other companies. If an agreement with one of our distributors or partners was terminated, any prolonged delay in securing a replacement distributor or partner could have a negative impact on our results of operations. We also face legal risk and potential reputational harm from the activities of these independent third parties including, but not limited to, export control violations, workplace conditions, corruption and anti-competitive behavior. We also rely on third-party service providers and technologies to deliver our solutions and business operations and to operate critical business systems, such as cloud-based infrastructure, data center facilities, generative AI, large language models, encryption and authentication technology, company email and other communication channels, and communications with customers. If such third parties are negatively affected, if we fail to effectively develop, manage and maintain our relationships with such third parties, or if we are unable to renew our agreements with them on favorable terms or at all, our expenses could significantly increase, and we and our customers may experience service interruptions. Any disruption or damage to, or failure of our systems generally, including the systems of our third-party platform providers, could result in interruptions in our services and harm our business. Further, interruptions in our services caused by us or our third-party service providers may cause us to issue credits or pay penalties, cause customers to make warranty or other claims against us or to terminate their subscriptions or contracts, and adversely affect our attrition rates and our ability to attract new customers, all of which may adversely affect our financial results. Our business and reputation would also be harmed if our customers and potential customers believe our services are unreliable. 41

  FY2025 → FY2025 Text Diffs 

  FY2025 → FY2025 Text Diffs 

de-emphasised Risks Related to Our Ability to Grow Our Business The detailed section addressing jurisdictional risks related to AI regulation, such as the EU AI Act, has been removed from the current filing. This removal eliminates disclosures concerning increased compliance costs, heightened liability exposure, and inherent risks associated with relying on third-party AI models.

FY 2025 Q1 10-Q
Removed
Filed Mar 26, 2025

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our operating results to suffer. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new, and enhance existing, products, services and solutions to retain customers and attract new customers. Developing new products, services and solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced products, services and solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other products, services and solutions. If we fail to anticipate or identify technological, creative or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, generative artificial intelligence technologies enable users of all skill levels to create and provide new ways of marketing, creating content and interacting with documents, which could significantly disrupt industries in which we operate and our existing products, services and solutions and our business may be harmed if we fail to invest or adapt. While we have released new generative artificial intelligence products, such as Adobe Firefly, and are focused on enhancing the artificial intelligence ("AI") capabilities of our products and incorporating AI across existing products, services and solutions, there can be no assurance that our new or enhanced products and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our offerings. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be harmed. Issues relating to the development and use of AI, including generative AI, in our offerings may result in reputational harm, liability and adverse financial results. Social, ethical and operational issues relating to the use of AI, including generative AI, in our offerings may result in reputational harm, liability and additional costs. We are increasingly incorporating AI technologies, developed by us and by third parties, into many of our offerings. If our AI development, deployment, content labeling or governance is ineffective or inadequate, it may result in incidents that impair the public acceptance of AI solutions or cause harm to individuals, customers or society, or result in our offerings not working as intended or producing unexpected outcomes. Jurisdictions around the world are developing and passing new regulations that apply specifically to the use of AI. For example, the EU AI Act was adopted in 2024 and will be implemented in phases through 2030, and other jurisdictions are considering similarly focused legislation. These regulations and the evolving AI regulatory environment may, among other impacts, result in inconsistencies among AI regulations and frameworks across jurisdictions, increase our compliance, governance and research and development costs, increase our exposure to claims related to our AI models and increase liability related to the use of AI by our customers or users that are beyond our control. While we have taken a responsible approach to the development and use of AI, such as in our Adobe Firefly offerings, there can be no guarantee that future AI regulations will not adversely impact us or conflict with our approach to AI, including affecting our ability to make our AI offerings available without costly changes, delaying or halting development of AI offerings, requiring us to change our AI development practices, monetization strategies and/or indemnity protections and subjecting us to additional compliance requirements, regulatory action, competitive harm, reputational harm and/or legal liability. To the extent we rely on third-party AI models in our products, services and solutions, we will face risks inherent in how those models have been developed and deployed, including situations in which the third party may lack a proper license or consent for the training data used for their model. In addition,

FY 2025 Q2 10-Q
Added
Filed Jun 25, 2025

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our operating results to suffer. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new, and enhance existing, products, services and solutions to retain customers and attract new customers. Developing new products, services and solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced products, services and solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other products, services and solutions. If we fail to anticipate or identify technological, creative or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, generative and agentic artificial intelligence technologies enable users of all skill levels to create and provide new ways of marketing, creating content and interacting with documents, which could significantly disrupt industries in which we operate and our existing products, services and solutions and our business may be harmed if we fail to invest or adapt. While we have released new generative artificial intelligence products, such as Adobe Firefly, and are focused on enhancing the artificial intelligence ("AI") capabilities of our products and incorporating AI across existing products, services and solutions, there can be no assurance that our new or enhanced products and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our offerings. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be harmed.

reworded •operating in locations with a higher rate of corruption and fraudulent business practices. The investment portfolio description was updated, reflecting a change in date from February 28, 2025, to May 30, 2025, and specifically removing references to U.S. agency securities and asset-backed securities.

FY 2025 Q1 10-Q
Removed
Filed Mar 26, 2025

•costs and delays associated with developing products in multiple languages; and •operating in locations with a higher rate of corruption and fraudulent business practices. Additionally, third parties we do business with and our customers have international operations and are also subject to the above risks. Adverse changes in global economic conditions have in the past resulted and may in the future result in our customers' and business partners' insolvency, inability to obtain credit to finance or purchase our products, services and solutions, or a delay in paying or an inability to pay their obligations to us. Other third parties, such as our service providers, suppliers and distributors, may be unable to deliver or be delayed in delivering critical services, products or technologies that we rely on, and our business and reputation may be harmed. Our customers' spending rate and demand for our products, services and solutions may also be adversely affected by the above risks. If our global sales are reduced, delayed or canceled because of any of the above risks, our revenue may decline. Further, a disruption in global financial markets could impair our banking partners, on which we rely for operating cash management, capital market transactions and derivative programs. Such disruption could also negatively impact our customers' ability to pay us due to delays or inability to access their existing cash. As of February 28, 2025, our investment portfolio consisted of money market funds, corporate debt securities, U.S. Treasury securities, time deposits, U.S. agency securities and asset-backed securities. These investments are subject to credit, liquidity, market, and interest rate risks as well as economic downturns or events that affect global or regional financial markets that may cause the value of our investments to decline, requiring impairment charges, which could adversely affect our financial condition.

FY 2025 Q2 10-Q
Added
Filed Jun 25, 2025

•costs and delays associated with developing products in multiple languages; and •operating in locations with a higher rate of corruption and fraudulent business practices. Additionally, third parties we do business with and our customers have international operations and are also subject to the above risks. Adverse changes in global economic conditions have in the past resulted and may in the future result in our customers' and business partners' insolvency, inability to obtain credit to finance or purchase our products, services and solutions, or a delay in paying or an inability to pay their obligations to us. Other third parties, such as our service providers, suppliers and distributors, may be unable to deliver or be delayed in delivering critical services, products or technologies that we rely on, and our business and reputation may be harmed. Our customers' spending rate and demand for our products, services and solutions may also be adversely affected by the above risks. If our global sales are reduced, delayed or canceled because of any of the above risks, our revenue may decline. Further, a disruption in global financial markets could impair our banking partners, on which we rely for operating cash management, capital market transactions and derivative programs. Such disruption could also negatively impact our customers' ability to pay us due to delays or inability to access their existing cash. As of May 30, 2025, our investment portfolio primarily consisted of money market funds, corporate debt securities, U.S. Treasury securities and time deposits. These investments are subject to credit, liquidity, market, and interest rate risks as well as economic downturns or events that affect global or regional financial markets that may cause the value of our investments to decline, requiring impairment charges, which could adversely affect our financial condition.

