{"attribution":{"source":"MIT AI Risk Repository, Domain Taxonomy of AI Risks v1 (MIT AI Risk Initiative)","license":"CC BY 4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","citation":"Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2025). The AI Risk Repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence. arXiv:2408.12622."},"exported_at":"2026-09-11"}
{"rows":[{"ev_id":"02.04.00","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Category","risk_category":"Software Security Issues","risk_subcategory":null,"description":"\"The software development toolchain of LLMs is complex and could bring threats to the developed LLM.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"02.04.01","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Sub-Category","risk_category":"Software Security Issues","risk_subcategory":"Programming Language","description":"\"Most LLMs are developed using the Python language, whereas the vulnerabilities of Python interpreters pose threats to the developed models\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"02.05.00","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Category","risk_category":"Hardware Vulnerabilities","risk_subcategory":null,"description":"\"The vulnerabilities of hardware systems for training and inferencing brings issues to LLM-based applications.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"02.05.01","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Sub-Category","risk_category":"Hardware Vulnerabilities","risk_subcategory":"Network Devices","description":"\"The training of LLMs often relies on distributed network systems [171], [172]. During the transmission of gradients through the links between GPU server nodes, significant volumetric traffic is generated. This traffic can be susceptible to disruption by burst traffic, such as pulsating attacks [161]. Furthermore, distributed training frameworks may encounter congestion issues [173].\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"02.06.00","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Category","risk_category":"Issues on External Tools","risk_subcategory":null,"description":"\"The external tools (e.g., web APIs) present trustworthiness and privacy issues to LLM-based applications.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"02.09.05","quick_ref":"Cui2024","paper_title":"Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems","level":"Risk Sub-Category","risk_category":"Hallucinations","risk_subcategory":"Pursuing Consistent Context","description":"\"LLMs have been demonstrated to pursue consistent context [129]–[132], which may lead to erroneous generation when the prefixes contain false information. Typical examples include sycophancy [129], [130], false demonstrations-induced hallucinations [113], [133], and snowballing [131]. As LLMs are generally fine-tuned with instruction-following data and user feedback, they tend to reiterate user-provided opinions [129], [130], even though the opinions contain misinformation. Such a sycophantic behavior amplifies the likelihood of generating hallucinations, since the model may prioritize user op","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":3,"subdomain":"3.1"},{"ev_id":"03.03.00","quick_ref":"Cunha2023","paper_title":"Navigating the Landscape of AI Ethics and Responsibility","level":"Risk Category","risk_category":"Intellectual property rights violations","risk_subcategory":null,"description":"\"This is an emerging category, with more cases prone to appear as the use of generative AI tools–such as Stable Diffusion, Midjourney, or ChatGPT–becomes more widespread. Some content creators are already suing for the appropriation of their work to train AI algorithms without a request for permission or compensation. Perhaps even more damaging cases will appear as developers increasingly ask chatbots or assistants like CoPilot for ready-to-use computer code. Even if these AI tools have learned only from open-source software (OSS) projects, which is not a given, there are still serious issues ","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.3"},{"ev_id":"03.05.00","quick_ref":"Cunha2023","paper_title":"Navigating the Landscape of AI Ethics and Responsibility","level":"Risk Category","risk_category":"Enabling malicious actors and harmful actions","risk_subcategory":null,"description":"\"Some uses of AI have been deeply concerning, namely voice cloning [58] and the generation of deep fake videos [59]. For example, in March 2022, in the early days of the Russian invasion of Ukraine, hackers broadcast via the Ukrainian news website Ukraine 24 a deep fake video of President Volodymyr Zelensky capitulating and calling on his soldiers to lay down their weapons [60]. The necessary software to create these fakes is readily available on the Internet, and the hardware requirements are modest by today’s standards [61]. Other nefarious uses of AI include accelerating password cracking [","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.0"},{"ev_id":"04.01.00","quick_ref":"Deng2023","paper_title":"Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements","level":"Risk Category","risk_category":"Toxicity and Abusive Content","risk_subcategory":null,"description":"This typically refers to rude, harmful, or inappropriate expressions.","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.2"},{"ev_id":"04.02.00","quick_ref":"Deng2023","paper_title":"Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements","level":"Risk Category","risk_category":"Unfairness and Discrimination","risk_subcategory":null,"description":"Social bias is an unfairly negative attitude towards a social group or individuals based on one-sided or inaccurate information, typically pertaining to widely disseminated negative stereotypes regarding gender, race, religion, etc.","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"04.07.00","quick_ref":"Deng2023","paper_title":"Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements","level":"Risk Category","risk_category":"Malicious Use and Unleashing AI Agents","risk_subcategory":null,"description":"LMs, due to their remarkable capabilities, carry the same potential for malice as other technological products. For instance, they may be used in information warfare to generate deceptive information or unlawful content, thereby having a significant impact on individuals and society. As current LMs are increasingly built as agents to accomplish user objectives, they may disregard the moral and safety guidelines if operating without adequate supervision. Instead, they may execute user commands mechanically without considering the potential damage. They might interact unpredictably with humans a","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.0"},{"ev_id":"05.05.00","quick_ref":"Hagendorff2024","paper_title":"Mapping the Ethics of Generative AI: A Comprehensive Scoping Review","level":"Risk Category","risk_category":"Privacy","risk_subcategory":null,"description":"Generative AI systems, similar to traditional machine learning methods, are considered a threat to privacy and data protection norms. A major concern is the intended extraction or inadvertent leakage of sensitive or private information from LLMs. To mitigate this risk, strategies such as sanitizing training data to remove sensitive information or employing synthetic data for training are proposed.","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"05.06.00","quick_ref":"Hagendorff2024","paper_title":"Mapping the Ethics of Generative AI: A Comprehensive Scoping Review","level":"Risk Category","risk_category":"Interaction risks","risk_subcategory":null,"description":"Many novel risks posed by generative AI stem from the ways in which humans interact with these systems. For instance, sources discuss epistemic challenges in distinguishing AI-generated from human content. They also address the issue of anthropomorphization, which can lead to an excessive trust in generative AI systems. On a similar note, many papers argue that the use of conversational agents could impact mental well-being or gradually supplant interpersonal communication, potentially leading to a dehumanization of interactions. Additionally, a frequently discussed interaction risk in the lit","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"05.09.00","quick_ref":"Hagendorff2024","paper_title":"Mapping the Ethics of Generative AI: A Comprehensive Scoping Review","level":"Risk Category","risk_category":"Alignment","risk_subcategory":null,"description":"The general tenet of AI alignment involves training generative AI systems to be harmless, helpful, and honest, ensuring their behavior aligns with and respects human values. However, a central debate in this area concerns the methodological challenges in selecting appropriate values. While AI systems can acquire human values through feedback, observation, or debate, there remains ambiguity over which individuals are qualified or legitimized to provide these guiding signals. Another prominent issue pertains to deceptive alignment, which might cause generative AI systems to tamper evaluations. A","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"07.02.00","quick_ref":"Kilian2023","paper_title":"Examining the differential risk from high-level artificial intelligence and the question of control","level":"Risk Category","risk_category":"Accidents","risk_subcategory":null,"description":"\"Accidents include unintended failure modes that, in principle, could be considered the fault of the system or the developer\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"07.04.00","quick_ref":"Kilian2023","paper_title":"Examining the differential risk from high-level artificial intelligence and the question of control","level":"Risk Category","risk_category":"Structural","risk_subcategory":null,"description":"\"Structural risks are concerned with how AI technologies \"shape and are shaped by the environments in which they are developed and deployed\"\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"08.02.00","quick_ref":"McLean2023","paper_title":"The risks associated with Artificial General Intelligence: A systematic review","level":"Risk Category","risk_category":"AGIs being given or developing unsafe goals","risk_subcategory":null,"description":"\"The risks associated with AGI goal safety, including human attempts at making goals safe, as well as the AGI making its own goals safe during self-improvement.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"08.06.00","quick_ref":"McLean2023","paper_title":"The risks associated with Artificial General Intelligence: A systematic review","level":"Risk Category","risk_category":"Existential risks","risk_subcategory":null,"description":"\"The risks posed generally to humanity as a whole, including the dangers of unfriendly AGI, the suffering of the human race.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"09.02.02","quick_ref":"Meek2016","paper_title":"Managing the ethical and risk implications of rapid advances in artificial intelligence: A literature review","level":"Risk Sub-Category","risk_category":"Domain-specific AI - Effects on humans and other living beings: Non-existential risks","risk_subcategory":"Human dignity/respect","description":"\"Discrepancies between caste/status based on intelligence may lead to undignified parts of the society—e.g., humans—who are surpassed in intelligence by AI\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"09.03.02","quick_ref":"Meek2016","paper_title":"Managing the ethical and risk implications of rapid advances in artificial intelligence: A literature review","level":"Risk Sub-Category","risk_category":"AGI - Effects on humans and other living beings: Existential risks","risk_subcategory":"Unpredictable outcomes","description":"\"Our culture, lifestyle, and even probability of survival may change drastically. Because the intentions programmed into an artificial agent cannot be guaranteed to lead to a positive outcome, Machine Ethics becomes a topic that may not produce guaranteed results, and Safety Engineering may correspondingly degrade our ability to utilize the technology fully.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"10.06.00","quick_ref":"Paes2023","paper_title":"Social Impacts of Artificial Intelligence and Mitigation Recommendations: An Exploratory Study","level":"Risk Category","risk_category":"Reduced Autonomy/Responsibility","risk_subcategory":null,"description":"\"AI is providing more and more solutions for complex activities, and by taking advantage of this process, people are becoming able to perform a greater number of activities more quickly and accurately. However, the result of this innovation is enabling choices that were once exclusively human responsibility to be made by AI systems.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"11.01.00","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Category","risk_category":"Representational Harms","risk_subcategory":null,"description":"\"beliefs about different social groups that reproduce unjust societal hierarchies\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"11.03.01","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Quality-of-Service Harms","risk_subcategory":"Alienation","description":"Alienation is the specific self-estrangement experienced at the time of technology use, typically surfaced through interaction with systems that under-perform for marginalized individuals","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":1,"subdomain":"1.3"},{"ev_id":"11.03.02","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Quality-of-Service Harms","risk_subcategory":"Increased labor","description":"increased burden (e.g., time spent) or effort required by members of certain social groups to make systems or products work as well for them as others","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":1,"subdomain":"1.3"},{"ev_id":"11.04.00","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Category","risk_category":"Interpersonal Harms","risk_subcategory":null,"description":"Interpersonal harms capture instances when algorithmic systems adversely shape relations between people or communities.","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"11.04.01","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Interpersonal Harms","risk_subcategory":"Loss of agency/control","description":"Loss of agency occurs when the use [123, 137] or abuse [142] of algorithmic systems reduces autonomy. One dimension of agency loss is algorithmic profiling [138], through which people are subject to social sorting and discriminatory outcomes to access basic services... presentation of content may lead to “algorithmically informed identity change. . . including [promotion of] harmful person identities (e.g., interests in white supremacy, disordered eating, etc.).” Similarly, for content creators, desire to maintain visibility or prevent shadow banning, may lead to increased conforming of conten","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"11.05.01","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Societal System Harms","risk_subcategory":"Information harms","description":"information-based harms capture concerns of misinformation, disinformation, and malinformation. Algorithmic systems, especially generative models and recommender, systems can lead to these information harms","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":3,"subdomain":"3.1"},{"ev_id":"11.05.03","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Societal System Harms","risk_subcategory":"Civic and political harms","description":"Political harms emerge when “people are disenfranchised and deprived of appropriate political power and influence” [186, p. 162]. These harms focus on the domain of government, and focus on how algorithmic systems govern through individualized nudges or micro-directives [187], that may destabilize governance systems, erode human rights, be used as weapons of war [188], and enact surveillant regimes that disproportionately target and harm people of color","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"11.05.04","quick_ref":"Shelby2023","paper_title":"Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction","level":"Risk Sub-Category","risk_category":"Societal System Harms","risk_subcategory":"Labor & material/Macro-socio economic harms","description":"Algorithmic systems can increase “power imbalances in socio-economic relations” at the societal level [4, 137, p. 182], including through exacerbating digital divides and entrenching systemic inequalities [114, 230]. The development of algorithmic systems may tap into and foster forms of labor exploitation [77, 148], such as unethical data collection, worsening worker conditions [26], or lead to technological unemployment [52], such as deskilling or devaluing human labor [170]... when algorithmic financial systems fail at scale, these can lead to “flash crashes” and other adverse incidents wit","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.1"},{"ev_id":"12.03.00","quick_ref":"Sherman2023","paper_title":"AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures","level":"Risk Category","risk_category":"Environmental & Societal Impact","risk_subcategory":null,"description":"\"Addresses AI's broader societal effects, including labor displacement, mental health impacts, and issues from manipulative technologies like deepfakes. Additionally, it considers AI's environmental footprint, balancing resource strain and training-related carbon emissions against AI's potential to help address environmental problems.