AIPolicyTracker

MIT AI Risk Repository · domain 7: AI system safety, failures, & limitations

7.3 Lack of capability or robustness

AI systems that fail to perform reliably or effectively under varying conditions, exposing them to errors and failures that can have significant consequences, especially in critical applications or areas that require moral reasoning.

Risk entries
126
Frameworks citing it
12
Recorded incidents
305
Incidents since 2020
207
Causal entity (risk entries)
Causal entity (risk entries) 81 0 AI: 81 AI 81 Human: 22 Human 22 Other: 20 Other 20 Not coded: 3 Not coded 3
Causal entity (risk entries)
LabelValue
AI81
Human22
Other20
Not coded3
Intent (risk entries)
Intent (risk entries) 89 0 Unintentional: 89 Unintentional 89 Other: 28 Other 28 Intentional: 6 Intentional 6 Not coded: 3 Not coded 3
Intent (risk entries)
LabelValue
Unintentional89
Other28
Intentional6
Not coded3
Timing (risk entries)
Timing (risk entries) 64 0 Post-deployment: 64 Post-deployment 64 Other: 32 Other 32 Pre-deployment: 27 Pre-deployment 27 Not coded: 3 Not coded 3
Timing (risk entries)
LabelValue
Post-deployment64
Other32
Pre-deployment27
Not coded3
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 37 0 2012: 3 2012 3 2013: 3 2013 3 2014: 7 2014 7 2015: 9 2015 9 2016: 16 2016 16 2017: 18 2017 18 2018: 21 2018 21 2019: 14 2019 14 2020: 31 2020 31 2021: 36 2021 36 2022: 31 2022 31 2023: 27 2023 27 2024: 32 2024 32 2025: 37 2025 37 2026: 13 2026 13
Recorded incidents per year
LabelValue
20123
20133
20147
20159
201616
201718
201821
201914
202031
202136
202231
202327
202432
202537
202613
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 82 0 Risk Category: 44 Risk Category 44 Risk Sub-Category: 82 Risk Sub-Category 82
Entries by level
LabelValue
Risk Category44
Risk Sub-Category82
  • Models distracted by irrelevant context

    "Models can easily become distracted by irrelevant provided information (such as “context” in LLMs), leading to a significant decrease in their performance after introducing irrelevant information. Th...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Unintentional · Post-deployment

  • Knowledge conflicts in retrieval-augmented LLMs

    "AI models can be particularly sensitive to coherent external evidence, even when they come into conflict with the models’ prior knowledge. This may lead to models producing false outputs given false...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Unintentional · Post-deployment

  • Model sensitivity to prompt formatting

    "LLMs can be highly sensitive to variations in prompt formatting, such as changes in separators, casing, or spacing. Even minor modifications can lead to significant shifts in model performance, poten...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Other · Post-deployment

  • Goal misgeneralization

    "Goal or objective misgeneralization is a type of robustness failure where an AI system appears to be pursuing the intended objective in training, but does not generalize to pursuing this objective in...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Intentional · Post-deployment

  • Damage to critical infrastructure

    "The integration of AI systems within critical infrastructure, ranging from trans- portation to power systems, can cause substantial damage in cases of failure or malfunction. With the increasing numb...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Unintentional · Post-deployment

  • Critical infrastructure component failures when integrated with AI systems

    "When relying on GPAI in critical infrastructure, there may be common mode failures that begin with vulnerabilities or robustness issues in the underlying model architecture or training setup. These f...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Other · Post-deployment

  • AI Systems interacting with brittle environments

    "Deployed AI systems can rely on physical sensors and data sources that may exhibit hardware drift and thus data distribution drift over time. This distribu- tion drift may affect system robustness an...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Unintentional · Post-deployment

  • Models generating code with security vulnerabilities

    "Models can generate code or coding suggestions that contain security vulner- abilities. This may occur across various LLM-based model families, including more advanced models with superior coding per...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Unintentional · Post-deployment

  • Homogenization or correlated failures in model derivatives

    "Homogenization refers to common methodologies and models used across down- stream GPAI systems, which may lead to uniform failures and amplification of biases [176, 30]. This risk arises when numerou...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Other · Other · Post-deployment

  • Incompetence

    "This means the AI simply failing in its job. The consequences can vary from unintentional death (a car crash) to an unjust rejection of a loan or job application."