  FY2024 → FY2025 Text Diffs 

escalated new competition regulations on AI development and deployment could impose new requirements on our markets that could impact our business and financial results. The disclosure was significantly expanded to include new risks related to competition regulations on AI development and deployment, as well as challenges accessing necessary AI models, datasets, or hardware. Furthermore, the current period details that evolving AI uses may require significant additional investment for responsible-use frameworks and mechanisms to compensate content creators.

FY 2024 10-K
Removed
Filed Jan 13, 2025

involved in such systems. These costs could adversely impact our margins as we continue to make significant investments in AI development, add AI capabilities to our offerings and scale our AI offerings without assurance that our customers and users will adopt them. Further, as with any new offerings based on new technologies, consumer reception and monetization pathways are uncertain, our strategies may not be successful and our business and financial results could be adversely impacted. New AI offerings and technologies could modify workforce needs, result in negative publicity about AI and decrease demand for our existing products, services and solutions, all of which could adversely impact our business.

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

new competition regulations on AI development and deployment could impose new requirements on our markets that could impact our business and financial results. Uncertainty around new and evolving AI uses may require significant, additional investment to develop models and proprietary datasets, responsible-use frameworks and new approaches and processes to attribute or compensate content creators. We have experienced, and may in the future experience, challenges accessing AI models, datasets or hardware. Developing, testing and deploying AI systems may also increase the cost of our offerings, including due to the nature of the computing costs involved in such systems. These costs could adversely impact our margins as we continue to make significant investments in AI development, add AI capabilities to our offerings and scale our AI offerings without assurance that our customers and users will adopt them. Further, as with any new offerings based on new technologies, consumer reception and monetization pathways are uncertain, our strategies may not be successful and our business and financial results could be adversely impacted. New AI offerings and technologies could modify workforce needs, result in negative publicity about AI and decrease demand for our existing products, services and solutions, all of which could adversely impact our business.

reworded Risks Related to Our Ability to Grow Our Business The current filing removes a significant section of risk disclosure, specifically eliminating details regarding the need for substantial additional investment in models and proprietary datasets, challenges accessing AI models or hardware, and increased costs related to developing and deploying AI systems.

FY 2024 10-K
Removed
Filed Jan 13, 2025

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our operating results to suffer. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new, and enhance existing, products, services and solutions to retain customers and attract new customers. Developing new products, services and solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced products, services and solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other products, services and solutions. If we fail to anticipate or identify technological, creative or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, generative artificial intelligence technologies enable users of all skill levels to create and provide new ways of marketing, creating content and interacting with documents, which could significantly disrupt industries in which we operate and our existing products, services and solutions and our business may be harmed if we fail to invest or adapt. While we have released new generative artificial intelligence products, such as Adobe Firefly, and are focused on enhancing the artificial intelligence ("AI") capabilities of our products and incorporating AI across existing products, services and solutions, there can be no assurance that our new or enhanced products and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our offerings. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be harmed. Issues relating to the development and use of AI, including generative AI, in our offerings may result in reputational harm, liability and adverse financial results. Social, ethical and operational issues relating to the use of AI, including generative AI, in our offerings may result in reputational harm, liability and additional costs. We are increasingly incorporating AI technologies, developed by us and by third parties, into many of our offerings. If our AI development, deployment, content labeling or governance is ineffective or inadequate, it may result in incidents that impair the public acceptance of AI solutions or cause harm to individuals, customers or society, or result in our offerings not working as intended or producing unexpected outcomes. Jurisdictions around the world are developing and passing new regulations that apply specifically to the use of AI. For example, the EU AI Act was adopted in 2024 and will be implemented in phases through 2030, and other jurisdictions are considering similarly focused legislation. These regulations and the evolving AI regulatory environment may, among other impacts, result in inconsistencies among AI regulations and frameworks across jurisdictions, increase our compliance, governance and research and development costs, increase our exposure to claims related to our AI models and increase liability related to the use of AI by our customers or users that are beyond our control. While we have taken a responsible approach to the development and use of AI, such as in our Adobe Firefly offerings, there can be no guarantee that future AI regulations will not adversely impact us or conflict with our approach to AI, including affecting our ability to make our AI offerings available without costly changes, delaying or halting development of AI offerings, requiring us to change our AI development practices, monetization strategies and/or indemnity protections and subjecting us to additional compliance requirements, regulatory action, competitive harm, reputational harm and/or legal liability. To the extent we rely on third-party AI models in our products, services and solutions, we will face risks inherent in how those models have been developed and deployed, including situations in which the third party may lack a proper license or consent for the training data used for their model. In addition, new competition regulations on AI development and deployment could impose new requirements on our markets that could impact our business and financial results. Uncertainty around new and evolving AI uses may require significant, additional investment to develop models and proprietary datasets, responsible-use frameworks and new approaches and processes to attribute or compensate content creators. We have experienced, and may in the future experience, challenges accessing AI models, datasets or hardware. Developing, testing and deploying AI systems may also increase the cost of our offerings, including due to the nature of the computing costs

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

Risks Related to Our Ability to Grow Our Business We may be unsuccessful at innovating in response to rapid technological or industry changes to meet customer needs, which could cause our operating results to suffer. We operate in rapidly evolving industries and expect the pace of innovation to continue to accelerate. We must continually introduce new, and enhance existing, products, services and solutions to retain customers and attract new customers. Developing new products, services and solutions is complex, requires significant investment and operational costs and may not be profitable, and our investments in new technologies are speculative and may not yield the expected business or financial benefits. The commercial success of new or enhanced products, services and solutions depends on a number of factors, including timely and successful development; effective distribution and marketing; market acceptance; compatibility with existing and emerging standards, platforms, software delivery methods and technologies; accurately predicting and anticipating customer needs and expectations and the direction of technological change; identifying and innovating in the right technologies; and differentiation from other products, services and solutions. If we fail to anticipate or identify technological, creative or marketing trends or fail to devote appropriate resources to adapt to such trends, our business could be harmed. For example, generative artificial intelligence technologies enable users of all skill levels to create and provide new ways of marketing, creating content and interacting with documents, which could significantly disrupt industries in which we operate and our existing products, services and solutions and our business may be harmed if we fail to invest or adapt. While we have released new generative artificial intelligence products, such as Adobe Firefly, and are focused on enhancing the artificial intelligence ("AI") capabilities of our products and incorporating AI across existing products, services and solutions, there can be no assurance that our new or enhanced products and AI innovations will be successful, adopted or monetizable or that we will innovate effectively to keep pace with the rapid evolution of AI across our offerings. If we do not successfully innovate, adapt to rapid technological or industry changes and meet customer needs, our business and our financial results may be harmed. Issues relating to the development and use of AI, including generative AI, in our offerings may result in reputational harm, liability and adverse financial results. Social, ethical and operational issues relating to the use of AI, including generative AI, in our offerings may result in reputational harm, liability and additional costs. We are increasingly incorporating AI technologies, developed by us and by third parties, into many of our offerings. If our AI development, deployment, content labeling or governance is ineffective or inadequate, it may result in incidents that impair the public acceptance of AI solutions or cause harm to individuals, customers or society, or result in our offerings not working as intended or producing unexpected outcomes. Jurisdictions around the world are developing and passing new regulations that apply specifically to the use of AI. For example, the EU AI Act was adopted in 2024 and will be implemented in phases through 2030, and other jurisdictions are considering similarly focused legislation. These regulations and the evolving AI regulatory environment may, among other impacts, result in inconsistencies among AI regulations and frameworks across jurisdictions, increase our compliance, governance and research and development costs, increase our exposure to claims related to our AI models and increase liability related to the use of AI by our customers or users that are beyond our control. While we have taken a responsible approach to the development and use of AI, such as in our Adobe Firefly offerings, there can be no guarantee that future AI regulations will not adversely impact us or conflict with our approach to AI, including affecting our ability to make our AI offerings available without costly changes, delaying or halting development of AI offerings, requiring us to change our AI development practices, monetization strategies and/or indemnity protections and subjecting us to additional compliance requirements, regulatory action, competitive harm, reputational harm and/or legal liability. To the extent we rely on third-party AI models in our products, services and solutions, we will face risks inherent in how those models have been developed and deployed, including situations in which the third party may lack a proper license or consent for the training data used for their model. In addition,