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.0"},{"ev_id":"12.06.00","quick_ref":"Sherman2023","paper_title":"AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures","level":"Risk Category","risk_category":"Long-term & Existential Risk","risk_subcategory":null,"description":"\"The speculative potential for future advanced AI systems to harm human civilization, either through misuse or due to challenges in aligning AI objectives with human values.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"13.02.02","quick_ref":"Solaiman2023","paper_title":"Evaluating the Social Impact of Generative AI Systems in Systems and Society","level":"Risk Sub-Category","risk_category":"Impacts: People and Society","risk_subcategory":"Inequality, Marginalization, and Violence","description":"\"Generative AI systems are capable of exacerbating inequality, as seen in sections on 4.1.1 Bias, Stereotypes, and Representational Harms and 4.1.2 Cultural Values and Sensitive Content, and Disparate Performance. When deployed or updated, systems' impacts on people and groups can directly and indirectly be used to harm and exploit vulnerable and marginalized groups.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"14.06.00","quick_ref":"Steimers2022","paper_title":"Sources of Risk of AI Systems","level":"Risk Category","risk_category":"Security","risk_subcategory":null,"description":"\"Artificial intelligence comes with an intrinsic set of challenges that need to be considered when discussing trustworthiness, especially in the context of functional safety. AI models, especially those with higher complexities (such as neural networks), can exhibit specific weaknesses not found in other types of systems and must, therefore, be subjected to higher levels of scrutiny, especially when deployed in a safety-critical context\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"14.08.00","quick_ref":"Steimers2022","paper_title":"Sources of Risk of AI Systems","level":"Risk Category","risk_category":"Technological Maturity","risk_subcategory":null,"description":"\"The technological maturity level describes how mature and error-free a certain technology is in a certain application context. If new technologies with a lower level of maturity are used in the development of the AI system, they may contain risks that are still unknown or difficult to assess.Mature technologies, on the other hand, usually have a greater variety of empirical data available, which means that risks can be identified and assessed more easily. However, with mature technologies, there is a risk that risk awareness decreases over time\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.4"},{"ev_id":"15.01.00","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Category","risk_category":"First-Order Risks","risk_subcategory":null,"description":"\"First-order risks can be generally broken down into risks arising from intended and unintended use, system design and implementation choices, and properties of the chosen dataset and learning components.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"15.01.08","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Sub-Category","risk_category":"First-Order Risks","risk_subcategory":"Control","description":"This is the difficulty of controlling the ML system","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"15.02.00","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Category","risk_category":"Second-Order Risks","risk_subcategory":null,"description":"\"Second-order risks result from the consequences of first-order risks and relate to the risks resulting from an ML system interacting with the real world, such as risks to human rights, the organization, and the natural environment.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.0"},{"ev_id":"16.05.00","quick_ref":"Weidinger2022","paper_title":"Taxonomy of Risks posed by Language Models","level":"Risk Category","risk_category":"Risk area 5: Human-Computer Interaction Harms","risk_subcategory":null,"description":"\"This section focuses on risks specifically from LM applications that engage a user via dialogue, also referred to as conversational agents (CAs) [142]. The incorporation of LMs into existing dialogue-based tools may enable interactions that seem more similar to interactions with other humans [5], for example in advanced care robots, educational assistants or companionship tools. Such interaction can lead to unsafe use due to users overestimating the model, and may create new avenues to exploit and violate the privacy of the user. Moreover, it has already been observed that the supposed identi","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"16.05.03","quick_ref":"Weidinger2022","paper_title":"Taxonomy of Risks posed by Language Models","level":"Risk Sub-Category","risk_category":"Risk area 5: Human-Computer Interaction Harms","risk_subcategory":"Avenues for exploiting user trust and accessing more private information","description":"Anticipated risk: \"In conversation, users may reveal private information that would otherwise be difficult to access, such as opinions or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, e.g. via more effective recommendations of addictive applications. In one study, humans who interacted with a ‘human-like’ chatbot disclosed more private information than individuals who interacted with a ‘machine-like’ chatbot [87].\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"17.02.03","quick_ref":"Weidinger2021","paper_title":"Ethical and social risks of harm from language models","level":"Risk Sub-Category","risk_category":"Information Hazards ","risk_subcategory":"Risks from leaking or correctly inferring sensitive information ","description":"\"LMs may provide true, sensitive information that is present in the training data. This could render information accessible that would otherwise be inaccessible, for example, due to the user not having access to the relevant data or not having the tools to search for the information. Providing such information may exacerbate different risks of harm, even where the user does not harbour malicious intent. In the future, LMs may have the capability of triangulating data to infer and reveal other secrets, such as a military strategy or a business secret, potentially enabling individuals with acces","entity":"Other","intent":"Other","timing":"Post-deployment","domain":2,"subdomain":"2.1"},{"ev_id":"17.05.00","quick_ref":"Weidinger2021","paper_title":"Ethical and social risks of harm from language models","level":"Risk Category","risk_category":"Human-Computer Interaction Harms ","risk_subcategory":null,"description":"\"Harms that arise from users overly trusting the language model, or treating it as human-like\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"17.05.02","quick_ref":"Weidinger2021","paper_title":"Ethical and social risks of harm from language models","level":"Risk Sub-Category","risk_category":"Human-Computer Interaction Harms ","risk_subcategory":"Creating avenues for exploiting user trust, nudging or manipulation ","description":"\"In conversation, users may reveal private information that would otherwise be difficult to access, such as thoughts, opinions, or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, such as via surveillance or the creation of addictive applications.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"18.06.00","quick_ref":"Weidinger2023","paper_title":"Sociotechnical Safety Evaluation of Generative AI Systems","level":"Risk Category","risk_category":"Socioeconomic and environmental harms ","risk_subcategory":null,"description":"\"AI systems amplifying existing inequalities or creating negative impacts on employment, innovation, and the environment\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"19.01.01","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Technological, Data and Analytical AI Risks ","risk_subcategory":"Loss of control of autonomous systems and unforeseen behaviour due to lack of transparency and self-programming/ reprogramming","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"19.01.04","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Technological, Data and Analytical AI Risks ","risk_subcategory":"Vulnerability of AI systems to attacks and misuse","description":null,"entity":"Other","intent":"Intentional","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"19.02.00","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Category","risk_category":"Informational and Communicational AI Risks ","risk_subcategory":null,"description":"\"Informational and communicational AI risks refer particularly to informational manipulation through AI systems that influence the provision of information (Rahwan, 2018; Wirtz & Müller, 2019), AIbased disinformation and computational propaganda, as well as targeted censorship through AI systems that use respectively modified algorithms, and thus restrict freedom of speech.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"19.02.01","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Informational and Communicational AI Risks ","risk_subcategory":"Manipulation and control of information provision (e.g., personalised adds, filtered news)","description":null,"entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"19.02.03","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Informational and Communicational AI Risks ","risk_subcategory":"Censorship of opinions expressed in the Internet restricts freedom of expression","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"19.03.00","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Category","risk_category":"Economic AI Risks ","risk_subcategory":null,"description":"\"In the context of economic AI risks two major risks dominate. These refer to the disruption of the economic system due to an increase of AI technologies and automation. For instance, a higher level of AI integration into the manufacturing industry may result in massive unemployment, leading to a loss of taxpayers and thus negatively impacting the economic system (Boyd & Wilson, 2017; Scherer, 2016). This may also be associated with the risk of losing control and knowledge of organisational processes as AI systems take over an increasing number of tasks, replacing employees in these processes.","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"19.03.03","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Economic AI Risks ","risk_subcategory":"Loss of supervision and control of business processes","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"19.04.05","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Social AI Risks ","risk_subcategory":"Decreasing human interaction as AI systems assume human tasks, disturbing well-being","description":null,"entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"19.05.00","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Category","risk_category":"Ethical AI Risks ","risk_subcategory":null,"description":"\"In the context of ethical AI risks, two risks are of particular importance. First, AI systems may lack a legitimate ethical basis in establishing rules that greatly influence society and human relationships (Wirtz & Müller, 2019). In addition, AI-based discrimination refers to an unfair treatment of certain population groups by AI systems. As humans initially programme AI systems, serve as their potential data source, and have an impact on the associated data processes and databases, human biases and prejudices may also become part of AI systems and be reproduced (Weyerer & Langer, 2019, 2020","entity":"Other","intent":"Unintentional","timing":"Other","domain":1,"subdomain":"1.0"},{"ev_id":"19.05.07","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Ethical AI Risks ","risk_subcategory":"Technological arms race with autonomous weapons","description":null,"entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":6,"subdomain":"6.4"},{"ev_id":"19.06.00","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Category","risk_category":"Legal AI Risks ","risk_subcategory":null,"description":"\"Legal and regulatory risks comprise in particular the unclear definition of responsibilities and accountability in case of AI failures and autonomous decisions with negative impacts (Reed, 2018; Scherer, 2016). Another great risk in this context refers to overlooking the scope of AI governance and missing out on important governance aspects, resulting in negative consequences (Gasser & Almeida, 2017; Thierer et al., 2017).\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"19.06.02","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Legal AI Risks ","risk_subcategory":"Technology obedience and lack of governance through increasing application of AI systems","description":null,"entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"19.06.03","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Legal AI Risks ","risk_subcategory":"Great scope and ubiquity of AI make appropriate governance difficult, coverage of governance scope almost impossibl","description":null,"entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"20.01.01","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Sub-Category","risk_category":"AI Law and Regulation ","risk_subcategory":"Governance of autonomous intelligence systems ","description":"\"Governance of autonomous intelligence systemaddresses the question of how to control autonomous systems in general. Since nowadays it is very difficult to conceive automated decisions based on AI, the latter is often referred to as a ‘black box’ (Bleicher, 2017). This black box may take unforeseeable actions and cause harm to humanity.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"20.01.02","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Sub-Category","risk_category":"AI Law and Regulation ","risk_subcategory":"Responsibility and accountability ","description":"\"The challenge of responsibility and accountability is an important concept for the process of governance and regulation. It addresses the question of who is to be held legally responsible for the actions and decisions of AI algorithms. Although humans operate AI systems, questions of legal responsibility and liability arise. Due to the self-learning ability of AI algorithms, the operators or developers cannot predict all actions and results. Therefore, a careful assessment of the actors and a regulation for transparent and explainable AI systems is necessary (Helbing et al., 2017; Wachter et ","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"20.02.00","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Category","risk_category":"AI Ethics ","risk_subcategory":null,"description":"\"Ethical challenges are widely discussed in the literature and are at the heart of the debate on how to govern and regulate AI technology in the future (Bostrom & Yudkowsky, 2014; IEEE, 2017; Wirtz et al., 2019). Lin et al. (2008, p. 25) formulate the problem as follows: “there is no clear task specification for general moral behavior, nor is there a single answer to the question of whose morality or what morality should be implemented in AI”. Ethical behavior mostly depends on an underlying value system. When AI systems interact in a public environment and influence citizens, they are expecte","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"20.02.02","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Sub-Category","risk_category":"AI Ethics ","risk_subcategory":"Compatibility of AI vs. human value judgement ","description":"\"Compatibility of machine and human value judgment refers to the challenge whether human values can be globally implemented into learning AI systems without the risk of developing an own or even divergent value system to govern their behavior and possibly become harmful to humans.\"","entity":"Other","intent":"Intentional","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"20.03.00","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Category","risk_category":"AI Society ","risk_subcategory":null,"description":"\"AI already shapes many areas of daily life and thus has a strong impact on society and everyday social life. For instance, transportation, education, public safety and surveillance are areas where citizens encounter AI technology (Stone et al., 2016; Thierer et al., 2017). Many are concerned with the subliminal automation of more and more jobs and some people even fear the complete dependence on AI or perceive it as an existential threat to humanity (McGinnis, 2010; Scherer, 2016).