    A framework for ethical Ai at the United Nations (Hogenhout2021) · AI · Unintentional · Post-deployment

  • Data usage restrictions

    "Laws and other restrictions can limit or prohibit the use of some data for specific AI use cases."

    AI Risk Atlas (IBM2025) · Human · Unintentional · Pre-deployment

  • Data acquisition restrictions

    "Laws and other regulations might limit the collection of certain types of data for specific AI use cases."

    AI Risk Atlas (IBM2025) · Human · Unintentional · Pre-deployment

  • Data transfer restrictions

    "Laws and other restrictions can limit or prohibit transferring data."

    AI Risk Atlas (IBM2025) · Human · Unintentional · Pre-deployment

  • Data contamination

    "Data contamination occurs when incorrect data is used for training. For example, data that is not aligned with model’s purpose or data that is already set aside for other development tasks such as te...

    AI Risk Atlas (IBM2025) · Human · Unintentional · Pre-deployment

  • Unrepresentative data

    "Unrepresentative data occurs when the training or fine-tuning data is not sufficiently representative of the underlying population or does not measure the phenomenon of interest."

    AI Risk Atlas (IBM2025) · Other · Unintentional · Pre-deployment

  • Improper retraining

    "Using undesirable output (for example, inaccurate, inappropriate, and user content) for retraining purposes can result in unexpected model behavior."

    AI Risk Atlas (IBM2025) · Human · Unintentional · Post-deployment

  • Improper data curation

    "Improper collection and preparation of training or tuning data includes data label errors and by using data with conflicting information or misinformation."

    AI Risk Atlas (IBM2025) · Human · Unintentional · Pre-deployment

  • Poor model accuracy

    "Poor model accuracy occurs when a model’s performance is insufficient to the task it was designed for. Low accuracy might occur if the model is not correctly engineered, or there are changes to the m...

    AI Risk Atlas (IBM2025) · Human · Unintentional · Post-deployment

  • Incomplete advice

    "When a model provides advice without having enough information, resulting in possible harm if the advice is followed."

    AI Risk Atlas (IBM2025) · AI · Unintentional · Post-deployment

  • Machine ethics

    "These evaluations assess the morality of LLMs, focusing on issues such as their ability to distinguish between moral and immoral actions, and the circumstances in which they fail to do so."

    Cataloguing LLM Evaluations (InfoComm2023) · AI · Other · Other

  • Psychological traits

    "These evaluations gauge a LLM's output for characteristics that are typically associated with human personalities (e.g., such as those from the Big Five Inventory). These can, in turn, shed light on...

    Cataloguing LLM Evaluations (InfoComm2023) · AI · Other · Other

  • Robustness

    "These evaluations assess the quality, stability, and reliability of a LLM's performance when faced with unexpected, out-of-distribution or adversarial inputs. Robustness evaluation is essential in en...

    Cataloguing LLM Evaluations (InfoComm2023) · AI · Unintentional · Other

  • Violation of Ethics

    "Unethical behaviors in AI systems pertain to actions that counteract the common goodor breach moral standards – such as those causing harm to others. These adverse behaviors often stem fromomitting e...

    AI Alignment: A Comprehensive Survey (Ji2023) · AI · Intentional · Other

  • Accidents

    "Accidents include unintended failure modes that, in principle, could be considered the fault of the system or the developer"

    Examining the differential risk from high-level artificial intelligence and the question of control (Kilian2023) · Other · Unintentional · Other

  • Harm caused by incompetent systems

    "While HP#1 concerns mean or best-case performance, HP#2 concerns worst-case performance: how can we ensure that AI systems will perform safely, and how can we prove this? ML systems have been impleme...

    Ten Hard Problems in Artificial Intelligence We Must Get Right (Leech2024 ) · AI · Unintentional · Post-deployment