reworded We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. The percentage of employees located outside the United States increased from approximately 50% to 51%. Additionally, the scope of subjects covered by laws and regulations was expanded to include "government actions."

FY 2024 10-K
Removed
Filed Jan 13, 2025

We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. We are a global company subject to varied and complex laws, regulations and customs, both domestically and internationally. These local, state, federal and international laws and regulations relate to a number of aspects of our business, including trade laws such as import and export controls, anti-boycott, economic sanctions and embargoes, data and transaction processing security, payment card industry data security standards, consumer protection, records management, user-generated content hosted on websites we operate, privacy practices, data residency, AI regulations, corporate governance, antitrust and competition, employee and third-party complaints, anti-corruption, conflicts of interest, securities regulations and other regulatory requirements affecting trade and investment. The application of these laws and regulations to our business is often unclear and evolving, and may at times conflict. Further, we are subject to the U.S. Foreign Corrupt Practices Act and other anti-corruption and anti-bribery laws, which may conflict with local customs and practices in other foreign countries, particularly those with developing economies where it is common to engage in practices that would be prohibited under such laws. We cannot provide assurance that our employees, contractors, agents, business partners and vendors will not take actions in violation of our internal policies, U.S. laws or other applicable international laws. Compliance with the above laws and regulations may involve significant costs or require additional changes to our business practices that result in reduced revenue and profitability. Non-compliance could also result in fines, damages, criminal sanctions against us, our officers or our employees, prohibitions on the conduct of our business and damage to our reputation. In addition, approximately 50% of our employees are located outside the United States. Accordingly, we are exposed to changes in laws governing our employee relationships in various U.S. and foreign jurisdictions, including laws and regulations regarding wage and hour requirements, fair labor standards, employee data privacy, unemployment tax rates, workers' compensation rates, citizenship requirements and payroll and other taxes, which likely would have a direct impact on our operating costs. Increasing regulatory focus on privacy and security issues and expanding laws and regulatory requirements could impact our business models and expose us to increased liability. We are subject to global data protection, privacy and security laws, regulations and codes of conduct that relate to our various business units and data processing activities, which may include sensitive, confidential, and personal information. These laws, regulations and codes are inconsistent across jurisdictions and are subject to evolving and differing (sometimes conflicting) interpretations. Government officials and regulators, privacy advocates and class action attorneys are increasingly scrutinizing how companies collect, process, use, store, share and transmit personal data, including the transferring of personal information across international borders. This scrutiny can result in new and shifting interpretations of existing laws, thereby further impacting our business. For example, European data transfers outside the European Economic Area are highly regulated and litigated. The mechanisms that we and many other companies rely upon for European data transfers (for example, Standard Contractual Clauses and the EU - US Data Privacy Framework) are the subject of legal challenge, regulatory interpretation and judicial decisions by the Court of Justice of the European Union. Several other countries, including but not limited to the United States, China, Australia, New Zealand, Brazil, Kingdom of Saudi Arabia, Hong Kong and Japan, have also established specific legal requirements for cross-border transfers of personal information and certain countries have also established specific legal requirements for data localization (such as where personal data must remain stored in the country). If other countries implement more restrictive regulations for cross-border data transfers or do not permit data to leave the country of origin, such developments could adversely impact our business and our enterprise customers' business, our financial condition and our results of operations in those jurisdictions. Additionally, the General Data Protection Regulation in the European Economic Area and the United Kingdom continues to be interpreted by European and UK courts in novel ways leading to shifting requirements, country-specific differences in application and uncertain enforcement priorities. Laws in Asia, such as the Personal Information Protection Law in China and developing laws in India, as well as state laws in the United States on privacy, data and related technologies, such as the California Consumer Privacy Act, the California Privacy Rights Act, the Colorado Privacy Act and the Virginia Consumer Data Protection Act, as well as industry self-regulatory codes and regulatory requirements, create additional privacy and security compliance obligations and expand the scope of potential liability, either jointly or severally with our customers and suppliers. Further, the U.S. Securities and Exchange Commission's Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure requires us to make certain disclosures related 30