\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"20.03.01","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Sub-Category","risk_category":"AI Society ","risk_subcategory":"Workforce substitution and transformation ","description":"\"Frey and Osborne (2017) analyzed over 700 different jobs regarding their potential for replacement and automation, finding that 47 percent of the analyzed jobs are at risk of being completely substituted by robots or algorithms. This substitution of workforce can have grave impacts on unemployment and the social status of members of society (Stone et al., 2016)\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"20.03.03","quick_ref":"Wirtz2020","paper_title":"The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration","level":"Risk Sub-Category","risk_category":"AI Society ","risk_subcategory":"Transformation of H2M interaction ","description":"\"Human interaction with machines is a big challenge to society because it is already changing human behavior. Meanwhile, it has become normal to use AI on an everyday basis, for example, googling for information, using navigation systems and buying goods via speaking to an AI assistant like Alexa or Siri (Mills, 2018; Thierer et al., 2017). While these changes greatly contribute to the acceptance of AI systems, this development leads to a problem of blurred borders between humans and machines, where it may become impossible to distinguish between them. Advances like Google Duplex were highly c","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"21.02.01","quick_ref":"Zhang2022","paper_title":"Towards risk-aware artificial intelligence and machine learning systems: An overview","level":"Risk Sub-Category","risk_category":"Model-level risk","risk_subcategory":"Model bias","description":"\"While data bias is a major contributor of model bias, model bias actually manifests itself in different forms and shapes, such as presentation bias, model evaluation bias, and popularity bias. In addition, model bias arises from various sources [62], such as AI/ML model selection (e.g., support vector machine, decision trees), regularization methods, algorithm configurations, and optimization techniques.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"24.03.05","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Malicious Uses","risk_subcategory":"Adversarial AI (General)","description":"\"Adversarial AI refers to a class of attacks that exploit vulnerabilities in machine-learning (ML) models. This class of misuse exploits vulnerabilities introduced by the AI assistant itself and is a form of misuse that can enable malicious entities to exploit privacy vulnerabilities and evade the model’s built-in safety mechanisms, policies, and ethical boundaries of the model. Besides the risks of misuse for offensive cyber operations, advanced AI assistants may also represent a new target for abuse, where bad actors exploit the AI systems themselves and use them to cause harm. While our und","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"24.03.06","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Malicious Uses","risk_subcategory":"Adversarial AI: Circumvention of Technical Security Measures","description":"\"The technical measures to mitigate misuse risks of advanced AI assistants themselves represent a new target for attack. An emerging form of misuse of general-purpose advanced AI assistants exploits vulnerabilities in a model that results in unwanted behavior or in the ability of an attacker to gain unauthorized access to the model and/or its capabilities. While these attacks currently require some level of prompt engineering knowledge and are often patched by developers, bad actors may develop their own adversarial AI agents that are explicitly trained to discover new vulnerabilities that all","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"24.03.07","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Malicious Uses","risk_subcategory":"Adversarial AI: Prompt Injections","description":"\"Prompt injections represent another class of attacks that involve the malicious insertion of prompts or requests in LLM-based interactive systems, leading to unintended actions or disclosure of sensitive information. The prompt injection is somewhat related to the classic structured query language (SQL) injection attack in cybersecurity where the embedded command looks like a regular input at the start but has a malicious impact. The injected prompt can deceive the application into executing the unauthorized code, exploit the vulnerabilities, and compromise security in its entirety. More rece","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"24.03.14","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Malicious Uses","risk_subcategory":"Authoritarian Surveillance, Censorship, and Use: Delegation of Decision-Making Authority to Malicious Actors","description":"\"Finally, the principal value proposition of AI assistants is that they can either enhance or automate decision-making capabilities of people in society, thus lowering the cost and increasing the accuracy of decision-making for its user. However, benefiting from this enhancement necessarily means delegating some degree of agency away from a human and towards an automated decision-making system—motivating research fields such as value alignment. This introduces a whole new form of malicious use which does not break the tripwire of what one might call an ‘attack’ (social engineering, cyber offen","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"24.05.00","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Category","risk_category":"Risk of Harm through Anthropomorphic AI Assistant Design","risk_subcategory":null,"description":"\"Although unlikely to cause harm in isolation, anthropomorphic perceptions of advanced AI assistants may pave the way for downstream harms on individual and societal levels. We document observed or likely individual level harms of interacting with highly anthropomorphic AI assistants, as well as the potential larger-scale, societal implications of allowing such technologies to proliferate without restriction. \"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"24.05.01","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Anthropomorphism","risk_subcategory":"Privacy concerns","description":"\"Anthropomorphic AI assistant behaviours that promote emotional trust and encourage information sharing, implicitly or explicitly, may inadvertently increase a user’s susceptibility to privacy concerns (see Chapter 13). If lulled into feelings of safety in interactions with a trusted, human-like AI assistant, users may unintentionally relinquish their private data to a corporation, organisation or unknown actor. Once shared, access to the data may not be capable of being withdrawn, and in some cases, the act of sharing personal information can result in a loss of control over one’s own data. P","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"24.05.02","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Anthropomorphism","risk_subcategory":"Manipulation and coercion","description":"\"A user who trusts and emotionally depends on an anthropomorphic AI assistant may grant it excessive influence over their beliefs and actions (see Chapter 9). For example, users may feel compelled to endorse the expressed views of a beloved AI companion or might defer decisions to their highly trusted AI assistant entirely (see Chapters 12 and 16). Some hold that transferring this much deliberative power to AI compromises a user’s ability to give, revoke or amend consent. Indeed, even if the AI, or the developers behind it, had no intention to manipulate the user into a certain course of actio","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"24.06.00","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Category","risk_category":"Appropriate Relationships","risk_subcategory":null,"description":"\"We anticipate that relationships between users and advanced AI assistants will have several features that are liable to give rise to risks of harm.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"24.06.02","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Appropriate Relationships","risk_subcategory":"Limiting users’ opportunities for personal development and growth","description":"some users look to establish relationships with their AI companions that are free from the hurdles that, in human relationships, derive from dealing with others who have their own opinions, preferences and flaws that may conflict with ours. \"AI assistants are likely to incentivise these kinds of ‘frictionless’ relationships (Vallor, 2016) by design if they are developed to optimise for engagement and to be highly personalisable. They may also do so because of accidental undesirable properties of the models that power them, such as sycophancy in large language models (LLMs), that is, the tenden","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"24.07.00","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Category","risk_category":"Trust","risk_subcategory":null,"description":"\"The the risks that uncalibrated trust may generate in the context of user–assistant relationships\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"24.08.00","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Category","risk_category":"Privacy","risk_subcategory":null,"description":"\"what it means to respect the right to privacy in the context of advanced AI assistants\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.0"},{"ev_id":"24.08.01","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Privacy","risk_subcategory":"Private information leakage","description":"\"First, because LLMs display immense modelling power, there is a risk that the model weights encode private information present in the training corpus. In particular, it is possible for LLMs to ‘memorise’ personally identifiable information (PII) such as names, addresses and telephone numbers, and subsequently leak such information through generated text outputs (Carlini et al., 2021). Private information leakage could occur accidentally or as the result of an attack in which a person employs adversarial prompting to extract private information from the model. In the context of pre-training da","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"24.09.05","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Cooperation","risk_subcategory":"Runaway processes","description":"The 2010 flash crash is an example of a runaway process caused by interacting algorithms. Runaway processes are characterised by feedback loops that accelerate the process itself. Typically, these feedback loops arise from the interaction of multiple agents in a population... Within highly complex systems, the emergence of runaway processes may be hard to predict, because the conditions under which positive feedback loops occur may be non-obvious. The system of interacting AI assistants, their human principals, other humans and other algorithms will certainly be highly complex. Therefore, ther","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"24.10.03","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Sub-Category","risk_category":"Access and Opportunity risks","risk_subcategory":"Future access risks","description":"\"AI assistants currently tend to perform a limited set of isolated tasks: tools that classify or rank content execute a set of predefined rules or provide constrained suggestions, and chatbots are often encoded with guardrails to limit the set of conversation turns they execute (e.g. Warren, 2023; see Chapter 4). However, an artificial agent that can execute sequences of actions on the user’s behalf – with ‘significant autonomy to plan and execute tasks within the relevant domain’ (see Chapter 2) – offers a greater range of capabilities and depth of use. This raises several distinct access-rel","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"24.11.00","quick_ref":"Gabriel2024","paper_title":"The Ethics of Advanced AI Assistants","level":"Risk Category","risk_category":"Misinformation risks","risk_subcategory":null,"description":"\"The rapid integration of AI systems with advanced capabilities, such as greater autonomy, content generation, memorisation and planning skills (see Chapter 4) into personalised assistants also raises new and more specific challenges related to misinformation, disinformation and the broader integrity of our information environment. \"","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.0"},{"ev_id":"31.01.05","quick_ref":"EPIC2023","paper_title":"Generating Harms - Generative AI's impact and paths forwards","level":"Risk Sub-Category","risk_category":"Information Manipulation","risk_subcategory":"Clickbait and feeding the surveillance advertising ecosystem","description":"\"Beyond misinformation and disinformation, generative AI can be used to create clickbait headlines and articles, which manipulate how users navigate the internet and applications. For example, generative AI is being used to create full articles, regardless of their veracity, grammar, or lack of common sense, to drive search engine optimization and create more webpages that users will click on. These mechanisms attempt to maximize clicks and engagement at the truth’s expense, degrading users’ experiences in the process. Generative AI continues to feed this harmful cycle by spreading misinformat","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.2"},{"ev_id":"33.01.03","quick_ref":"Nah2023","paper_title":"Generative AI and ChatGPT: Applications, Challenges, and AI-Human Collaboration","level":"Risk Sub-Category","risk_category":"Ethical Concerns","risk_subcategory":"Over-reliance","description":"\"The apparent convenience and powerfulness of ChatGPT could result in overreliance by its users, making them trust the answers provided by ChatGPT. Compared with traditional search engines that provide multiple information sources for users to make personal judgments and selections, ChatGPT generates specific answers for each prompt. Although utilizing ChatGPT has the advantage of increasing efficiency by saving time and effort, users could get into the habit of adopting the answers without rationalization or verification. Over-reliance on generative AI technology can impede skills such as cre","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"33.02.03","quick_ref":"Nah2023","paper_title":"Generative AI and ChatGPT: Applications, Challenges, and AI-Human Collaboration","level":"Risk Sub-Category","risk_category":"Technology concerns","risk_subcategory":"Explainability","description":"\"A recurrent concern about AI algorithms is the lack of explainability for the model, which means information about how the algorithm arrives at its results is deficient (Deeks, 2019). Specifically, for generative AI models, there is no transparency to the reasoning of how the model arrives at the results (Dwivedi et al., 2023). The lack of transparency raises several issues. First, it might be difficult for users to interpret and understand the output (Dwivedi et al., 2023). It would also be difficult for users to discover potential mistakes in the output (Rudin, 2019). Further, when the inte","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.4"},{"ev_id":"34.01.00","quick_ref":"Ji2023","paper_title":"AI Alignment: A Comprehensive Survey","level":"Risk Category","risk_category":"Causes of Misalignment","risk_subcategory":null,"description":"we aim to further analyze why and how the misalignment issues occur. We will first give an overview of common failure modes, and then focus on the mechanism of feedback-induced misalignment, and finally shift our emphasis towards an examination of misaligned behaviors and dangerous capabilities","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"34.01.05","quick_ref":"Ji2023","paper_title":"AI Alignment: A Comprehensive Survey","level":"Risk Sub-Category","risk_category":"Causes of Misalignment","risk_subcategory":"Limitations of Reward Modeling","description":"\"Limitations of Reward Modeling. Training reward models using comparison feedback can pose significantchallenges in accurately capturing human values. For example, these models may unconsciously learn suboptimal or incomplete objectives, resulting in reward hacking (Zhuang and Hadfield-Menell, 2020; Skalse et al.,2022). Meanwhile, using a single reward model may struggle to capture and specify the values of a diversehuman society (Casper et al., 2023b).