MIT AI Risk Repository · Risk Sub-Category · 65.01.02
Uncertain data provenance
Category: Training Data Risks (Transparency)
Description
"Data provenance refers to tracing history of data, which includes its ownership, origin, and transformations. Without standardized and established methods for verifying where the data came from, there are no guarantees that the data is the same as the original source and has the correct usage terms."
From AI Risk Atlas (IBM2025), as extracted by the MIT AI Risk Repository (CC BY 4.0).
Classification
- Subdomain
- 6.5 Governance failure
- Causal entity
- Human
- Intent
- Other
- Timing
- Pre-deployment
Subdomain definition: Inadequate regulatory frameworks and oversight mechanisms failing to keep pace with AI development, leading to ineffective governance and the inability to manage AI risks appropriately.
Real-world incidents in this subdomain
- Nippon Life Alleged ChatGPT Practiced Law Without a License in Illinois Disability Case
- OpenAI Allegedly Did Not Alert RCMP After ChatGPT Flagged Violent Chats Before British Columbia School Shooting
- Remotely Operated Taser-Armed Drones Proposed by Taser Manufacturer as Defense for School Shootings in the US
How other frameworks describe this risk
- Mobility
- Liability issues in case of accidents
- Faster scientific progress makes it harder for governance to keep pace with development
- Type 1: Diffusion of responsibility
- Products Liability Law
- Institutional responsibilities
- Difficult to develop metrics for evaluating benefits or harms caused by AI assistants
- Benchmarking (Cross-lingual data contamination)