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. We are a global company subject to varied and complex laws, regulations, government actions and customs, both domestically and internationally. These local, state, federal and international laws and regulations relate to a number of aspects of our business, including trade laws such as import and export controls, anti-boycott, economic sanctions and embargoes, data and transaction processing security, payment card industry data security standards, consumer protection, records management, user-generated content hosted on websites we operate, privacy practices, data residency, AI regulations, corporate governance, antitrust and competition, employee and third-party complaints, anti-corruption, conflicts of interest, securities regulations and other regulatory requirements affecting trade and investment. The application of these laws and regulations to our business is often unclear and evolving, and may at times conflict. Further, we are subject to the U.S. Foreign Corrupt Practices Act and other anti-corruption and anti-bribery laws, which may conflict with local customs and practices in other foreign countries, particularly those with developing economies where it is common to engage in practices that would be prohibited under such laws. We cannot provide assurance that our employees, contractors, agents, business partners and vendors will not take actions in violation of our internal policies, U.S. laws or other applicable international laws. Compliance with the above laws and regulations may involve significant costs or require additional changes to our business practices that result in reduced revenue and profitability. Non-compliance could also result in fines, damages, criminal sanctions against us, our officers or our employees, prohibitions on the conduct of our business and damage to our reputation. In addition, approximately 51% of our employees are located outside the United States. Accordingly, we are exposed to changes in laws governing our employee relationships in various U.S. and foreign jurisdictions, including laws and regulations regarding wage and hour requirements, fair labor standards, employee data privacy, unemployment tax rates, workers' compensation rates, citizenship requirements and payroll and other taxes, which likely would have a direct impact on our operating costs. Increasing regulatory focus on privacy and security issues and expanding laws and regulatory requirements could impact our business models and expose us to increased liability. We are subject to global data protection, privacy and security laws, regulations and codes of conduct that relate to our various business units and data processing activities, which may include sensitive, confidential, and personal information. These laws, regulations and codes are inconsistent across jurisdictions and are subject to evolving and differing (sometimes conflicting) interpretations. Government officials and regulators, privacy advocates and class action attorneys are increasingly scrutinizing how companies collect, process, use, store, share and transmit personal data, including the transferring of personal information across international borders. This scrutiny can result in new and shifting interpretations of existing laws, thereby further impacting our business. For example, European data transfers outside the European Economic Area are highly regulated and litigated. The mechanisms that we and many other companies rely upon for European data transfers (for example, Standard Contractual Clauses and the EU - US Data Privacy Framework) are the subject of legal challenge, regulatory interpretation and judicial decisions by the Court of Justice of the European Union. Several other countries, including but not limited to the United States, China, Australia, New Zealand, Brazil, Kingdom of Saudi Arabia, Hong Kong and Japan, have also established specific legal requirements for cross-border transfers of personal information and certain countries have also established specific legal requirements for data localization (such as where personal data must remain stored in the country). If other countries implement more restrictive regulations for cross-border data transfers or do not permit data to leave the country of origin, such developments could adversely impact our business and our enterprise customers' business, our financial condition and our results of operations in those jurisdictions. Additionally, the General Data Protection Regulation in the European Economic Area and the United Kingdom continues to be interpreted by European and UK courts in novel ways leading to shifting requirements, country-specific differences in application and uncertain enforcement priorities. Laws in Asia, such as the Personal Information Protection Law in China and developing laws in India, as well as state laws in the United States on privacy, data and related technologies, such as the California Consumer Privacy Act, the California Privacy Rights Act, the Colorado Privacy Act and the Virginia Consumer Data Protection Act, as well as industry self-regulatory codes and regulatory 44

reworded We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. The current filing explicitly names the U.S. Securities and Exchange Commission's Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure as the requirement driving material cybersecurity incident disclosures. Additionally, the text was updated to mention that compliance obligations may expand the scope of potential liability, which could be shared jointly or severally with customers and suppliers.

FY 2024 10-K
Removed
Filed Jan 13, 2025

to material cybersecurity incidents and the reasonably likely impact of such an incident on Form 8-K. Determining whether a cybersecurity incident is notifiable or reportable may not be straightforward and any such mandatory disclosures could be costly and lead to negative publicity, loss of customer confidence in the effectiveness of our security measures, diversion of management's attention and governmental investigations. While we have invested in readiness to comply with applicable requirements, the dynamic and evolving nature of these laws, regulations and codes, as well as their interpretation by regulators and courts, may affect our ability (and our enterprise customers' ability) to reach current and prospective customers, to respond to both enterprise and individual customer requests under the laws (such as individual rights of access, correction and deletion of their personal information), to implement our business models effectively and to adequately address disclosure requirements. These laws, regulations and codes may also impact our innovation and business drivers in developing new and emerging technologies (for example, AI and machine learning) and may impact demand for our offerings and force us to bear the burden of more onerous obligations in our contracts. Perception of our practices, products, services or solutions, even if unfounded, as a violation of individual privacy, data protection rights or cybersecurity requirements, subjects us to public criticism, lawsuits, investigations, claims and other proceedings by regulators, industry groups or other third parties, all of which could disrupt or adversely impact our business and reputation and expose us to increased liability, fines and other punitive measures including prohibition on sales of our products, services or solutions, restrictive judicial orders and disgorgement of data. Additionally, we collect and store information on behalf of our business customers and if our customers fail to comply with contractual obligations or applicable laws, it could result in litigation or reputational harm to us. Our intellectual property portfolio is a valuable asset and we may not be able to protect our intellectual property rights, including our source code, from infringement or unauthorized copying, use or disclosure. Our patents, trademarks, trade secrets, copyrights and other intellectual property are valuable assets to us. Infringement or misappropriation of such intellectual property could result in lost revenues and ultimately reduce their value. We protect our intellectual property by relying on federal, state and common law rights in the United States and internationally, as well as a variety of administrative procedures and contractual restrictions. Despite our efforts, protecting our intellectual property rights and preventing unauthorized use of our intellectual property are inherently difficult. For instance, we actively combat software piracy, but we continue to lose revenue due to illegal use of our software. Third parties may illegally copy and sell counterfeit versions of our products. To the extent counterfeit installations and sales replace otherwise legitimate ones, our operating results could be adversely affected. We apply for patents in the United States and in foreign countries, but we are not always successful in obtaining patent protection or in obtaining such protection timely to meet our business needs. Our patents may be invalidated or circumvented. Moreover, due to challenges in detecting patent infringement pertaining to generative AI technologies, it may be more difficult to protect our generative AI and related innovations with patents. Additionally, if we use generative AI in the creation of our source code, we may not be able to rely on copyright to protect such intellectual property. Further, the laws of some foreign countries do not provide the same level of intellectual property protection as U.S. laws and courts and could fail to adequately protect our intellectual property rights. If unauthorized disclosure of our source code occurs through security breach, cyber-attack or otherwise, we could lose future trade secret protection for that source code. Such loss could make it easier for third parties to compete with our products by copying functionality, which could cause us to lose customers and could adversely affect our revenue and operating margins. If we cannot protect our intellectual property against unauthorized copying, use, or other misappropriation, our business could be harmed.

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

requirements, create additional privacy and security compliance obligations and expand the scope of potential liability, either jointly or severally with our customers and suppliers. Further, the U.S. Securities and Exchange Commission's Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure requires us to make certain disclosures related to material cybersecurity incidents and the reasonably likely impact of such an incident on Form 8-K. Determining whether a cybersecurity incident is notifiable or reportable may not be straightforward and any such mandatory disclosures could be costly and lead to negative publicity, loss of customer confidence in the effectiveness of our security measures, diversion of management's attention and governmental investigations. While we have invested in readiness to comply with applicable requirements, the dynamic and evolving nature of these laws, regulations and codes, as well as their interpretation by regulators and courts, may affect our ability (and our enterprise customers' ability) to reach current and prospective customers, to respond to both enterprise and individual customer requests under the laws (such as individual rights of access, correction and deletion of their personal information), to implement our business models effectively and to adequately address disclosure requirements. These laws, regulations and codes may also impact our innovation and business drivers in developing new and emerging technologies (for example, AI and machine learning) and may impact demand for our offerings and force us to bear the burden of more onerous obligations in our contracts. Perception of our practices, products, services or solutions, even if unfounded, as a violation of individual privacy, data protection rights or cybersecurity requirements, subjects us to public criticism, lawsuits, investigations, claims and other proceedings by regulators, industry groups or other third parties, all of which could disrupt or adversely impact our business and reputation and expose us to increased liability, fines and other punitive measures including prohibition on sales of our products, services or solutions, restrictive judicial orders and disgorgement of data. Additionally, we collect and store information on behalf of our business customers and if our customers fail to comply with contractual obligations or applicable laws, it could result in litigation or reputational harm to us. Our intellectual property portfolio is a valuable asset and we may not be able to protect our intellectual property rights, including our source code, from infringement or unauthorized copying, use or disclosure. Our patents, trademarks, trade secrets, copyrights and other intellectual property are valuable assets to us. Infringement or misappropriation of such intellectual property could result in lost revenues and ultimately reduce their value. We protect our intellectual property by relying on federal, state and common law rights in the United States and internationally, as well as a variety of administrative procedures and contractual restrictions. Despite our efforts, protecting our intellectual property rights and preventing unauthorized use of our intellectual property are inherently difficult. For instance, we actively combat software piracy, but we continue to lose revenue due to illegal use of our software. Third parties may illegally copy and sell counterfeit versions of our products. To the extent counterfeit installations and sales replace otherwise legitimate ones, our operating results could be adversely affected. We apply for patents in the United States and in foreign countries, but we are not always successful in obtaining patent protection or in obtaining such protection timely to meet our business needs. Our patents may be invalidated or circumvented. Moreover, due to challenges in detecting patent infringement pertaining to generative AI technologies, it may be more difficult to protect our generative AI and related innovations with patents. Additionally, if we use generative AI in the creation of our source code, we may not be able to rely on copyright to protect such intellectual property. Further, the laws of some foreign countries do not provide the same level of intellectual property protection as U.S. laws and courts and could fail to adequately protect our intellectual property rights. If unauthorized disclosure of our source code occurs through security breach, cyber-attack or otherwise, we could lose future trade secret protection for that source code. Such loss could make it easier for third parties to compete with our products by copying functionality, which could cause us to lose customers and could adversely affect our revenue and operating margins. If we cannot protect our intellectual property against unauthorized copying, use, or other misappropriation, our business could be harmed.