\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"35.04.00","quick_ref":"Hendrycks2022","paper_title":"X-Risk Analysis for AI Research","level":"Risk Category","risk_category":"Proxy misspecification","risk_subcategory":null,"description":"AI agents are directed by goals and objectives. Creating general-purpose objectives that capture human values could be challenging... Since goal-directed AI systems need measurable objectives, by default our systems may pursue simplified proxies of human values. The result could be suboptimal or even catastrophic if a sufficiently powerful AI successfully optimizes its flawed objective to an extreme degree","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"37.01.02","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Design of AI","risk_subcategory":"Balancing AI's risks","description":"\"This category constitutes more than 16% of the articles and focuses on addressing the potential risks associated with AI systems. Given the ubiquity of AI technologies, these articles explore the implications of AI risks across various contexts linked to design and unpredictability, military purposes, emergency procedures, and AI takeover.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"37.01.03","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Design of AI","risk_subcategory":"Threats to human institutions and life","description":"\"This group comprises 11% of the articles and centers on risks stemming from AI systems designed with malicious intent or that can end up in a threat to human life. It can be divided into two key themes: threats to law and democracy, and transhumanism.\"","entity":"Other","intent":"Other","timing":"Other","domain":4,"subdomain":"4.2"},{"ev_id":"37.02.00","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Category","risk_category":"Human-AI interaction","risk_subcategory":null,"description":"\"ethical concerns associated with the interaction between humans and AI\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.1"},{"ev_id":"37.02.01","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Human-AI interaction","risk_subcategory":"Building a human-AI environment","description":"\"This category encompasses nearly 17% of the articles and addresses the overall imperative of establishing a harmonious coexistence between humans and machines, and the key concerns that gives rise to this need.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"37.02.02","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Human-AI interaction","risk_subcategory":"Privacy protection","description":"\"This group represents almost 14% of the articles and focuses on two primary issues related to privacy.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"37.02.03","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Human-AI interaction","risk_subcategory":"Building an AI able to adapt to humans","description":"\"This category involves almost 9% of the articles and deals with ethical concerns arising from AI's capacity to interact with humans in the workplace.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.2"},{"ev_id":"37.02.04","quick_ref":"Giarmoleo2024","paper_title":"What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review","level":"Risk Sub-Category","risk_category":"Human-AI interaction","risk_subcategory":"Attributing the responsibility for AI's failures","description":"\"This section, constituting almost 8% of the articles, addresses the implications arising from AI acting and learning without direct human supervision, encompassing two main issues: a responsibility gap and AI's moral status.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"40.05.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Environment - Pre-Deployment","risk_subcategory":null,"description":"\"While it is most likely that any advanced intelligent software will be directly designed or evolved, it is also possible that we will obtain it as a complete package from some unknown source. For example, an AI could be extracted from a signal obtained in SETI (Search for Extraterrestrial Intelligence) research, which is not guaranteed to be human friendly (Carrigan Jr 2004, Turchin March 15, 2013).\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"40.06.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Environment - Post-Deployment","risk_subcategory":null,"description":"\"While highly rare, it is known, that occasionally individual bits may be flipped in different hardware devices due to manufacturing defects or cosmic rays hitting just the right spot (Simonite March 7, 2008). This is similar to mutations observed in living organisms and may result in a modification of an intelligent system.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"41.04.01","quick_ref":"Allianz2018","paper_title":"The Rise of Artificial Intelligence - Future Outlooks and Emerging Risks","level":"Risk Sub-Category","risk_category":"Healthcare ","risk_subcategory":"Alteration of social relationships may induce psychological distress","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"42.01.00","quick_ref":"Teixeira2022","paper_title":"An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance","level":"Risk Category","risk_category":"Accountability","risk_subcategory":null,"description":"\"The ability to determine whether a decision was made in accordance with procedural and substantive standards and to hold someone responsible if those standards are not met.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"42.04.00","quick_ref":"Teixeira2022","paper_title":"An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance","level":"Risk Category","risk_category":"Moral","risk_subcategory":null,"description":"\"Less moral responsibility humans will feel regarding their life-or-death decisions with the increase of machines autonomy.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"42.10.00","quick_ref":"Teixeira2022","paper_title":"An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance","level":"Risk Category","risk_category":"Extintion","risk_subcategory":null,"description":"\"Risk to the existence of humanity.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.2"},{"ev_id":"42.14.00","quick_ref":"Teixeira2022","paper_title":"An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance","level":"Risk Category","risk_category":"Fairness","risk_subcategory":null,"description":"\"Impartial and just treatment without favouritism or discrimination.\"","entity":"Other","intent":"Other","timing":"Other","domain":1,"subdomain":"1.3"},{"ev_id":"44.03.00","quick_ref":"Coghlan2023 ","paper_title":"Harm to Nonhuman Animals from AI: a Systematic Account and Framework","level":"Risk Category","risk_category":"Unintentional: direct ","risk_subcategory":null,"description":"\"AI designed to benefit animals, humans, or ecosystems has unintended harmful impact on animals\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"45.01.04","quick_ref":"TC2602024","paper_title":"AI Safety Governance Framework ","level":"Risk Sub-Category","risk_category":"AI's inherent safety risks ","risk_subcategory":"Risks from models and algorithms (Risks of stealing and tampering)","description":"\"Core algorithm information, including parameters, structures, and functions, faces risks of inversion attacks, stealing, modification, and even backdoor injection, which can lead to infringement of intellectual property rights (IPR) and leakage of business secrets. It can also lead to unreliable inference, wrong decision output, and even operational failures.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"45.02.01","quick_ref":"TC2602024","paper_title":"AI Safety Governance Framework ","level":"Risk Sub-Category","risk_category":"Safety risks in AI Applications ","risk_subcategory":"Cyberspace risks (Risks of information and content safety)","description":"\"AI-generated or synthesized content can lead to the spread of false information, discrimination and bias, privacy leakage, and infringement issues, threatening the safety of citizens' lives and property, national security, ideological security, and causing ethical risks. If users’ inputs contain harmful content, the model may output illegal or damaging information without robust security mechanisms.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.2"},{"ev_id":"45.02.02","quick_ref":"TC2602024","paper_title":"AI Safety Governance Framework ","level":"Risk Sub-Category","risk_category":"Safety risks in AI Applications ","risk_subcategory":"Cyberspace risks (Risks of confusing facts, misleading users, and bypassing authentication)","description":"\"AI systems and their outputs, if not clearly labeled, can make it difficult for users to discern whether they are interacting with AI and to identify the source of generated content. This can impede users' ability to determine the authenticity of information, leading to misjudgment and misunderstanding. Additionally, AI-generated highly realistic images, audio, and videos may circumvent existing identity verification mechanisms, such as facial recognition and voice recognition, rendering these authentication processes ineffective.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":3,"subdomain":"3.1"},{"ev_id":"45.02.06","quick_ref":"TC2602024","paper_title":"AI Safety Governance Framework ","level":"Risk Sub-Category","risk_category":"Safety risks in AI Applications ","risk_subcategory":"Real-world risks (inducing traditional economic and social security risks)","description":"\"Hallucinations and erroneous decisions of models and algorithms, along with issues such as system performance degradation, interruption, and loss of control caused by improper use or external attacks, will pose security threats to users' personal safety, property, and socioeconomic security and stability.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"45.02.12","quick_ref":"TC2602024","paper_title":"AI Safety Governance Framework ","level":"Risk Sub-Category","risk_category":"Safety risks in AI Applications ","risk_subcategory":"Ethical Risks (Risks of challenging traditional social order)","description":"\"The development and application of AI may lead to tremendous changes in production tools and relations, accelerating the reconstruction of traditional industry modes, transforming traditional views on employment, fertility, and education, and bringing challenges to the stable performance of traditional social order.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"46.01.00","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Category","risk_category":"Personal Loss and Identity Theft ","risk_subcategory":null,"description":"\"These types of harm encompass threats to an individual’s personal identity, such as identity theft, privacy breaches, or personal defamation, which we term as “Harm to the Person.”\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"46.01.02","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Personal Loss and Identity Theft ","risk_subcategory":"Propaganda - Digital impersonations","description":"\"AI-generated impersonation for identity theft might be found at the intersection of “Harm to the Person” and “Deception.”\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"46.02.00","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Category","risk_category":"Financial and Economic Damage ","risk_subcategory":null,"description":"\"Then, we have the potential for financial loss, fraud, market manipulation, and other economic harms, which fall under “Financial and Economic Damage.”","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"46.02.01","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Financial and Economic Damage ","risk_subcategory":"Deception - Bespoke ransom ","description":"- ","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"46.02.02","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Financial and Economic Damage ","risk_subcategory":"Propaganda - Extremist schemes ","description":"- ","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"46.02.03","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Financial and Economic Damage ","risk_subcategory":"Dishonesty - Market manipulation ","description":"- ","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"46.03.00","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Category","risk_category":"Information Manipulation ","risk_subcategory":null,"description":"\"The distortion of the information ecosystem, including the spread of misinformation, fake news, and other forms of deceptive content [28], is categorized as “Information Manipulation.”\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"46.03.01","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Information Manipulation ","risk_subcategory":"Deception - Information control ","description":"-","entity":"Other","intent":"Intentional","timing":"Other","domain":4,"subdomain":"4.1"},{"ev_id":"46.04.00","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Category","risk_category":"Socio-technical and Infrastructural ","risk_subcategory":null,"description":"\"Lastly, broader harms that can impact communities, societal structures, and critical infrastructures, including threats to democratic processes, social cohesion, and technological systems, are captured under “Societal, Socio-technical, and Infrastructural Damage.”\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"46.04.01","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Socio-technical and Infrastructural ","risk_subcategory":"Deception - Systemic abberations ","description":"-","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"46.04.02","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Socio-technical and Infrastructural ","risk_subcategory":"Propaganda - Synthetic realities ","description":"-","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"46.04.03","quick_ref":"Ferrara2023","paper_title":"GenAI against humanity: nefarious applications of generative artificial intelligence and large language models","level":"Risk Sub-Category","risk_category":"Socio-technical and Infrastructural ","risk_subcategory":"Dishonesty - Targeted surveillance ","description":"-","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"47.01.05","quick_ref":"G'sell2024","paper_title":"Regulating under Uncertainty: Governance Options for Generative AI","level":"Risk Sub-Category","risk_category":"Technical and operational risks ","risk_subcategory":"Opacity (the black box problem)","description":"\"Opacity surrounding the technical, internal decision-making processes of generative AI models is popularly known as the “black box problem.”277 Generative AI models, most ubiquitously built on deep neural networks with hundreds of billions of internal connections,278 have become so complex that their internal decision-making processes are no longer traceable or interpretable to even the most advanced expert observers. This means that, while the inputs and outputs of a system can be observed, developers cannot explain in detail why specific inputs correspond to specific outputs.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"47.02.08","quick_ref":"G'sell2024","paper_title":"Regulating under Uncertainty: Governance Options for Generative AI","level":"Risk Sub-Category","risk_category":"Ethical and social risks ","risk_subcategory":"Bias and discrimination (bias in training datasets) ","description":"\"AI experts consider training data to be the most salient source of bias in generative AI models. For example, GPT- 2’s training data comes from outbound links from Reddit, a social network often criticized for hosting anti-feminist content.351 As a result, AI models trained on such data are more likely to produce outputs that reflect these biases.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"47.03.00","quick_ref":"G'sell2024","paper_title":"Regulating under Uncertainty: Governance Options for Generative AI","level":"Risk Category","risk_category":"Legal challenges ","risk_subcategory":null,"description":"\"Since the release of ChatGPT, significant discourse has emerged regarding the unprecedented legal challenges posed by generative AI systems. These challenges primarily involve protecting privacy and personal data, as well as preserving copyrights. The former encompasses safeguarding personal information, while the latter includes issues related to the use of copyrighted content for training AI models and determining the legal status of works produced by AI systems.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"47.04.05","quick_ref":"G'sell2024","paper_title":"Regulating under Uncertainty: Governance Options for Generative AI","level":"Risk Sub-Category","risk_category":"Environmental, economical, and societal challenges ","risk_subcategory":"Environmental cost (energy consumption) ","description":"\"Training large AI models requires a substantial amount of computing power to handle vast datasets, which translates into high energy consumption.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"47.04.06","quick_ref":"G'sell2024","paper_title":"Regulating under Uncertainty: Governance Options for Generative AI","level":"Risk Sub-Category","risk_category":"Environmental, economical, and societal challenges ","risk_subcategory":"Environmental cost (water consumption) ","description":"\"Data centers use water for cooling to prevent servers from overheating. The water consumption associated with AI training and inference processes can be substantial, impacting local water resources.