MIT AI Risk Repository · domain 4: Malicious actors

4.2 Cyberattacks, weapon development or use, and mass harm

Using AI systems to develop cyber weapons (e.g., coding cheaper, more effective malware), develop new or enhance existing weapons (e.g., Lethal Autonomous Weapons or CBRNE), or use weapons to cause mass harm.

Risk entries
82
Frameworks citing it
12
Recorded incidents
15
Incidents since 2020
14
Causal entity (risk entries)
Causal entity (risk entries) 61 0 Human: 61 Human 61 AI: 11 AI 11 Other: 8 Other 8 Not coded: 2 Not coded 2
Causal entity (risk entries)
LabelValue
Human61
AI11
Other8
Not coded2
Intent (risk entries)
Intent (risk entries) 68 0 Intentional: 68 Intentional 68 Other: 10 Other 10 Unintentional: 2 Unintentional 2 Not coded: 2 Not coded 2
Intent (risk entries)
LabelValue
Intentional68
Other10
Unintentional2
Not coded2
Timing (risk entries)
Timing (risk entries) 71 0 Post-deployment: 71 Post-deployment 71 Other: 7 Other 7 Pre-deployment: 2 Pre-deployment 2 Not coded: 2 Not coded 2
Timing (risk entries)
LabelValue
Post-deployment71
Other7
Pre-deployment2
Not coded2
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 9 0 2017: 1 2017 1 2020: 1 2020 1 2022: 1 2022 1 2023: 1 2023 1 2024: 2 2024 2 2025: 9 2025 9
Recorded incidents per year
LabelValue
20171
20201
20221
20231
20242
20259
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 66 0 Risk Category: 16 Risk Category 16 Risk Sub-Category: 66 Risk Sub-Category 66
Entries by level
LabelValue
Risk Category16
Risk Sub-Category66
  • Operational harms (autonomous weapons)

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Not coded · Not coded · Not coded

  • Dangerous content (e.g., CBRN)

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Not coded · Not coded · Not coded

  • Fine-tuning related (Harmful fine-tuning of open-weights models)

    "Models with publicly available weights can be fine-tuned for harmful activities by bad actors, using significantly fewer resources (in terms of time and money) compared to the original training cost...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • AI-based tools attacking critical infrastructure

    "Critical infrastructure can also be damaged without AI integration, for instance, when AI-based tools are used indirectly to aid actions such as in coordinated power outages caused by large-scale use...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Systemic large-scale manipulation

    "AI systems embedded with systemic biases can manipulate large population segments, particularly when these biases align with the beliefs or behaviors of the targeted group. When weaponized at scale,...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Impacts of AI (Cyberattacks)

    -

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Automated discovery and exploitation of software systems

    "GPAIs can be used to aid in the automated discovery of software vulnerabilities [33]. This can empower malicious actors, making their cyberattacks more effi- cient and potentially more damaging. This...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Amplification of cyberattacks

    "General-purpose AI models may significantly enhance the magnitude and ef- fectiveness of cyberattacks, by amplifying existing capabilities or resources of malicious actors [3]. For example, GPAI mode...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Impacts of AI (Weapons)

    -

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Misuse of AI systems to assist in the creation of weapons

    "AI systems may be misused to aid in the creation of weapons, such as chemical, biological, radiological, and nuclear (CBRN) weapons, or augment the abilities of existing weapons, such as providing au...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Misuse of drug-discovery models

    "Models used for drug discovery, such as drug-target affinity prediction models, can be used to identify or develop dangerous toxins. This is particularly concern- ing if the training data contains in...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Human · Intentional · Post-deployment

  • Malicious use and abuse (cyberattacks)

    "Generative AI can help amplify the frequency and destructiveness of cyberattacks.311 It has the capacity “to increase the accessibility, success rate, scale, speed, stealth, and potency of cyberattac...

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · Human · Intentional · Post-deployment

  • Malicious use and abuse (biosecurity threats)

    "Many fear that generative AI could make the creation of biological weapons easier by providing access to critical knowledge and automated assistance to a wider range of actors to engage in malicious...

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · Human · Intentional · Post-deployment

  • Malicious use and abuse (military applications)

    "The advancement of AI for military purposes is rapidly ushering in a new phase of growth in military technology. Lethal Autonomous Weapons Systems (LAWS) possess the capability to detect, engage, and...

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · Human · Intentional · Post-deployment

  • Lethal Autonomous Weapons Systems (LAWS)

    LAWS are a distinctive category of weapon systems that employ sensor arrays and computer algorithms to detect and attack a target without direct human intervention in the system’s operation

    Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, Applications, Challenges and Future Research Directions (Habbal2024) · AI · Intentional · Post-deployment

  • Cybercrime

    Closely related to discussions surrounding security and harmful content, the field of cybersecurity investigates how generative AI is misused for fraudulent online activities. A particular focus lies...

    Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024) · Human · Intentional · Post-deployment

  • Weaponization

    weaponizing AI may be an onramp to more dangerous outcomes. In recent years, deep RL algorithms can outperform humans at aerial combat [18], AlphaFold has discovered new chemical weapons [66], researc...

    X-Risk Analysis for AI Research (Hendrycks2022) · Human · Intentional · Post-deployment

  • Bioterrorism

    "AIs with knowledge of bioengineering could facilitate the creation of novel bioweapons and lower barriers to obtaining such agents."

    An Overview of Catastrophic AI Risks (Hendrycks2023) · AI · Intentional · Post-deployment

  • Unleashing AI Agents

    "people could build AIs that pursue dangerous goals’"

    An Overview of Catastrophic AI Risks (Hendrycks2023) · Human · Intentional · Pre-deployment

  • Lethal Autonomous Weapons (LAW)

    "What is debated as an ethical issue is the use of LAW — AI-driven weapons that fully autonomously take actions that intentionally kill humans."

    A framework for ethical Ai at the United Nations (Hogenhout2021) · AI · Intentional · Post-deployment

  • Offensive cyber capabilities

    "These evaluations focus on whether a LLM possesses certain capabilities in the cyber-domain. This includes whether a LLM can detect and exploit vulnerabilities in hardware, software, and data. They a...

    Cataloguing LLM Evaluations (InfoComm2023) · AI · Intentional · Other

  • Weapons acquisition

    "These assessments seek to determine if a LLM can gain unauthorized access to current weapon systems or contribute to the design and development of new weapons technologies."

    Cataloguing LLM Evaluations (InfoComm2023) · AI · Intentional · Other

  • Dual-Use Science

    "LLM has science capabilities that can be used to cause harm (e.g., providing step-by-step instructions for conducting malicious experiments)"

    Cataloguing LLM Evaluations (InfoComm2023) · Human · Intentional · Other

  • Cyberattacks

    "Generative AI facilitating the damage, disruption or destruction of a third-party system and/or its components via malfunction, cyberattacks, etc"

    A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025) · AI · Other · Post-deployment

  • Cyberattack

    ability of LLMs to write reasonably good-quality code with extremely low cost and incredible speed, such great assistance can equally facilitate malicious attacks. In particular, malicious hackers can...

    Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024) · Human · Intentional · Post-deployment