reworded Contracting with government entities exposes us to additional risks inherent in the government procurement process. The disclosure expands on regulatory risks by specifying that the company is subject to complex requirements and executive orders covering areas such as procurement, export controls, employment, and security; it also adds "changes in governmental administrations and policies" to the list of inherent challenges.

FY 2024 10-K
Removed
Filed Jan 13, 2025

Contracting with government entities exposes us to additional risks inherent in the government procurement process. We provide products, services and solutions, directly and indirectly, to a variety of domestic and foreign government entities, which introduces certain risks and challenges not present in private commercial agreements, including varying governmental budgeting processes, fluctuations due to government spending cuts and shutdowns, highly competitive and lengthy bidding process that may be subject to political influence and adherence to complex procurement regulations and other government-specific contractual requirements. We incur significant up-front time and costs without any assurance that we will win a contract. Operating within a highly regulated industry, we have been and may in the future be subject to audits and investigations relating to our government contracts and any violations could result in termination of contracts and various civil and criminal penalties and administrative sanctions, including payment of fines and suspension or debarment from future government business, as well as harm to our reputation and financial results. We have made, and may continue to make, significant investments to support future sales opportunities in various government sectors, including to obtain various security authorizations and certifications. Such processes are complex, lengthy and can often be delayed. Furthermore, requirements may change, or we may be unable to achieve or sustain one or more government authorizations or certifications, which could affect our ability to sell to government entities until we meet any new or revised requirements.

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

Contracting with government entities exposes us to additional risks inherent in the government procurement process. We provide products, services and solutions, directly and indirectly, to a variety of domestic and foreign government entities, which introduces certain risks and challenges not present in private commercial agreements, including varying governmental budgeting processes; changes in governmental administrations and policies; fluctuations due to government spending cuts and shutdowns; and highly competitive and lengthy bidding process that may be subject to political influence. Additionally, we are subject to complex regulatory requirements and executive orders, including those related to procurement; export controls; employment; security; and other evolving government-specific contractual requirements. We incur significant up-front time and costs without any assurance that we will win a contract. Operating within a highly regulated industry, we have been and may in the future be subject to audits and investigations relating to our government contracts and any violations could result in termination of contracts and various civil and criminal penalties and administrative sanctions, including payment of fines and suspension or debarment from future government business, as well as harm to our reputation and financial results. We have made, and may continue to make, significant investments to support future sales opportunities in various government sectors, including to obtain various security authorizations and certifications. Such processes are complex, lengthy and can often be delayed. Furthermore, requirements may change, or we may be unable to achieve or sustain one or more government authorizations or certifications, which could affect our ability to sell to government entities until we meet any new or revised requirements.

reworded Our existing and future debt obligations may adversely affect our financial condition and future financial results.

FY 2024 10-K
Removed
Filed Jan 13, 2025

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of November 29, 2024, we had $5.65 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of February 28, 2025, we had $6.15 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

reworded General Risk Factors The disclosure regarding ESG risks was significantly expanded to specify that failure to meet commitments may expose the company not only to reputational harm but also to legal proceedings, enforcement actions, and stakeholder actions due to the rapidly evolving regulatory landscape.

FY 2024 10-K
Removed
Filed Jan 13, 2025

General Risk Factors Catastrophic events, including events associated with climate change, may disrupt our business and adversely affect our financial condition and results of operations. Our business relies on our network infrastructure and enterprise Apps, internal technology systems and websites. A disruption, infiltration or failure of our systems, data centers or operations, or those of our third-party service providers due to a major earthquake, other natural disasters, including climate-related events (such as drought, water security, heat waves, cold waves, wildfires and poor air quality), power shutoff or loss, telecommunications failure, epidemic, pandemic, war, terrorist attack or other catastrophic event, could cause interruptions to our systems and business operations, damage to critical infrastructure, loss of intellectual property, data security breaches and data loss. Our corporate headquarters, significant research and development activity, certain of our data centers and other critical business operations are in the San Francisco Bay Area and the Salt Lake Valley Area, both of which are near major earthquake faults. Climate-related catastrophic events that may harm our business are also increasing in frequency and severity. A catastrophic event, particularly one that may disrupt our data centers or our critical activities, could prevent us from conducting normal business operations and providing our products, services and solutions, which could adversely affect our business. A catastrophic event could negatively impact a country or region in which we sell and, in turn, decrease demand for our products, services and solutions, which could negatively impact our business. Laws, regulations and policies relating to environmental, social, and governance are expanding globally. We may be subject to additional climate-related regulations and reporting requirements in the future, as well as changing market dynamics and stakeholder expectations regarding climate change and our environmental impacts. Compliance with such regulations, investments in our environmental, social and governance commitments, may involve significant costs and negatively impact our business, financial condition and results of operations. Additionally, we may experience reputational harm from our actual or perceived failure to meet our environmental, social and governance commitments. 33 The occurrence of an epidemic or a pandemic, such as the COVID-19 pandemic, has had, and may in the future, have an adverse effect on our operating results. The extent to which epidemics and pandemics impact our financial condition or results of operations will depend on many factors outside of our control and whether there is a material impact on the businesses or productivity of our customers, employees, suppliers and other partners. A global pandemic may also intensify the other risks described in this Part I, Item 1A of this report.