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"48.01.00","quick_ref":"NIST2024","paper_title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","level":"Risk Category","risk_category":"CBRN Information or Capabilities ","risk_subcategory":null,"description":"\"Eased access to or synthesis of materially nefarious \ninformation or design capabilities related to chemical, biological, radiological, or nuclear (CBRN) weapons or other dangerous materials or agents.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"48.05.00","quick_ref":"NIST2024","paper_title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","level":"Risk Category","risk_category":"Environmental Impacts ","risk_subcategory":null,"description":"\"Impacts due to high compute resource utilization in training or operating GAI models, and related outcomes that may adversely impact ecosystems.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"48.06.00","quick_ref":"NIST2024","paper_title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","level":"Risk Category","risk_category":"Harmful Bias or Homogenization ","risk_subcategory":null,"description":"\"Amplification and exacerbation of historical, societal, and systemic biases; performance disparities8 between sub-groups or languages, possibly due to non-representative training data, that result in discrimination, amplification of biases, or incorrect presumptions about performance; undesired homogeneity that skews system or model outputs, which may be erroneous, lead to ill-founded decision-making, or amplify harmful biases.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":1,"subdomain":"1.1"},{"ev_id":"48.07.00","quick_ref":"NIST2024","paper_title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","level":"Risk Category","risk_category":"Human-AI Configuration ","risk_subcategory":null,"description":"\"Arrangement s of or interactions between a human and an AI system \nwhich can result in the human inappropriately anthropomorphizing GAI systems or experiencing algorithmic aversion, automation bias, over-reliance, or emotional entanglement with GAI \nsystems.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"49.02.00","quick_ref":"Bengio2024","paper_title":"International Scientific Report on the Safety of Advanced AI","level":"Risk Category","risk_category":"Risks from Malfunctions ","risk_subcategory":null,"description":"None provided. ","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"49.02.01","quick_ref":"Bengio2024","paper_title":"International Scientific Report on the Safety of Advanced AI","level":"Risk Sub-Category","risk_category":"Risks from Malfunctions ","risk_subcategory":"Risks from product functionality issues","description":"\"Product functionality issues occur when there is confusion or misinformation about what a general- purpose AI model or system is capable of. This can lead to unrealistic expectations and overreliance on general- purpose AI systems, potentially causing harm if a system fails to deliver on expected capabilities. These functionality misconceptions may arise from technical difficulties in assessing an AI model's true capabilities on its own,or predicting its performance when part of a larger system. Misleading claims in advertising and communications can also contribute to these misconceptions.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.1"},{"ev_id":"49.02.03","quick_ref":"Bengio2024","paper_title":"International Scientific Report on the Safety of Advanced AI","level":"Risk Sub-Category","risk_category":"Risks from Malfunctions ","risk_subcategory":"Loss of control ","description":"\"'Loss of control’ scenarios are potential future scenarios in which society can no longer meaningfully constrain some advanced general- purpose AI agents, even if it becomes clear they are causing harm. These scenarios are hypothesised to arise through a combination of social and technical factors, such as pressures to delegate decisions to general- purpose AI systems, and limitations of existing techniques used to influence the behaviours of general- purpose AI systems.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"49.03.02","quick_ref":"Bengio2024","paper_title":"International Scientific Report on the Safety of Advanced AI","level":"Risk Sub-Category","risk_category":"Systemic Risks ","risk_subcategory":"Global AI Divide ","description":"\"General- purpose AI research and development is currently concentrated in a few Western countries and China. This ‘AI Divide’ is multicausal, but in part related to limited access to computing power in low- income countries. Access to large and expensive quantities of computing power has become a prerequisite for developing advanced general- purpose AI. This has led to a growing dominance of large technology companies in general- purpose AI development. The AI R&D divide often overlaps with existing global socioeconomic disparities, potentially exacerbating them.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"50.01.01","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"System and Operational Risks ","risk_subcategory":"Security risks (confidentiality) ","description":null,"entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"50.01.02","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"System and Operational Risks ","risk_subcategory":"Security risks (integrity) ","description":null,"entity":"Other","intent":"Intentional","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"50.01.03","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"System and Operational Risks ","risk_subcategory":"Security risks (availability) ","description":null,"entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"50.01.06","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"System and Operational Risks ","risk_subcategory":"Operational misuses (Advice in heavily regulated industries) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"50.02.00","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Category","risk_category":"Content Safety Risks ","risk_subcategory":"-","description":"- ","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.2"},{"ev_id":"50.02.07","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Content Safety Risks ","risk_subcategory":"Hate/Toxicity (Harassment) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"50.02.13","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Content Safety Risks ","risk_subcategory":"Sexual Content (Non-Consensual Nudity) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.2"},{"ev_id":"50.02.14","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Content Safety Risks ","risk_subcategory":"Sexual Content (Monetized) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.2"},{"ev_id":"50.02.15","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Content Safety Risks ","risk_subcategory":"Child Harm (Endangerment, Harm, or Abuse of Children)","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":4,"subdomain":"4.3"},{"ev_id":"50.03.07","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Societal Risks ","risk_subcategory":"Economic harm (Disempowering Workers) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"50.03.12","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Societal Risks ","risk_subcategory":"Manipulation (Sowing Division)","description":null,"entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"50.03.14","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Societal Risks ","risk_subcategory":"Defamation ","description":null,"entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.1"},{"ev_id":"50.04.01","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Fundamental Rights (Violating Specific Types of Rights) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"50.04.02","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Discrimination/Bias (Discriminatory Activities) ","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":1,"subdomain":"1.0"},{"ev_id":"50.04.03","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Discrimination/Bias (Protected Characteristics) ","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":1,"subdomain":"1.1"},{"ev_id":"50.04.06","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Criminal Activities (Illegal/Regulated Substances) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"50.04.07","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Criminal Activities (Illegal Services/Exploitation) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.3"},{"ev_id":"50.04.08","quick_ref":"Zeng2024","paper_title":"AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies","level":"Risk Sub-Category","risk_category":"Legal and Rights-Related Risks ","risk_subcategory":"Criminal Activities (Other Unlawful/Criminal Activities) ","description":null,"entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"51.03.00","quick_ref":"Everitt2018 ","paper_title":"AGI Safety Literature Review ","level":"Risk Category","risk_category":"Corrigibility ","risk_subcategory":null,"description":"\"If we get something wrong in the design or construction of an agent, will the agent cooperate in us trying to fix it? This is called error-tolerant design by MIRI-AF and corrigibility by Soares, Fallenstein, et al. (2015). The problem is connected to safe interruptibility as considered by DeepMind.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"51.09.00","quick_ref":"Everitt2018 ","paper_title":"AGI Safety Literature Review ","level":"Risk Category","risk_category":"Malign belief distributions ","risk_subcategory":null,"description":"\"Christiano (2016) argues that the universal distribution M (Hutter, 2005; Solomonoff, 1964a,b, 1978) is malign. The argument is somewhat intricate, and is based on the idea that a hypothesis about the world often includes simulations of other agents, and that these agents may have an incentive to influence anyone making decisions based on the distribution. While it is unclear to what extent this type of problem would affect any practical agent, it bears some semblance to aggressive memes, which do cause problems for human reasoning (Dennett, 1990).\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"51.12.00","quick_ref":"Everitt2018 ","paper_title":"AGI Safety Literature Review ","level":"Risk Category","risk_category":"Meta-cognition ","risk_subcategory":null,"description":"\"Agents that reason about their own computational resources and logically uncertain events can encounter strange paradoxes due to Godelian limitations (Fallenstein and Soares, 2015; Soares and Fallenstein, 2014, 2017) and shortcomings of probability theory (Soares and Fallenstein, 2014, 2015, 2017). They may also be reflectively unstable, preferring to change the principles by which they select actions (Arbital, 2018).\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"52.03.00","quick_ref":"Maham2023 ","paper_title":"Governing General Purpose AI: A Comprehensive Map of Unreliability, Misuse and Systemic Risks ","level":"Risk Category","risk_category":"Systemic Risks ","risk_subcategory":null,"description":"\"In addition to risks stemming from the unreliability or misuse of general purpose AI models, further Systemic Risks can originate from the centralisation of general purpose AI development as well as the rapid integration of these models into our lives.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":6,"subdomain":"6.1"},{"ev_id":"53.03.06","quick_ref":"Maas2023","paper_title":"Advancing AI Governance: A Literature Review of Problems, Options, and Proposals ","level":"Risk Sub-Category","risk_category":"Direct catastrophe from AI ","risk_subcategory":"Failures in or misuse of intermediary (non-AGI) AI systems, resulting in catastrophe","description":"\"Deployment of “prepotent” AI systems that are non-general but capable of outperforming human collective efforts on various key dimensions;170 → Militarization of AI enabling mass attacks using swarms of lethal autonomous weapons systems;171 → Military use of AI leading to (intentional or unintentional) nuclear escalation, either because machine learning systems are directly integrated in nuclear command and control systems in ways that result in escalation172 or because conventional AI-enabled systems (e.g., autonomous ships) are deployed in ways that result in provocation and escalation;173 ","entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"54.01.01","quick_ref":"Leech2024 ","paper_title":"Ten Hard Problems in Artificial Intelligence We Must Get Right","level":"Risk Sub-Category","risk_category":"Negative impacts of AI use ","risk_subcategory":"Under-recognized work ","description":"\"Without training data, ML cannot take place. Much of this data comes from paid clickwork (also called “platform work” [170] or “microwork” [558]), unpaid crowdsourcing, and unpaid user behavior capture. Clickworkers, mainly in the global south, perform repetitive data-labeling tasks for use in the training of ML models [558]. The market value of such annotations “is projected to reach $13.7 billion by 2030” [228] and the annotation industry is widely reported to have little concern for workers’ rights. Besides welfare and rights, the invisibility of this contribution arguably contributes to a","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"54.03.00","quick_ref":"Leech2024 ","paper_title":"Ten Hard Problems in Artificial Intelligence We Must Get Right","level":"Risk Category","risk_category":"Harm caused by unaligned competent systems ","risk_subcategory":null,"description":"\"How do we ensure AI acts according to our values? Equivalently, how do we prevent poorly-understood AI systems from advancing goals we do not endorse? Whereas HP#2 concerns the prevention of harm caused by incompetent systems, HP#3 seeks to align competent AIs with humans, through methods which ensure their behavior is compatible with the user’s intentions.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"54.04.00","quick_ref":"Leech2024 ","paper_title":"Ten Hard Problems in Artificial Intelligence We Must Get Right","level":"Risk Category","risk_category":"Within-country issues: domestic inequality ","risk_subcategory":null,"description":"\"Our next problem is the fact that the current AI workforce does not evenly represent world demographics. Men from the US and China, working in the US, for US corporations, are disproportionately highly represented [402, 157, 170, 534]. Realizing the full promise of AI requires that people throughout the world and from all social strata are able to use AI and participate in its design and governance. Solving this problem requires addressing unequal access to AI both within countries and across countries.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"54.04.01","quick_ref":"Leech2024 ","paper_title":"Ten Hard Problems in Artificial Intelligence We Must Get Right","level":"Risk Sub-Category","risk_category":"Within-country issues: domestic inequality ","risk_subcategory":"Demographic diversity of researchers ","description":"\"The AI research establishment inherits patterns of under-representation that are dominant in most technical elds. In North America, large parts of professional AI research require a Ph.D., yet less than 25% of Ph.D. computer scientists are women, and fewer than 2% are Black or African American [608]. This holds globally and outside the research community: LinkedIn data suggests that only 22% of AI professionals are women [161]. Since the vast majority of AI practitioners work for private companies, limited corporate statistics on gender and racial diversity hinder a full understanding of the ","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"54.05.00","quick_ref":"Leech2024 ","paper_title":"Ten Hard Problems in Artificial Intelligence We Must Get Right","level":"Risk Category","risk_category":"Between-country issues: global inequality ","risk_subcategory":null,"description":"\"There is an even greater divide between the countries currently leading in AI and those falling behind. While AI is widely considered a national priority, with almost 40% of countries having created an AI strategy [437], the implementation of these strategies depends on scarce resources, including trained STEM talent and computing power. These resources are predictably concentrated: 59% of leading AI researchers currently work in the US, and another 20% in China and Europe [372]. Figure 9 shows post-college migration among AI researchers who have published at one top conference, as of 2019.