
For most of the past decade, digital accessibility—the practice of designing websites and other digital tools so people with disabilities can use them—was the responsibility of marketing, IT or legal. It rarely appeared on a formal risk register. The exposure was treated as a website usability problem that only surfaced when a discrimination claim arrived. However, three new developments have converged to raise the stakes around digital accessibility: a steep rise in discrimination litigation, the arrival of new global regulation and a measurable gap between what executives believe their organizations are doing and what their websites deliver.
This is no longer a niche risk. In fact, according to an AudioEye survey of more than 400 business leaders about digital accessibility, 59% said their organization would be exposed if they were audited today. Digital accessibility is one of the more predictable, frequently realized and unevenly governed risks in the modern enterprise—but it is also almost entirely manageable.
A Growing Legal and Regulatory Risk
According to Seyfarth Shaw's annual ADA Title III tracking, federal courts saw 8,667 ADA Title III filings in 2025, roughly triple the count from when Seyfarth began compiling this data in 2013. More specifically in terms of digital risk, federal website accessibility filings rose to 3,117 in 2025, a 27% jump from the prior year, pushing the segment back near its 2022 peak.
Seyfarth's analysts also note that a meaningful share of accessibility litigation has migrated to state courts, where it is not captured in these federal totals. The federal numbers, in other words, are a floor, not a ceiling. The plaintiff bar has stepped up website-related claims, demand letters have become a high-volume, low-friction enforcement mechanism, and the cost to defend a single matter, even one that settles quickly, routinely runs in the tens of thousands of dollars. AudioEye's 2026 Web Accessibility Litigation Report tracks where these filings are concentrating, and the pattern is clear: the targets are not just the Fortune 500. Mid-market companies and regional brands are increasingly in the crosshairs.
In addition, the European Accessibility Act (EAA) recently came into force in 2025. The law created private-sector obligations across the EU for a broad slice of digital products and services, from banking and e-commerce to consumer electronics. Companies that sell in Europe, regardless of their headquarters, are now operating under a second compliance regime alongside the ADA. Enforcement varies by member state, but the regulatory direction is unambiguous: Digital accessibility is no longer a domestic legal question.
Inside the enterprise, the gap between perceived posture and actual exposure has widened. The AudioEye Digital Accessibility Index, which scans tens of thousands of public-facing pages, finds an average of nearly 300 accessibility issues per page. Many of those issues are minor but plenty are not. They accumulate in places risk managers are not looking, such as marketing landing pages, third-party widgets, dynamic content and post-launch updates to UI components.
The risk has grown because the surface area has grown. Every new page, every new feature, every CMS migration and every third-party tag is a new opportunity for an accessibility issue to be introduced. A static annual audit—the historic answer to this problem—is no longer effective on its own.
Estimating Risk Exposure
In order to better understand an organization’s potential exposure to digital accessibility risk, risk managers should consider three components:
Frequency: What is the probability of receiving a demand letter or discrimination filing each year? For a U.S.-based public-facing site, this is no longer a hypothetical. Plaintiff law firms send demand letters at scale, and the targets are not limited to large enterprises. Roughly three-quarters of recent ADA Title III filings have involved e-commerce sites. If you sell anything online, your frequency assumption is closer to when than if.
Severity: Costs scale across three tiers. A demand letter resolved pre-suit can reach a few thousand dollars in settlement plus legal fees. A filed case typically runs into the low six figures, including defense costs. A litigated case with adverse rulings, depending on injunctive relief and ongoing monitoring obligations, can be materially more. The hidden severity component is reputational and operational and can involve brand impact, engineering disruption when a court orders fixes on a deadline and management distraction.
Frequency multiplier from regulatory expansion: The EAA introduced a parallel regime for any company selling in the EU. Section 508 has long applied to federal contractors. Several U.S. states have moved on their own digital accessibility requirements, and the Department of Justice has affirmed in its official guidance that the ADA applies to web content. Each regime adds a non-zero increment to total annual exposure. A program sized only against ADA Title III is sized against the last decade's risk.
The output of this exercise is a defensible annual loss expectancy figure that can sit on the risk register alongside other operational risks. It will not be a precise number, and it does not need to be. It needs to be defensible, refreshed annually and tied to mitigation decisions. A reasonable starting point for the diagnostic side of this work is a current-state scan of your public-facing properties.
Implementing a Mature Accessibility Program
The most common reason for failure is not under-investment, it is mis-ownership. In many organizations, accessibility responsibility tends to fall into one of three areas: Marketing owns the website but not the legal exposure; IT owns the code but not the policy; and legal owns the demand letters after they arrive. The result is a risk that is technically owned by everyone and effectively governed by no one.
Digital accessibility is not a single risk. It is a portfolio of risks that touches operations, legal, brand and compliance.
These four practices can help ensure compliance with digital accessibility obligations:
- Continuous monitoring, not periodic audits: A point-in-time audit captures the state of a site on a Tuesday. By Friday, marketing has created four new landing pages, and product development has updated a checkout flow. Mature programs run continuous automated detection on every page, on every change and surface new issues into a workflow with service level agreements (SLA) attached. The annual audit becomes a checkpoint, not the program.
- Combined automation and expert review: Automation finds the patterns. Experts handle the judgment calls. Programs that rely on automation alone catch a meaningful portion of the issue surface but miss the contextual ones like alt text accuracy, form labeling logic and navigation order that require a human to evaluate. Programs that rely solely on expert review are too slow to keep up with the pace of site change. The combination of automation and human review is a more effective strategy.
- Evidence on demand: When a demand letter arrives, legal teams ask, "What was the company's posture at the time of the alleged violation?" Mature programs can answer that without a fire drill. They retain dated scan results, conformance reports and a documented response process. This is the same logic that drives evidence retention in any well-run compliance function.
- Accountability that survives turnover: The most fragile accessibility programs are the ones built around a single passionate employee. When that person leaves, the program often follows. Codifying ownership, service level agreements and reporting cadence into the operating model protects the program from the predictable churn of personnel. For risk managers, the practical translation is straightforward. Add digital accessibility to the next iteration of the risk register, name an owner, define the metric and set the review cadence. Treat it the way you treat any other operational risk that has clear regulatory exposure and a measurable mitigation path.
Reframing Digital Accessibility Risk
The accessibility conversation has lived for too long in the language of compliance, audits and reactive lawsuit defense. That framing has produced a generation of programs that are under-resourced, under-owned and continuously surprised by their own exposure.
The risk management lens asks: what is the exposure, who owns it, how is it measured and how is it brought inside the organization's defined risk tolerance? Those are familiar questions in any risk function. Applied here, they produce a digital accessibility program that is more defensible, more cost-effective and more aligned with what regulators, courts and customers are now requiring of every organization with a digital footprint.