AI risk
AI risk, evidenced
Advanced AI must be handled with great responsibility. Here is what has actually gone wrong, who it hurt, and which rules answer it.
Concern about AI risk is now shared by researchers, boards, regulators and heads of state. This page keeps that concern honest: every number below comes from the AI Incident Database (recorded harms) and the MIT AI Risk Repository (how experts classify risk), is dated, and links to the record behind it and to the policy instruments that respond.
1. Harm is rising, and its shape is changing
Recorded incidents grow year on year while the mix shifts: generative systems moved misinformation, impersonation and fraud from the margins to the centre. The timeline marks the policy milestones that followed; each bar opens the incidents of that year.
| Year | Incidents |
|---|---|
| 2016 | 41 |
| 2017 | 50 |
| 2018 | 46 |
| 2019 | 44 |
| 2020 | 91 |
| 2021 | 80 |
| 2022 | 106 |
| 2023 | 174 |
| 2024 | 299 |
| 2025 | 449 |
| 2026 | 212 |
- 2019-05 OECD AI Principles
- 2021-04 EU AI Act proposed
- 2021-11 UNESCO AI ethics recommendation
- 2023-01 NIST AI RMF 1.0
- 2023-11 Bletchley Declaration
- 2024-05 Council of Europe AI Convention
- 2024-08 EU AI Act in force
- 2025-02 EU prohibited practices apply
- 2025-09 Italy Law 132/2025
- 2026-01 Texas TRAIGA in force
- 2026-08 EU high-risk obligations apply
| Label | Value |
|---|---|
| Privacy & Security | 14 |
| AI system safety… | 32 |
| Discrimination and Toxic... | 36 |
| Malicious Actors & Misus... | 11 |
| Misinformation | 5 |
| Human-Computer Interacti... | 2 |
| Label | Value |
|---|---|
| Discrimination and Toxic... | 6 |
| Malicious Actors & Misus... | 58 |
| AI system safety… | 9 |
| Misinformation | 16 |
| Human-Computer Interacti... | 4 |
| Privacy & Security | 6 |
| Socioeconomic & Environm... | 1 |
2. Who is harmed, and who deploys the systems involved
Harm concentrates on identifiable groups: minors, women, the public, workers and specific communities. The organisations named as deployers repeat, which is where obligations for deployers, transparency and post-market monitoring bite.
| Label | Value |
|---|---|
| Privacy | 88 |
| Women and girls | 82 |
| Women | 67 |
| Epistemic integrity | 46 |
| Biometric data subject... | 38 |
| Students | 35 |
| General public | 30 |
| Minors | 29 |
| Educational communitie... | 28 |
| Victims of deepfake ab... | 24 |
| Label | Value |
|---|---|
| Scammers | 62 |
| Synthetic media creato... | 44 |
| Deepfake creators | 42 |
| 42 | |
| Tesla | 41 |
| Openai | 40 |
| 35 | |
| Unknown | 24 |
| Meta | 23 |
| Amazon | 22 |
| Label | Value |
|---|---|
| None | 126 |
| AI tangible harm event | 44 |
| Unclear | 10 |
| AI tangible harm near-... | 10 |
| AI tangible harm issue | 10 |
3. Where harm is recorded versus where rules exist
For policymakers and funders the question is coverage: do the places where incidents are recorded have binding AI rules? Only 140 incidents carry a country code, and reporting is biased toward English-language media, so read this as a prompt for enquiry rather than a ranking.
| Country | Incidents | Instruments tracked | Binding | Status |
|---|---|---|---|---|
| United States | 91 | 4 | 2 | Federal: executive-branch policy (Executive Order 14179 of January 2025 and the July 2025 AI Action Plan) plus... |
| United Kingdom | 6 | 4 | — | Principles-based, regulator-led framework; no AI-specific Act in force. The government has signalled a future... |
| Russia | 4 | 2 | 1 | National AI strategy (2019, updated 2024) as policy; experimental legal regimes in force; AI ethics code volun... |
| China | 4 | 3 | 2 | Instruments on record: Interim Measures for the Management of Generative Artificial Intelligence Services (202... |
| Germany | 3 | 2 | 1 | EU AI Act applies; national implementing act (KI-Marktüberwachungs- und Innovationsförderungsgesetz) proposed;... |
| New Zealand | 3 | 2 | — | National AI Strategy (2025) and responsible-AI guidance as policy; Algorithm Charter for government agencies;... |
| Canada | 3 | 3 | — | Instruments on record: Pan-Canadian Artificial Intelligence Strategy (2017, strategy, adopted); Artificial Int... |
| France | 3 | 2 | — | EU AI Act applies; national AI strategy (phases since 2018) as policy; CNIL AI guidance; competent-authority d... |
| Vietnam | 2 | 2 | 1 | Instruments on record: National Strategy on Research, Development and Application of Artificial Intelligence t... |
| India | 2 | 4 | 1 | No binding cross-sector AI law. Binding obligations arise from the DPDP Act 2023 (phased commencement under th... |
| Ireland | 2 | 1 | — | EU AI Act applies; competent authorities designated in phases; national AI strategy refreshed 2024. |
| Australia | 2 | 3 | — | No binding cross-sector AI law; mandatory guardrails were consulted on in 2024 but the December 2025 National... |
| South Korea | 2 | 1 | 1 | Instruments on record: Framework Act on the Development of Artificial Intelligence and Establishment of a Foun... |
| Indonesia | 1 | 3 | 1 | Instruments on record: Strategi Nasional Kecerdasan Artifisial Indonesia 2020-2045 (2020, strategy, adopted);... |
| Sweden | 1 | 1 | — | EU AI Act applies; AI Commission roadmap (2024) under implementation as policy; national approach (2018). |
4. How policy responds, domain by domain
Each domain links to the instruments whose recorded use cases address it, and to the obligations, deadlines and templates behind them. Click a domain for its subdomains, frameworks and incidents.
Domain 1
Discrimination & Toxicity
- Incidents
- 243
- Risk entries
- 224
- Instruments
- 20
Domain 2
Privacy & Security
- Incidents
- 112
- Risk entries
- 199
- Instruments
- 10
Domain 3
Misinformation
- Incidents
- 196
- Risk entries
- 80
- Instruments
- 39
Domain 4
Malicious actors
- Incidents
- 566
- Risk entries
- 270
- Instruments
- 40
Domain 5
Human-Computer Interaction
- Incidents
- 42
- Risk entries
- 107
- Instruments
- 41
Domain 6
Socioeconomic & Environmental
- Incidents
- 24
- Risk entries
- 300
- Instruments
- 104
Domain 7
AI system safety, failures, & limitations
- Incidents
- 313
- Risk entries
- 422
- Instruments
- 40
5. What to do with this, depending on who you are
AI CISO or compliance lead
Start from the domains your systems touch, then the obligations with dates.
Researcher
Filter, drill down and export with licence and citation attached.
Policymaker or diplomat
Compare jurisdictions and see which harms remain unaddressed.
Civil society, donor, journalist
Evidence of who is harmed and where governance is missing, with sources.
Causal taxonomy: who causes the risk, and was it intended?
| Entity \ Intent | Intentional | Unintentional | Other | Not coded |
|---|---|---|---|---|
| Human | 356 | 149 | 88 | 1 |
| AI | 147 | 320 | 194 | 1 |
| Other | 39 | 84 | 210 | 2 |
| Not coded | 1 | 1 | 2 | 238 |
Explore: domains and subdomains
Each band is a domain; each block a subdomain, sized by how much of the evidence it carries. Click a block for its definition, causal breakdowns, frameworks, risk entries and incidents.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.