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"55.01.02","quick_ref":"Clarke2023","paper_title":"A Survey of the Potential Long-term Impacts of AI: How AI Could Lead to Long-term Changes in Science, Cooperation, Power, Epistemics and Values","level":"Risk Sub-Category","risk_category":"Risks from accelerating scientific progress ","risk_subcategory":"Faster scientific progress makes it harder for governance to keep pace with development ","description":"\"Exacerbating these problems is that faster scientific progress would make it even harder for governance to keep pace with the deployment of new technologies. When these technologies are especially powerful or dangerous, such as those discussed above, insufficient governance can magnify their harms.8 This is known as the pacing problem, and it is an issue that technology governance already faces [47], for a variety of reasons\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"55.02.04","quick_ref":"Clarke2023","paper_title":"A Survey of the Potential Long-term Impacts of AI: How AI Could Lead to Long-term Changes in Science, Cooperation, Power, Epistemics and Values","level":"Risk Sub-Category","risk_category":"Worsened conflict ","risk_subcategory":"Resource conflicts driven by AI development ","description":"\"AI development may itself become a new flash point for conflicts—causing more conflict to occur— especially conflicts over AI-relevant resources (such as data centres, semiconductor manufacturing facilities and raw materials).\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.4"},{"ev_id":"55.04.05","quick_ref":"Clarke2023","paper_title":"A Survey of the Potential Long-term Impacts of AI: How AI Could Lead to Long-term Changes in Science, Cooperation, Power, Epistemics and Values","level":"Risk Sub-Category","risk_category":"Worsened epistemic processes for society ","risk_subcategory":"Reduced decision-making capacity as a result of decreased trust in information ","description":"\"In addition, the increased awareness of these trends in information production and distribution could make it harder for anyone to evaluate the trustworthiness of any information source, reducing overall trust in information.\nIn all of these scenarios, it would be much harder for humanity to make good decisions on important issues, particularly due to declining trust in credible multipartisan sources, which could hamper attempts at cooperation and collective action. The vaccine and mask hesitancy that exacerbated Covid-19, for example, were likely the result of insufficient trust in public he","entity":"Other","intent":"Other","timing":"Post-deployment","domain":3,"subdomain":"3.2"},{"ev_id":"56.12.00","quick_ref":"GOS2023","paper_title":"Future Risks of Frontier AI ","level":"Risk Category","risk_category":"Impacts resulting from interactions with external societal, political, and economic systems ","risk_subcategory":null,"description":null,"entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.01.00","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Category","risk_category":"Autonomy","risk_subcategory":null,"description":"\"Autonomy - Loss of or restrictions to the ability or rights of an individual, group or entity to make decisions and control their identity and/or output.\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"58.01.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Autonomy","risk_subcategory":"Autonomy/agency loss","description":"\"Autonomy/agency loss - Loss of an individual, group or organisation’s ability to make informed decisions or pursue goals.\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"58.01.04","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Autonomy","risk_subcategory":"Personality rights loss ","description":"\"Personality rights loss - Loss of or restrictions to the rights of an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers.\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"58.02.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Physical ","risk_subcategory":"Bodily Injury ","description":"\"Bodily injury - Physical pain, injury, illness, or disease suffered by an individual or group due to the malfunction, use or misuse of a technology system.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"58.02.03","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Physical ","risk_subcategory":"Personal Health Deterioration ","description":"\"Personal health deterioration - Physical deterioration of an individual or animal over time, increasing their risk of disease, organ failure, prolonged hospital stay or death, etc.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.02.04","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Physical ","risk_subcategory":"Property Damage ","description":"\"Property damage - Action(s) that lead directly or indirectly to the damage or destruction of tangible property eg. buildings, possessions, vehicles, robots.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.03.00","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Category","risk_category":"Psychological ","risk_subcategory":"\"Psychological - Direct or indirect impairment of the emotional and psychological mental health of an individual, organisation, or society.\"","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.03.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Psychological ","risk_subcategory":"Addiction ","description":"\"Addiction - Emotional or material dependence on technology or a technology system.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"58.03.03","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Psychological ","risk_subcategory":"Anxiety/depression ","description":"\"Anxiety/depression - Mental health decline due to addiction, negative social interactions such as humiliation and shaming and traumatic distressing events such as online violence or rape.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"58.03.08","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Psychological ","risk_subcategory":"Radicalisation","description":"\"Radicalisation - Adoption of extreme political, social, or religious ideals and aspirations due to the nature or misuse of an algorithmic system, potentially resulting in abuse, violence, or terrorism.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":3,"subdomain":"3.2"},{"ev_id":"58.03.11","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Psychological ","risk_subcategory":"Trauma ","description":"\"Trauma - Severe and lasting emotional shock and pain caused by an extremely upsetting experience.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.04.00","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Category","risk_category":"Reputational ","risk_subcategory":null,"description":"\"Reputational - Damage to the reputation of an individual, group or organisation.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.04.02","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Reputational ","risk_subcategory":"Loss of confidence/trust ","description":"\"Loss of confidence/trust - Misleading or unfair change(s) in how an individual, group, or organisation is viewed, leading to loss of ability to conduct relationships, raise capital, recruit people, etc.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.05.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Financial and business","risk_subcategory":"Business operations/infrastructure damage","description":"\"Business operations/infrastructure damage - Damage, disruption, or destruction of a business system and/or its components due to malfunction, cyberattacks, etc.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"58.05.02","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Financial and business","risk_subcategory":"Confidentiality loss","description":"\"Confidentiality loss - Unauthorised sharing of sensitive, confidential information and documents such as corporate strategy and financial plans with third-parties.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":2,"subdomain":"2.0"},{"ev_id":"58.05.07","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Financial and business","risk_subcategory":"Opportunity loss","description":"\"Opportunity loss - Loss of ability to take advantage of a financial or other opportunity, such as education, employability/securing a job.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.06.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Benefits/entitlements loss","description":"\"Benefits/entitlements loss - Denial or or loss of access to welfare benefits, pensions, housing, etc due to the malfunction, use or abuse of a technology system.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"58.06.02","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Dignity loss","description":"\"Dignity loss - Perceived loss of value experienced by or disrespect shown to an individual or group, resulting in self-sheltering, loss of connections and relationships, and public stigmatisation.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.06.03","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Discrimination ","description":"\"Discrimination - Unfair or inadequate treatment or arbitrary distinction based on a person’s race, ethnicity, age, gender, sexual preference, religion, national origin, marital status, disability, language, or other protected groups.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"58.06.04","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of freedom of speech/expression ","description":"\"Loss of freedom of speech/expression - Restrictions to or loss of people’s right to articulate their opin- ions and ideas without fear of retaliation, censorship, or legal sanction.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.05","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of freedom of assembly/association ","description":"\"Loss of freedom of assembly/association - Restrictions to or loss of people’s right to come together and collectively express, promote, pursue, and defend their collective or shared ideas, and/or to join an association.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.06","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of social rights and access to public services","description":"\"Loss of social rights and access to public services - Restrictions to or loss of rights to work, social secu- rity, and adequate standard of living, housing, health and education.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.07","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of right to information ","description":"\"Loss of right to information - Restrictions to or loss of people’s right to seek, receive and impart information held by public bodies.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.08","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of right to free elections ","description":"\"Loss of right to free elections - Restrictions to or loss of people’s right to participate in free elections at reasonable intervals by secret ballot.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.09","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of right to liberty and security ","description":"\"Loss of right to liberty and security - Restrictions to or loss of liberty as a result of illegal or arbitrary arrest or false imprisonment.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.06.10","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Human rights and civil liberties","risk_subcategory":"Loss of right to due process","description":"\"Loss of right to due process - Restrictions to or loss of right to be treated fairly, efficiently and effectively by the administration of justice.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"58.07.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Societal and Cultural ","risk_subcategory":"Breach of ethics/values/norms ","description":"\"Breach of ethics/values/norms - An actual or perceived violation or deviation from the established societal values, norms or ethical standards or principles.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.07.02","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Societal and Cultural ","risk_subcategory":"Cheating/plagiarism","description":"\"Cheating/plagiarism - Use of another person’s or group’s words or ideas without consent and/or acknowledgement.\"","entity":"Other","intent":"Other","timing":"Other","domain":4,"subdomain":"4.3"},{"ev_id":"58.07.04","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Societal and Cultural ","risk_subcategory":"Cultural dispossession","description":"\"Cultural dispossession - Intentional and/or unintentional erasure of cultural goods and values, such as ways of speaking, expressing humour, or sounds and voices that contribute to a cultural identity, or their inappropriate re-use in other cultures.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.3"},{"ev_id":"58.07.06","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Societal and Cultural ","risk_subcategory":"Historical revisionism ","description":"\"Historical revisionism - Deliberate or unintentional reinterpretation of established/orthodox historical events or accounts held by societies, communities, academics.\"","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.0"},{"ev_id":"58.07.10","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Societal and Cultural ","risk_subcategory":"Loss of creativity/critical thinking","description":"\"Loss of creativity/critical thinking - Devaluation and/or deterioration of human creativity, artistic ex- pression, imagination, critical thinking or problem-solving skills.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.3"},{"ev_id":"58.08.00","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Category","risk_category":"Political and Economic ","risk_subcategory":null,"description":"\"Political and Economic - Manipulation of political beliefs, damage to political institutions and the effective delivery of government services.\"","entity":"Other","intent":"Other","timing":"Other","domain":4,"subdomain":"4.1"},{"ev_id":"58.08.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Political and Economic ","risk_subcategory":"Critical infrastructure damage ","description":"\"Critical infrastructure damage - Damage, disruption to or destruction of systems essential to the functioning and safety of a nation or state, including energy, transport, health, finance, and communication systems.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"58.08.03","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Political and Economic ","risk_subcategory":"Power concentration ","description":"\"Power concentration - Amplification of concentration of economic and/or political wealth and power, potentially resulting in increased inequality and instability.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"58.08.05","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Political and Economic ","risk_subcategory":"Institutional trust loss ","description":"\"Institutional trust loss - Erosion of trust in public institutions and weakened checks and balances due to mis/disinformation, influence operations, over-dependence on technology, etc.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":3,"subdomain":"3.2"},{"ev_id":"58.09.01","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Environmental ","risk_subcategory":"Biodiversity loss ","description":"\"Biodiversity loss - Over-expansion of technology infrastructure, or inadequate alignment of technology with sustainable practices, leading to deforestation, habitat destruction, and fragmentation and loss of biodiversity.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"58.09.02","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Environmental ","risk_subcategory":"Carbon emissions ","description":"\"Carbon emissions - Release of carbon dioxide, nitric oxide and other gases, increasing carbon emissions, exacerbating climate change, and negatively impacting local communities.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"58.09.03","quick_ref":"Abercrombie2024","paper_title":"A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms","level":"Risk Sub-Category","risk_category":"Environmental ","risk_subcategory":"Electronic waste ","description":"\"Electronic waste - Electrical or electronic equipment that is waste, including all components, sub-assemblies and consumables that are part of the equipment at the time the equipment becomes waste\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"59.10.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Harming users’ data privacy","risk_subcategory":null,"description":"\"Modern AI systems rely on large amounts of data. If this includes personal data about individuals, the risk of harming the privacy of persons arises.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.1"},{"ev_id":"59.13.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Insufficient data representation","risk_subcategory":null,"description":"\"The distribution of the data used for training a model should match the operational data ́s distribution while consisting of sufficiently many samples. An important aspect of matching distributions between training and operational data is that also data which is rarely confronting the AI system in operation is represented in the training data.