FY 2025 Q1 10-Q
Added
Filed Mar 26, 2025

General Risk Factors Catastrophic events, including events associated with climate change, may disrupt our business and adversely affect our financial condition and results of operations. Our business relies on our network infrastructure and enterprise Apps, internal technology systems and websites. A disruption, infiltration or failure of our systems, data centers or operations, or those of our third-party service providers due to a major earthquake, other natural disasters, including climate-related events (such as drought, water security, heat waves, cold waves, wildfires and poor air quality), power shutoff or loss, telecommunications failure, epidemic, pandemic, war, terrorist attack or other catastrophic event, could cause interruptions to our systems and business operations, damage to critical infrastructure, loss of intellectual property, data security breaches and data loss. Our corporate headquarters, significant research and development activity, certain of our data centers and other critical business operations are in the San Francisco Bay Area and the Salt Lake Valley Area, both of which are near major earthquake faults. Climate-related catastrophic events that may harm our business are also increasing in frequency and severity. A catastrophic event, particularly one that may disrupt our data centers or our critical activities, could prevent us from conducting normal business operations and providing our products, services and solutions, which could adversely affect our business. A catastrophic event could negatively impact a country or region in which we sell and, in turn, decrease demand for our products, services and solutions, which could negatively impact our business. 47 Laws, regulations, executive orders and policies relating to environmental, social, and governance ("ESG") matters are expanding globally. We may be subject to additional climate-related regulations and reporting requirements in the future, as well as changing market dynamics and stakeholder expectations regarding climate change and our environmental impacts. Compliance with such regulations and investments in our ESG commitments may involve significant costs and negatively impact our business, financial condition and results of operations. Additionally, we may be subject to legal proceedings, enforcement actions, stakeholder actions or reputational harm related to our ESG commitments, programs and actions, or from our actual or perceived failure to meet such ESG commitments that could be caused by a variety of factors beyond our control, such as the rapidly evolving regulatory landscape for ESG. The occurrence of an epidemic or a pandemic, such as the COVID-19 pandemic, has had, and may in the future have, an adverse effect on our operating results. The extent to which epidemics and pandemics impact our financial condition or results of operations will depend on many factors outside of our control and whether there is a material impact on the businesses or productivity of our customers, employees, suppliers and other partners. A global pandemic may also intensify the other risks described in this Part II, Item 1A of this report.

  FY2023 → FY2024 Text Diffs 

escalated We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. The intellectual property risk disclosure was significantly expanded, moving from a general statement to one that specifically identifies assets such as patents, trademarks, trade secrets, and copyrights, details the potential impact of infringement (lost revenues), and describes mitigation strategies using federal, state, and international legal rights and contractual restrictions.

FY 2023 10-K
Removed
Filed Jan 17, 2024

While we have invested in readiness to comply with applicable requirements, the dynamic and evolving nature of these laws, regulations and codes, as well as their interpretation by regulators and courts, may affect our ability (and our enterprise customers' ability) to reach current and prospective customers, to respond to both enterprise and individual customer requests under the laws (such as individual rights of access, correction and deletion of their personal information), to implement our business models effectively and to adequately address disclosure requirements. These laws, regulations and codes may also impact our innovation and business drivers in developing new and emerging technologies (for example, AI and machine learning) and may impact demand for our offerings and force us to bear the burden of more onerous obligations in our contracts. Perception of our practices, products, services or solutions, even if unfounded, as a violation of individual privacy, data protection rights or cybersecurity requirements, subjects us to public criticism, lawsuits, investigations, claims and other proceedings by regulators, industry groups or other third parties, all of which could disrupt or adversely impact our business and reputation and expose us to increased liability, fines and other punitive measures including prohibition on sales of our products, services or solutions, restrictive judicial orders and disgorgement of data. Additionally, we collect and store information on behalf of our business customers and if our customers fail to comply with contractual obligations or applicable laws, it could result in litigation or reputational harm to us. Transferring personal information across international borders is complex and subject to legal and regulatory requirements as well as active litigation and enforcement in a number of jurisdictions around the world, each of which could have an adverse impact on our ability to process and transfer personal data as part of our business operations. For example, European data transfers outside the European Economic Area are highly regulated and litigated. The mechanisms that we and many other companies rely upon for European data transfers (for example, Standard Contractual Clauses and the EU - US Data Privacy Framework) are the subject of legal challenge, regulatory interpretation and judicial decisions by the Court of Justice of the European Union. The suitability of Standard Contractual Clauses for data transfer in some scenarios has recently been the subject of legal challenge, and while the United States and the European Union reached agreement on the EU - US Data Privacy Framework, there are legal challenges to that data transfer mechanism as well. We continue to closely monitor for developments related to valid transfer mechanisms available for transferring personal data outside the European Economic Area (including the EU - US Data Privacy Framework) and other countries that have similar trans-border data flow requirements and adjust our practices accordingly. The open judicial questions and regulatory interpretations related to the validity of transfers using Standard Contractual Clauses have resulted in some changes in the obligations required to provide our services in the European Union and could expose us to potential sanctions and fines for non-compliance. Several other countries, including China, Australia, New Zealand, Brazil, Hong Kong and Japan, have also established specific legal requirements for cross-border transfers of personal information and certain countries have also established specific legal requirements for data 29 localization (such as where personal data must remain stored in the country). If other countries implement more restrictive regulations for cross-border data transfers or do not permit data to leave the country of origin, such developments could adversely impact our business and our enterprise customers' business, our financial condition and our results of operations in those jurisdictions. Our intellectual property portfolio is a valuable asset and we may not be able to protect our intellectual property rights, including our source code, from infringement or unauthorized copying, use or disclosure.

FY 2024 Q3 10-Q
Added
Filed Sep 25, 2024

While we have invested in readiness to comply with applicable requirements, the dynamic and evolving nature of these laws, regulations and codes, as well as their interpretation by regulators and courts, may affect our ability (and our enterprise customers' ability) to reach current and prospective customers, to respond to both enterprise and individual customer requests under the laws (such as individual rights of access, correction and deletion of their personal information), to implement our business models effectively and to adequately address disclosure requirements. These laws, regulations and codes may also impact our innovation and business drivers in developing new and emerging technologies (for example, AI and machine learning) and may impact demand for our offerings and force us to bear the burden of more onerous obligations in our contracts. Perception of our practices, products, services or solutions, even if unfounded, as a violation of individual privacy, data protection rights or cybersecurity requirements, subjects us to public criticism, lawsuits, investigations, claims and other proceedings by regulators, industry groups or other third parties, all of which could disrupt or adversely impact our business and reputation and expose us to increased liability, fines and other punitive measures including prohibition on sales of our products, services or solutions, restrictive judicial orders and disgorgement of data. Additionally, we collect and store information on behalf of our business customers and if our customers fail to comply with contractual obligations or applicable laws, it could result in litigation or reputational harm to us. Transferring personal information across international borders is complex and subject to legal and regulatory requirements as well as active litigation and enforcement in a number of jurisdictions around the world, each of which could have an adverse impact on our ability to process and transfer personal data as part of our business operations. For example, European data transfers outside the European Economic Area are highly regulated and litigated. The mechanisms that we and many other companies rely upon for European data transfers (for example, Standard Contractual Clauses and the EU - US Data Privacy Framework) are the subject of legal challenge, regulatory interpretation and judicial decisions by the Court of Justice of the European Union. The suitability of Standard Contractual Clauses for data transfer in some scenarios has recently been the subject of legal challenge, and while the United States and the European Union reached agreement on the EU - US Data Privacy Framework, there are legal challenges to that data transfer mechanism as well. We continue to closely monitor for developments related to valid transfer mechanisms available for transferring personal data outside the European Economic Area (including the EU - US Data Privacy Framework) and other countries that have similar trans-border data flow requirements and adjust our practices accordingly. The open judicial questions and regulatory interpretations related to the validity of transfers using Standard Contractual Clauses have resulted in some changes in the obligations required to provide our services in the European Union and could expose us to potential sanctions and fines for non-compliance. Several other countries, including China, Australia, New Zealand, Brazil, Hong Kong and Japan, have also established specific legal requirements for cross-border transfers of personal information and certain countries have also established specific legal requirements for data localization (such as where personal data must remain stored in the country). If other countries implement more restrictive regulations for cross-border data transfers or do not permit data to leave the country of origin, such developments could adversely impact our business and our enterprise customers' business, our financial condition and our results of operations in those jurisdictions. Our intellectual property portfolio is a valuable asset and we may not be able to protect our intellectual property rights, including our source code, from infringement or unauthorized copying, use or disclosure. Our patents, trademarks, trade secrets, copyrights and other intellectual property are valuable assets to us. Infringement or misappropriation of such intellectual property could result in lost revenues and ultimately reduce their value. We protect our intellectual property by relying on federal, state and common law rights in the United States and internationally, as well as a variety of administrative procedures and contractual restrictions. Despite our efforts, protecting our intellectual property rights and preventing unauthorized use of our intellectual property are inherently difficult. For instance, we actively combat software 47

