MIT AI Risk Repository · domain 4: Malicious actors

4.2 Cyberattacks, weapon development or use, and mass harm

Using AI systems to develop cyber weapons (e.g., coding cheaper, more effective malware), develop new or enhance existing weapons (e.g., Lethal Autonomous Weapons or CBRNE), or use weapons to cause mass harm.

Risk entries
82
Frameworks citing it
12
Recorded incidents
15
Incidents since 2020
14
Causal entity (risk entries)
Causal entity (risk entries) 61 0 Human: 61 Human 61 AI: 11 AI 11 Other: 8 Other 8 Not coded: 2 Not coded 2
Causal entity (risk entries)
LabelValue
Human61
AI11
Other8
Not coded2
Intent (risk entries)
Intent (risk entries) 68 0 Intentional: 68 Intentional 68 Other: 10 Other 10 Unintentional: 2 Unintentional 2 Not coded: 2 Not coded 2
Intent (risk entries)
LabelValue
Intentional68
Other10
Unintentional2
Not coded2
Timing (risk entries)
Timing (risk entries) 71 0 Post-deployment: 71 Post-deployment 71 Other: 7 Other 7 Pre-deployment: 2 Pre-deployment 2 Not coded: 2 Not coded 2
Timing (risk entries)
LabelValue
Post-deployment71
Other7
Pre-deployment2
Not coded2
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 9 0 2017: 1 2017 1 2020: 1 2020 1 2022: 1 2022 1 2023: 1 2023 1 2024: 2 2024 2 2025: 9 2025 9
Recorded incidents per year
LabelValue
20171
20201
20221
20231
20242
20259
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 66 0 Risk Category: 16 Risk Category 16 Risk Sub-Category: 66 Risk Sub-Category 66
Entries by level
LabelValue
Risk Category16
Risk Sub-Category66
  • Acquisition of a goal to harm society

    "cases of AI systems being given the outright goal of harming humanity (ChaosGPT);"

    Advancing AI Governance: A Literature Review of Problems, Options, and Proposals (Maas2023) · Human · Intentional · Pre-deployment

  • Failures in or misuse of intermediary (non-AGI) AI systems, resulting in catastrophe

    "Deployment of “prepotent” AI systems that are non-general but capable of outperforming human collective efforts on various key dimensions;170 → Militarization of AI enabling mass attacks using swarms...

    Advancing AI Governance: A Literature Review of Problems, Options, and Proposals (Maas2023) · Other · Other · Post-deployment

  • Biosecurity Threats

    "The potential misuse of general purpose AI models also extends to biosecurity threats. Biological weapons are generally understood as biological toxins or infectious agents such as viruses that are i...

    Governing General Purpose AI: A Comprehensive Map of Unreliability, Misuse and Systemic Risks (Maham2023 ) · Human · Intentional · Post-deployment

  • Model diversion

    "Model Diversion takes model manipulation one step further, by repurposing (often open-source) generative AI models in a way that diverts them from their intended functionality or from the use cases e...

    Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024) · Human · Intentional · Post-deployment

  • Unauthorized manipulation of AI

    "AI machines could be hacked and misused, e.g. manipulating an airport luggage screening system to smuggle weapons"

    Managing the ethical and risk implications of rapid advances in artificial intelligence: A literature review (Meek2016) · Human · Intentional · Post-deployment

  • CBRN Information or Capabilities

    "Eased access to or synthesis of materially nefarious information or design capabilities related to chemical, biological, radiological, or nuclear (CBRN) weapons or other dangerous materials or agent...

    Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST2024) · Other · Other · Post-deployment

  • Information Security

    "Lowered barriers for offensive cyber capabilities, including via automated discovery and exploitation of vulnerabilities to ease hacking, malware, phishing, offensive cyber operations, or other cyber...

    Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST2024) · Human · Intentional · Post-deployment

  • Purposeful or malicious harm

    "EAI systems present distinct physical risks due to their embodiment in the physical world. EAI technologies have already been designed and deployed with lethal intent, such as AI-controlled drones [5...

    Embodied AI: Emerging Risks and Opportunities for Policy Action (Perlo2025) · Human · Intentional · Post-deployment

  • Abuse & Misuse

    "The potential for AI systems to be used maliciously or irresponsibly, including for creating deepfakes, automated cyber attacks, or invasive surveillance systems. Specifically denotes intentional use...

    AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures (Sherman2023) · Human · Intentional · Post-deployment

  • Cyber-offense

    "The model can discover vulnerabilities in systems (hardware, software, data). It can write code for exploiting those vulnerabilities. It can make effective decisions once it has gained access to a sy...

    Model Evaluation for Extreme Risks (Shevlane2023) · AI · Intentional · Post-deployment

  • Chemical Risks

    "Chemical risks involve the exploitation of agents to synthesize chemical weapons, as well as the creation or release of hazardous substances during autonomous chemical experiments. This category also...

    Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025) · Human · Intentional · Post-deployment

  • Biological Risks

    "Biological risks encompass the dangerous modification of pathogens and unethical manipulation of genetic material, potentially leading to unforeseen biohazardous outcomes."

    Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025) · Other · Unintentional · Other

  • Cyberspace risks (Risks of abuse for cyberattacks)

    "AI can be used in launching automatic cyberattacks or increasing attack efficiency, including exploring and making use of vulnerabilities, cracking passwords, generating malicious codes, sending phis...

    AI Safety Governance Framework (TC2602024) · Human · Intentional · Post-deployment

  • Real-world risks (Risks of misuse of dual-use items and technologies)

    "Due to improper use or abuse, AI can pose serious risks to national security, economic security, and public health security, such as greatly reducing the capability requirements for non-experts to de...

    AI Safety Governance Framework (TC2602024) · Human · Intentional · Post-deployment

  • Security

    "Implications of the weaponization of AI for defence (the embeddedness of AI-based capabilities across the land, air, naval and space domains may affect combined arms operations)."

    An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance (Teixeira2022) · Human · Intentional · Post-deployment

  • Cyber Offense Risks

    "AI-enabled cyber offense poses a significant cyber domain security risk by fundamentally transforming the scale, sophistication, and accessibility of cyber-attacks. Unlike traditional cyber threats,...

    Frontier AI Risk Management Framework (v1.0) (Tse2025) · Human · Intentional · Post-deployment

  • Biological and Chemical Risks

    "The dual-use nature of AI technology presents a critical risk by significantly lowering technical thresholds for malicious non-state actors to design, synthesize, acquire, and deploy CBRNE (Chemical,...

    Frontier AI Risk Management Framework (v1.0) (Tse2025) · Human · Intentional · Post-deployment

  • Physical Harm and Injury Risks

    "The integration of general-purpose AI models into embodied systems creates direct physical threats through malicious exploitation of autonomous decision-making capabilities in real-world environments...

    Frontier AI Risk Management Framework (v1.0) (Tse2025) · Human · Intentional · Post-deployment

  • Warfare

    "The dangers of AI amplifying the effectiveness/failures of nuclear, chemical, biological, and radiological weapons."

    A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025) · AI · Other · Other

  • Ability to enhance and modify pathogens

    "AI can be used to enhance pathogens, making them more lethal or resistant to treatments."

    A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025) · Human · Intentional · Post-deployment

  • Terrorist access

    "Powerful AI technologies may fall into the hands of terrorists."

    A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025) · Human · Other · Other

  • Weaponization capabilities

    "AI capabilities that could be deliberately weaponized for destructive purposes."

    A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025) · Human · Intentional · Post-deployment

  • Indiscriminate weapons (CBRNE)

    "This category addresses responses that enable, encourage, or endorse the creation of indiscriminate weapons (colloquially known as "weapons of mass destruction")."

    Introducing v0.5 of the AI Safety Benchmark from MLCommons (Vidgen2024) · AI · Other · Post-deployment

  • Assisting code generation for cyber attacks, weapons, or malicious use

    Ethical and social risks of harm from language models (Weidinger2021) · Human · Intentional · Post-deployment

  • Assisting code generation for cyber security threats

    Anticipated risk: "Creators of the assistive coding tool Co-Pilot based on GPT-3 suggest that such tools may lower the cost of developing polymorphic malware which is able to change its features in or...

    Taxonomy of Risks posed by Language Models (Weidinger2022) · Human · Intentional · Post-deployment