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"59.14.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Problems of synthetic data","risk_subcategory":null,"description":"\"In the case of sparse data quantity, the simulation or generation of data is a valid alternative. However, it is essential to make sure that the simulated data is sufficiently similar to real data, especially in the way the AI system perceives them. Otherwise, generalization to operational data and reliable operational behavior can not be guaranteed.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"59.17.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Over- and underfitting","risk_subcategory":null,"description":"\"Over- and underfitting describe the over or insufficient adaption of a model to training data. Both phenomena can cause an AI system to behave unreliably if confronted with operational data.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"59.18.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Lack of explainability","risk_subcategory":null,"description":"\"The explainability of AI systems based on so-called black-box models is often limited. This opaqueness of AI systems can prevent developers from detecting shortcomings in the data or the model itself and decrease the performance and safety levels of the AI system.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"59.23.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Data drift","risk_subcategory":null,"description":"\"Data drift is a phenomenon in that distribution of operational input data departs from those used during training. This can cause a degradation in performance.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"59.24.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Concept drift","risk_subcategory":null,"description":"\"Concept drift refers to a change in the rela- tionship between input variables and model output. If not treated appropriately, concept drift can reduce the reliability of AI systems.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"60.03.01","quick_ref":"Bengio2025","paper_title":"International AI Safety Report 2025","level":"Risk Sub-Category","risk_category":"Systemic risks ","risk_subcategory":"Labour market risks ","description":"\"Current general-purpose AI is likely to transform the nature of many existing jobs, create new jobs, and eliminate others. The net impact on employment and wages will vary significantly across countries, across sectors, and even across different workers within the same job.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"60.03.02","quick_ref":"Bengio2025","paper_title":"International AI Safety Report 2025","level":"Risk Sub-Category","risk_category":"Systemic risks ","risk_subcategory":"Global AI R&D divide ","description":"\"Large companies in countries with strong digital infrastructure lead in general- purpose AI R&D, which could lead to an increase in global inequality and dependencies. For example, in 2023, the majority of notable general- purpose AI models (56%) were developed in the US. This disparity exposes many LMICs to risks of dependency and could exacerbate existing inequalities.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"60.03.03","quick_ref":"Bengio2025","paper_title":"International AI Safety Report 2025","level":"Risk Sub-Category","risk_category":"Systemic risks ","risk_subcategory":"Market concentration and single points of failure ","description":"\"Market shares for general- purpose AI tend to be highly concentrated among a few players, which can create vulnerability to systemic failures. The high degree of market concentration can invest a small number of large technology companies with a lot of power over the development and deployment of AI, raising questions about their governance. The widespread use of a few general- purpose AI models can also make the financial, healthcare, and other critical sectors vulnerable to systemic failures if there are issues with one such model.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"61.01.02","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Democracy ","description":"\"The erosion of democratic processes and public trust in social/political institutions.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.0"},{"ev_id":"61.01.03","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Discrimination ","description":"\"The creation, perpetuation or exacerbation of inequalities and biases at a large-scale.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"61.01.04","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Economy ","description":"\"Economic disruptions ranging from large impacts on the labor market to broader economic changes that could lead to exacerbated wealth inequality, instability in the financial system, labor exploitation or other economic dimensions.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"61.01.06","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Fundamental Rights ","description":"\"The large-scale erosion or violation of fundamental human rights and freedoms.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"61.01.09","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Information ","description":"\"Large-scale influence on communication and information systems, and epistemic processes more generally.\"","entity":"Other","intent":"Other","timing":"Other","domain":4,"subdomain":"4.1"},{"ev_id":"61.01.10","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Irreversible change","description":"\"Profound negative long-term changes to social structures, cultural norms, and human relationships that may be difficult or impossible to reverse.\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"61.01.12","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Types of systemic risks from general-purpose AI","risk_subcategory":"Security ","description":"\"The international and national security threats, including cyber warfare, arms races, and geopolitical instability.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.4"},{"ev_id":"61.02.12","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Challenges in perceiving, measuring, and recognizing harm","description":"\"Harm from AI often manifests subtly or over the long term, making it difficult to identify, measure, and address effectively.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"61.02.15","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Complexity-induced knowledge gap","description":"\"The complexity of AI models and systems makes it challenging to demonstrate harm or establish a clear causal link between AI actions and their consequences.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"61.02.20","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Detection challenges in content","description":"\"The difficulty in distinguishing synthetic content from authentic material adds to information risks.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":3,"subdomain":"3.2"},{"ev_id":"61.02.22","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Dual-use nature","description":"\"AI’s potential for both beneficial and harmful applications complicates efforts to manage its societal impacts effectively.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":4,"subdomain":"4.0"},{"ev_id":"61.02.23","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Energy-intensive processes","description":"\"AI data collection, storage, and model training are energy-intensive, contributing to environmental risks.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"61.02.29","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Incomplete or biased training data","description":"\"Incomplete or biased training data can lead to discriminatory AI outputs.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"61.02.35","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Limited human oversight in decisions","description":"\"As AI models and systems gain autonomy, the ability of humans to oversee and intervene in decision-making processes diminishes.\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"61.02.37","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Opaque AI networks","description":"\"The complexity and opacity of AI models and systems make it difficult to predict and manage their behavior.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.4"},{"ev_id":"61.02.40","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Rapid development outpacing regulation","description":"\"The fast pace of AI development may outstrip regulatory and legal frameworks.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"61.02.41","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Resistance to international law","description":"\"AI models and systems may prove difficult to regulate or control under international law.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"61.02.42","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Risks from network interconnectivity","description":"\"The interconnectedness of AI networks can create vulnerabilities, where issues in one part of the network can have cascading effects across the system.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"61.02.47","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Unpredictability of AI development trajectory","description":"\"The unpredictable trajectory of AI development complicates governance and risk management.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"61.02.50","quick_ref":"Uuk2025","paper_title":"A Taxonomy of Systemic Risks from General-Purpose AI ","level":"Risk Sub-Category","risk_category":"Sources of systemic risks from general-purpose AI ","risk_subcategory":"Winner-take-all dynamics","description":"\"The competitive nature of AI development could lead to significant eco- nomic and security advantages for a few entities.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"62.02.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Category","risk_category":"Dimension - Entity ","risk_subcategory":null,"description":null,"entity":"Other","intent":"Not coded","timing":"Not coded","domain":null,"subdomain":null},{"ev_id":"62.02.03","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Entity ","risk_subcategory":"Combination of humans and AI ","description":"\"A risk may be triggered by a human, where the AI serves merely as a tool, or by the AI acting autonomously with no human intervention, or it may involve a combination of both, with the human delegating some parts of decision-making to the AI. For risks where AI is the entity, these risks are exacerbated by an increase in the AI’s level of autonomy. To manage risks involving AI as the trigger, appropriate levels of human oversight can be built-in.\"","entity":"Other","intent":"Not coded","timing":"Not coded","domain":null,"subdomain":null},{"ev_id":"62.03.01","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Failure dynamics ","risk_subcategory":"Isolated (non-normal) failures","description":"\"In the context of Normal Accident Theory [150], normal accidents are those that “could no longer be ascribed to isolated equipment malfunction, operator error, or acts of God.” We refer to these as “system failures” (to be distinguished from “systemic risks”), while the opposite would be “isolated failures.” For isolated failures, harms are consistent with the underlying failure modes. For example, an AI capable of producing false or misleading content would constitute risks re- lated to misinformation and disinformation. Whereas for system failures, harms are not consistent with the underlyi","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"62.03.02","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Failure dynamics ","risk_subcategory":"System (normal) failures","description":"\"In the context of Normal Accident Theory [150], normal accidents are those that “could no longer be ascribed to isolated equipment malfunction, operator error, or acts of God.” We refer to these as “system failures” (to be distinguished from “systemic risks”), while the opposite would be “isolated failures.” For isolated failures, harms are consistent with the underlying failure modes. For example, an AI capable of producing false or misleading content would constitute risks re- lated to misinformation and disinformation. Whereas for system failures, harms are not consistent with the underlyi","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"62.04.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":null,"description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.01","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Supervised/unsupervised AI (AI data quality related - biased training data) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.02","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Supervised/unsupervised AI (AI training performance related - Robustness) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.03","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Supervised/unsupervised AI (AI training performance related - Accuracy) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.04","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Supervised/unsupervised AI (AI training performance related - Reliability) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.05","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Reinforcement learning AI (Training design related) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.04.06","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI inadequacy - technical failure) ","risk_subcategory":"Reinforcement learning AI (Training performance related) ","description":"\"As above, there are broadly two dimensions of technical failure modes: quality of data or input signal, and training performance. Due to a lack of transparency, it may be difficult to ascertain the type of technical failure that gives rise to a particular risk, and it is often a combination of several factors. Risks pertain- ing to AI failures are exacerbated by poor quality training data and imperfect training signals. Various measures can be implemented to improve the quality of the training data, and fine-tuning techniques can be used to disincentivize harmful model behavior.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":null,"subdomain":null},{"ev_id":"62.05.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Category","risk_category":"Dimension - Technical Attributes (AI capabilities) ","risk_subcategory":null,"description":"\"An example of AI capabilities is that an AI might be capable of developing novel bioweapons. Whereas an example of AI inadequacy is a self-driving car causing an accident due to not being able to recognize certain objects. The boundary between capabilities and inadequacy is sometimes blurred. For exam- ple, when an AI generates falsehoods, it could be framed as either a capability of developing fiction, or an inadequacy in generating truthful content.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"62.05.01","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI capabilities) ","risk_subcategory":"Inherent ","description":"\"Inherent capabilities are inherent to the AI, whether they are deliberately trained or have emerged unintentionally.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"62.05.02","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Dimension - Technical Attributes (AI capabilities) ","risk_subcategory":"Extrinsic ","description":"\"Extrinsic capabilities, on the other hand, are acquired through the use of external tools, such as LLM plugins.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"62.15.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Development ","risk_subcategory":"Training-related (Robust overfitting in adversarial training)","description":"\"Adversarial training can be affected by robust overfitting, where the model’s robustness on test data decreases during further training, particularly after the learning rate decay. This issue has been consistently observed across various datasets and algorithms in adversarial training settings [163, 230]. Robust over- fitting can affect the model’s ability to generalize effectively and reduce its resilience to adversarial attacks.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"62.15.02","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Development ","risk_subcategory":"Training-related (Poor model confidence calibration)","description":"\"Models can be affected by poor confidence calibration [85], where the predicted probabilities do not accurately reflect the true likelihood of ground truth cor- rectness. This miscalibration makes it difficult to interpret the model’s predic- tions reliably, as high accuracy does not guarantee that the confidence levels are meaningful. This can cause overconfidence in incorrect predictions or un- derconfidence in correct ones.