de-emphasised Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of August 30, 2024, senior unsecured notes increased from $3.65 billion to $5.65 billion, and the delayed draw term loan agreement was removed from the listed obligations.

FY 2023 10-K
Removed
Filed Jan 17, 2024

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of December 1, 2023, we had $3.65 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement and $3.5 billion delayed draw term loan agreement, both of which were undrawn. Subsequent to December 1, 2023, the delayed draw term loan agreement was terminated. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

FY 2024 Q3 10-Q
Added
Filed Sep 25, 2024

Our existing and future debt obligations may adversely affect our financial condition and future financial results. As of August 30, 2024, we had $5.65 billion in senior unsecured notes outstanding and a $3 billion commercial paper program with no amounts outstanding. We also had a $1.5 billion senior unsecured revolving credit agreement, which was undrawn. This debt or future additional indebtedness may adversely affect our financial condition and future financial results by, among other things: •requiring the dedication of a portion of our expected cash flows from operations to service our debt, thereby reducing the amount of expected cash flows available for other purposes, including capital expenditures and acquisitions;

reworded We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. While the substance of the intellectual property risks remains consistent across both periods, the specific cross-reference for further information has been updated from Part II, Item 8, Note 16 to Part I, Item 1, Note 13.

FY 2023 10-K
Removed
Filed Jan 17, 2024

Our patents, trademarks, trade secrets, copyrights and other intellectual property are valuable assets to us. Infringement or misappropriation of such intellectual property could result in lost revenues and ultimately reduce their value. We protect our intellectual property by relying on federal, state and common law rights in the United States and internationally, as well as a variety of administrative procedures and contractual restrictions. Despite our efforts, protecting our intellectual property rights and preventing unauthorized use of our intellectual property are inherently difficult. For instance, we actively combat software piracy, but we continue to lose revenue due to illegal use of our software. Third parties may illegally copy and sell counterfeit versions of our products. To the extent counterfeit installations and sales replace otherwise legitimate ones, our operating results could be adversely affected. We apply for patents in the United States and in foreign countries, but we are not always successful in obtaining patent protection or in obtaining such protection timely to meet our business needs. Our patents may be invalidated or circumvented. Moreover, due to challenges in detecting patent infringement pertaining to generative AI technologies, it may be more difficult to protect our generative AI and related innovations with patents. Additionally, if we use generative AI in the creation of our source code, we may not be able to rely on copyright to protect such intellectual property. Further, the laws of some foreign countries do not provide the same level of intellectual property protection as U.S. laws and courts and could fail to adequately protect our intellectual property rights. If unauthorized disclosure of our source code occurs through security breach, cyber-attack or otherwise, we could lose future trade secret protection for that source code. Such loss could make it easier for third parties to compete with our products by copying functionality, which could cause us to lose customers and could adversely affect our revenue and operating margins. If we cannot protect our intellectual property against unauthorized copying, use, or other misappropriation, our business could be harmed. We are, and may in the future become, subject to litigation, regulatory inquiries and intellectual property infringement claims, which could result in an unfavorable outcome and have an adverse effect on our business, financial condition, results of operation and cash flows. We are subject to various legal proceedings (including class action lawsuits), claims and regulatory inquiries that are not yet resolved and additional claims, enforcement actions and inquiries may arise in the future. Any proceedings, actions, claims or inquiries initiated by or against us, whether successful or not, may be time consuming; result in costly litigation, damage awards, consent decrees, injunctive relief or increased costs of business; require us to change our business practices or products; result in negative publicity; require significant amounts of management time; result in the diversion of significant operational resources, or otherwise harm our business and financial results. Additionally, we are currently, and may in the future be subject to claims, negotiations and complex, protracted litigation relating to disputes regarding the validity or alleged infringement of third-party intellectual property rights, including patent rights. Intellectual property disputes and litigation are typically costly and can be disruptive to our business operations by diverting the attention of management and key personnel. Third-party intellectual property disputes, including those initiated by patent assertion entities, could subject us to significant liabilities, require us to enter into royalty and licensing arrangements on unfavorable terms, prevent us from offering certain products, services or solutions, subject us to injunctions restricting our sales, cause severe disruptions to our operations or the markets in which we compete, or require us to satisfy indemnification commitments with our customers, including contractual provisions under various license arrangements and service agreements. In addition, we have incurred, and may in the future incur, significant costs in acquiring the necessary third-party intellectual property rights for use in our products, in some cases to fulfill contractual obligations with our customers. Any of these occurrences could significantly harm our business. We have not prevailed, and may not in the future prevail, in every lawsuit or dispute. For further information about specific litigation and proceedings, see the section titled "Legal Proceedings" contained in Part II, Item 8, Note 16 of our Notes to Consolidated Financial Statements of this report.

FY 2024 Q3 10-Q
Added
Filed Sep 25, 2024

piracy, but we continue to lose revenue due to illegal use of our software. Third parties may illegally copy and sell counterfeit versions of our products. To the extent counterfeit installations and sales replace otherwise legitimate ones, our operating results could be adversely affected. We apply for patents in the United States and in foreign countries, but we are not always successful in obtaining patent protection or in obtaining such protection timely to meet our business needs. Our patents may be invalidated or circumvented. Moreover, due to challenges in detecting patent infringement pertaining to generative AI technologies, it may be more difficult to protect our generative AI and related innovations with patents. Additionally, if we use generative AI in the creation of our source code, we may not be able to rely on copyright to protect such intellectual property. Further, the laws of some foreign countries do not provide the same level of intellectual property protection as U.S. laws and courts and could fail to adequately protect our intellectual property rights. If unauthorized disclosure of our source code occurs through security breach, cyber-attack or otherwise, we could lose future trade secret protection for that source code. Such loss could make it easier for third parties to compete with our products by copying functionality, which could cause us to lose customers and could adversely affect our revenue and operating margins. If we cannot protect our intellectual property against unauthorized copying, use, or other misappropriation, our business could be harmed. We are, and may in the future become, subject to litigation, regulatory inquiries and intellectual property infringement claims, which could result in an unfavorable outcome and have an adverse effect on our business, financial condition, results of operation and cash flows. We are subject to various legal proceedings (including class action lawsuits), claims and regulatory inquiries that are not yet resolved and additional claims, enforcement actions and inquiries may arise in the future. Any proceedings, actions, claims or inquiries initiated by or against us, whether successful or not, may be time consuming; result in costly litigation, damage awards, consent decrees, injunctive relief or increased costs of business; require us to change our business practices or products; result in negative publicity; require significant amounts of management time; result in the diversion of significant operational resources, or otherwise harm our business and financial results. Additionally, we are currently, and may in the future be subject to claims, negotiations and complex, protracted litigation relating to disputes regarding the validity or alleged infringement of third-party intellectual property rights, including patent rights. Intellectual property disputes and litigation are typically costly and can be disruptive to our business operations by diverting the attention of management and key personnel. Third-party intellectual property disputes, including those initiated by patent assertion entities, could subject us to significant liabilities, require us to enter into royalty and licensing arrangements on unfavorable terms, prevent us from offering certain products, services or solutions, subject us to injunctions restricting our sales, cause severe disruptions to our operations or the markets in which we compete, or require us to satisfy indemnification commitments with our customers, including contractual provisions under various license arrangements and service agreements. In addition, we have incurred, and may in the future incur, significant costs in acquiring the necessary third-party intellectual property rights for use in our products, in some cases to fulfill contractual obligations with our customers. Any of these occurrences could significantly harm our business. We have not prevailed, and may not in the future prevail, in every lawsuit or dispute. For further information about specific litigation and proceedings, see the section titled "Legal Proceedings" contained in Part I, Item 1, Note 13 of our Notes to Consolidated Financial Statements of this report.

reworded •failure to identify significant problems, liabilities or other challenges during due diligence. The final sentence regarding acquisition failure was truncated in the current period's filing, omitting the statement that not achieving strategic goals may lead to incurring additional costs.

FY 2023 10-K
Removed
Filed Jan 17, 2024

•failure to identify significant problems, liabilities or other challenges during due diligence. Our ability to acquire other businesses or technologies, make strategic investments or integrate acquired businesses effectively may also be impaired by adverse economic and political events, including trade tensions, and increased global scrutiny of acquisitions and strategic investments. A number of countries, including the United States and countries in Europe and the Asia-Pacific region, are considering or have adopted more stringent restrictions or guidelines for such transactions. Governments may continue to adopt or tighten restrictions of this nature, and such restrictions or government actions could negatively impact our business and financial results. Further, if we are not able to complete an announced acquisition or investment, or we do not achieve the financial and strategic goals of an acquisition or investment, we may not realize the anticipated benefits of such acquisition or investment or we may incur additional costs, which may negatively impact our business and financial results.

FY 2024 Q3 10-Q
Added
Filed Sep 25, 2024

•failure to identify significant problems, liabilities or other challenges during due diligence. Our ability to acquire other businesses or technologies, make strategic investments or integrate acquired businesses effectively may also be impaired by adverse economic and political events, including trade tensions, and increased global scrutiny of acquisitions and strategic investments. A number of countries, including the United States and countries in Europe and the Asia-Pacific region, are considering or have adopted more stringent restrictions or guidelines for such transactions. Governments may continue to adopt or tighten restrictions of this nature, and such restrictions or government actions could negatively impact our business and financial results. Further, if we are not able to complete an announced acquisition or investment, or we do not achieve the financial and strategic goals of an acquisition or investment, we may not realize the

reworded If our reputation or our brands are damaged, our business and financial results may be adversely affected. The change is purely cosmetic; the text maintains identical substance regarding brand risks, with only minor stylistic shifts from using commas to using semicolons when enumerating various ways brands could be damaged.

FY 2023 10-K
Removed
Filed Jan 17, 2024

If our reputation or our brands are damaged, our business and financial results may be adversely affected. We believe our reputation and brands have been, and we expect them to continue to be, important to our business and financial results. Maintaining and enhancing our brands may require us to make substantial investments and these investments may not be successful. There are numerous ways that our reputation or brands could be damaged, including, among other things, introduction of new products, features or services that do not meet customer expectations, our position on or approach to new and evolving technologies, backlash from customers, government entities or other stakeholders that disagree with our product offering decisions or public policy positions, significant litigation or regulatory actions that negatively reflect on our business practices, our action or inaction or actual or perceived failure to meet our commitments on environmental, social and governance, ethical or political issues, public scrutiny regarding our handling of user privacy, data practices or content, data security breaches or compliance failures, or our approach to AI. Further, our brands may be negatively affected by uses of our products, services or solutions, particularly our AI offerings, in ways that are out of our control, such as to create or disseminate content that is deemed to be misleading, deceptive or intended to manipulate public opinion, or for illicit, objectionable or illegal ends, or by our failure to respond appropriately and in a timely manner to such uses. Such uses may result in controversy or claims related to defamation, rights of publicity, illegal content, intellectual property infringement, harmful content, misinformation and disinformation, harmful bias, misappropriation, data privacy, derivative uses of third-party AI and personal injury torts. If we fail to appropriately respond to objectionable content created using our products, services or solutions or shared on our platforms, our users may lose confidence in our brands. Entry into markets with weaker protection of brands or changes in the legal systems in countries in which we operate may also impact our ability to protect our brands. If we fail to maintain, enhance or protect our brands, or if we incur excessive expenses in our efforts to do so, our business and financial results may be adversely affected. 24

FY 2024 Q3 10-Q
Added
Filed Sep 25, 2024

If our reputation or our brands are damaged, our business and financial results may be adversely affected. We believe our reputation and brands have been, and we expect them to continue to be, important to our business and financial results. Maintaining and enhancing our brands may require us to make substantial investments and these investments may not be successful. There are numerous ways that our reputation or brands could be damaged, including, among other things, introduction of new products, features or services that do not meet customer expectations; our position on or approach to new and evolving technologies; backlash from customers, government entities or other stakeholders that disagree with our product offering decisions or public policy positions; significant litigation or regulatory actions that negatively reflect on our business practices; our action or inaction or actual or perceived failure to meet our commitments on environmental, social and governance, ethical or political issues; public scrutiny regarding our handling of user privacy, data practices or content; data security breaches or compliance failures; or our approach to AI. Further, our brands may be negatively affected by uses of our products, services or solutions, particularly our AI offerings, in ways that are out of our control, such as to create or disseminate content that is deemed to be misleading, deceptive or intended to manipulate public opinion, or for illicit, objectionable or illegal ends, or by our failure to respond appropriately and in a timely manner to such uses. Such uses may result in controversy or claims related to defamation, rights of publicity, illegal content, intellectual property infringement, harmful content, misinformation and disinformation, harmful bias, misappropriation, data privacy, derivative uses of third-party AI and personal injury torts. If we fail to appropriately respond to objectionable content created using our products, services or solutions or shared on our platforms, our users may lose confidence in our brands. Entry into markets with weaker protection of brands or changes in the legal systems in countries in which we operate may also impact our ability to protect our brands. If we fail to maintain, enhance or protect our brands, or if we incur excessive expenses in our efforts to do so, our business and financial results may be adversely affected.