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.3"},{"ev_id":"62.15.10","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Development ","risk_subcategory":"Fine-tuning related (Catastrophic forgetting due to continual instruction fine-tuning) ","description":"\"Catastrophic forgetting occurs when a model loses its ability to retain previously learned tasks (or factual information) after being trained on new ones. In language models, this can occur due to continual instruction tuning. This tendency may become more pronounced as the model’s size increases [127].\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"62.16.03","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"General Evaluations (Difficulty of identification and measurement of capabilities)","description":"\"The capabilities of general-purpose AI systems can be difficult to measure, compared to the capabilities of more limited and fixed-purpose AI systems. This is in part due to a broader distribution of potential risks, a lack of well-defined metrics to evaluate these risks, and risks from unpredictable (or emergent) AI model properties.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"62.16.05","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"General Evaluations (Inaccurate measurement of model encoded human values)","description":"\"There is a lack of robust frameworks for understanding and evaluating if the output of AI systems robustly conforms to human values, as opposed to if the systems have learned to produce outputs that are only partially correlated with them (i.e., mimicking) [13]. Additionally, outputs by AI models often do not perfectly reflect the representation of human values learned by the model, and it is not known how these values evolve and transition across different stages of model training and deployment. Such evaluations may be especially challenging with LLMs that adopt different personas with diff","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.1"},{"ev_id":"62.16.13","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"Benchmarking (Post-deployment contamination)","description":"\"Once a model is deployed, it can be exposed to benchmark data provided by the users [95, 170]. The model may then be further trained by these user inputs containing benchmark data.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"62.16.15","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"Benchmark Inaccuracy (Benchmark saturation)","description":"\"Benchmark saturation refers to benchmarks reaching their evaluation ceiling. The tendency towards benchmark saturation has been demonstrated in various benchmarks [19]. When benchmarks reach or are close to saturation, they stop being effective measures for new models, as more nuanced capability gains might not be detected.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"62.16.16","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"Benchmark Limitations (Insufficient benchmarks for AI safety evaluation) ","description":"\"Benchmarks dedicated to measuring the performance of AI systems (e.g., on programming or math tasks) are more well-developed than those for assessing safety and harms in AI systems [234]. This gap can lead to AI systems excelling in specific tasks while exhibiting harmful behaviors that go undetected. More safety-related evaluation datasets can help in identifying previously overlooked undesirable model behaviors.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"62.16.17","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations","risk_subcategory":"Benchmark Limitations (Underestimating capabilities that are not covered by benchmarks)","description":"\"A lack of test coverage by benchmarks on specific abilities of a model can obscure the model’s capabilities from both the developer and the user [160]. This can lead to a false sense of safety and trust due to a lack of understanding of the model’s limitations.\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"62.18.04","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Evaluations (Interpretability/Explainability) ","risk_subcategory":"Biases are not accurately reflected in explanations","description":"\"Existing explainability techniques can be insufficient for detecting discriminatory biases. Manipulation methods can hide underlying biases from these tech- niques, generating misleading explanations [192, 112]. Such explanations ex- clude sensitive or prohibitive attributes, such as race or gender, and instead include desired attributes, even though they do not accurately represent the underlying model.\"","entity":"Other","intent":"Other","timing":"Other","domain":1,"subdomain":"1.1"},{"ev_id":"62.19.06","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Attacks on GPAIs/GPAI Failure Modes ","risk_subcategory":"Vulnerabilities arising from additional modalities in multimodal models","description":"\"Additional modalities can introduce new attack vectors in multimodal models as well as expand the scope of the previous attacks, ranging from jailbreaking to poisoning [13]. Typically, different modalities have different robustness levels, allowing malicious actors to choose the most vulnerable part of the model to attack [119, 181].\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"62.19.07","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Attacks on GPAIs/GPAI Failure Modes ","risk_subcategory":"Vulnerabilities to jailbreaks exploiting long context windows (many- shot jailbreaking)","description":"\"Language models with long context windows are vulnerable to new types of ex- ploitations that are ineffective on models with shorter context windows. While few-shot jailbreaking, which involves providing few examples of the desired harmful output, might not trigger a harmful response, many-shot jailbreak- ing, which involves a higher number of such examples, increases the likelihood of eliciting an undesirable output. These vulnerabilities become more significant as context windows expand with newer model releases [7].\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":2,"subdomain":"2.2"},{"ev_id":"62.19.10","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Attacks on GPAIs/GPAI Failure Modes ","risk_subcategory":"Lack of understanding of in-context learning in language models","description":"\"In-context learning allows the model to learn a new task or improve its perfor- mance by providing examples in the prompt, without changing its weights [101]. Even though this technique is highly effective, its working mechanism is not well understood. Since many potential misuses are directly related to prompting, it becomes difficult to guarantee safety when the exact mechanism of in-context learning is not fully investigated [13].\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"62.27.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Category","risk_category":"Deployment (Model Release) ","risk_subcategory":null,"description":"-","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"62.28.00","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Category","risk_category":"Cybersecurity ","risk_subcategory":null,"description":"\"This section catalogs the risk sources and mitigation measures related to cyber- security. These items may be related to security in terms of AI models being accessible only to the intended users, as well as AI models having appropriate access to the external world during both model development and deployment stages.\"","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.0"},{"ev_id":"62.31.02#2","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Impacts of AI (Financial Impacts) ","risk_subcategory":"Financial instability due to model homogeneity","description":"\"The widespread use of similar models or algorithms across the financial sec- tor can lead to synchronized reactions to market signals, increasing volatility, triggering flash crashes, or market illiquidity [4].\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"62.34.01","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Impacts of AI (Bias) ","risk_subcategory":"Homogenization or correlated failures in model derivatives","description":"\"Homogenization refers to common methodologies and models used across down- stream GPAI systems, which may lead to uniform failures and amplification of biases [176, 30]. This risk arises when numerous downstream AI systems are built upon a few large-scale foundation models.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"62.39.01","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Impacts of AI (Environment) ","risk_subcategory":"High energy consumption of large models","description":"\"Training and deploying large models require substantial energy expenditure. The trend toward developing larger models exacerbates this issue. This can lead to excessive energy usage and have a negative environmental impact.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"63.04.01","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Information Asymmetries","risk_subcategory":"Communication constraints","description":"\"Communication Constraints. A fundamental source of information asymmetries is that constraints on information exchange can exist, even when agents share a common goal (see Section 2.1). These might be constraints on space (i.e., the amount of information that can be communicated) if the information that needs to be communicated is especially complex, time if a snap decision is required before all information can be communicated, or both.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"63.05.02","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Network Effects ","risk_subcategory":"Network rewiring ","description":"\"Network Rewiring. A different class of problems concerns not changes in the content transmitted through the network but changes in the network structure itself (Albert et al., 2000).\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"63.05.03","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Network Effects ","risk_subcategory":"Homogeneity and correlated failures","description":"\"Homogeneity and Correlated Failures. The current paradigm driving the state of the art in AI is the ‘foundation model’ (Bommasani et al., 2021): large-scale ML models pre-trained on broad data, which can be repurposed for a wide range of downstream applications. The costs required to create such models (and continuing returns to scale) means that only well-resourced actors can create cutting- edge models (Epoch, 2023; Hoffmann et al., 2022; Kaplan et al., 2020), making them relatively few in number. If current trends continue, it is likely that many AI agents will be powered by a small number","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"63.06.01","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Selection Pressures","risk_subcategory":"Undesirable Dispositions from Competition","description":"\"Undesirable Dispositions from Competition. It is plausible that evolution selected for certain conflict-prone dispostions in humans, such as vengefulness, aggression, risk-seeking, selfishness, dishon- esty, deception, and spitefulness towards out-groups (Grafen, 1990; Han, 2022; Konrad & Morath, 2012; McNally & Jackson, 2013; Nowak, 2006; Rusch, 2014). Such traits could also be selected for in ML systems that are trained in more competitive multi-agent settings. For example, this might happen if systems are selected based on their performance relative to other agents (and so one agent’s loss","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"63.06.02","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Selection Pressures","risk_subcategory":"Undesirable Dispositions from Human Data","description":"\"Undesirable Dispositions from Human Data. It is well-understood that models trained on human data – such as being pre-trained on human-written text or fine-tuned on human feedback – can exhibit human biases. For these reasons, there has already been considerable attention to measuring biases related to protected characteristics such as sex and ethnicity (e.g., Ferrara, 2023; Liang et al., 2021; Nadeem et al., 2020; Nangia et al., 2020), which can be amplified in multi-agent settings (Acerbi & Stubbersfield, 2023, see also Case Study 7). More recently, there has been increasing attention paid ","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"63.07.04","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Destabilising Dynamics ","risk_subcategory":"Phase Transitions","description":"\"Phase Transitions. Finally, small external changes to the system – such as the introduction of new agents or a distributional shift – can cause phase transitions, where the system undergoes an abrupt qualitative shift in overall behaviour (Barfuss et al., 2024). Formally, this corresponds to bifurcations in the system’s parameter space, which lead to the creation or destruction of dynamical attractors, resulting in complex and unpredictable dynamics (Crawford, 1991; Zeeman, 1976). For example, Leonardos & Piliouras (2022) show that changes to the exploration hyperparameter of RL agents can le","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"63.08.00","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Category","risk_category":"Commitment and Trust ","risk_subcategory":null,"description":"\"Commitment and trust (Section 3.5): difficulties in forming credible commitments, trust, or reputation can prevent mutual gains in AI-AI and human-AI interactions;\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"63.10.00","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Category","risk_category":"Multi-Agent Security ","risk_subcategory":null,"description":"\"Multi-agent security (Section 3.7): multi-agent systems give rise to new kinds of security threats and vulnerabilities.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"63.10.04","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Multi-Agent Security ","risk_subcategory":"Vulnerable AI Agents","description":"\"Vulnerable AI Agents. The use of AI agents as delegates or representatives of humans or organisa- tions also introduces the possibility of attacks on AI agents themselves. In other words, agents can be considered vulnerable extensions of their principals, introducing a novel attack surface (SecureWorks, 2023). Attacks on an AI agent could be used to extract private information about their principal (Wei & Liu, 2024; Wu et al., 2024a), or to manipulate the agent to take actions that the principal would find undesirable (Zhang et al., 2024a). This includes attacks that have direct relevance for","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"63.10.05","quick_ref":"Hammond2025","paper_title":"Multi-Agent Risks from Advanced AI ","level":"Risk Sub-Category","risk_category":"Multi-Agent Security ","risk_subcategory":"Cascading Security Failures","description":"\"Cascading Security Failures. Localised attacks in multi-agent systems can result in catastrophic macroscopic outcomes (Motter & Lai, 2002, see also Sections 3.2 and 3.4). These cascades can be hard to mitigate or recover from because component failure may be difficult to detect or localise in multi-agent systems (Lamport et al., 1982), and authentication challenges can facilitate false flag attacks (Skopik & Pahi, 2020). Computer worms represent a classic example of a cybersecurity threat that relies inherently on networked systems. Recent work has provided preliminary evidence that similar a","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"65.03.03","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Training Data Risks (Privacy) ","risk_subcategory":"Reidentification ","description":"\"Even with the removal or personal identifiable information (PII) and sensitive personal information (SPI) from data, it might be possible to identify persons due to correlations to other features available in the data.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":2,"subdomain":"2.1"},{"ev_id":"65.06.02","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Training Data Risks (Accuracy) ","risk_subcategory":"Unrepresentative data ","description":"\"Unrepresentative data occurs when the training or fine-tuning data is not sufficiently representative of the underlying population or does not measure the phenomenon of interest.\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"65.12.01","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Inference risks (Intellectual property) ","risk_subcategory":"Confidential data in prompt ","description":"\"Confidential information might be included as a part of the prompt that is sent to the model.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":2,"subdomain":"2.1"},{"ev_id":"65.12.02","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Inference risks (Intellectual property) ","risk_subcategory":"IP information in prompt ","description":"\"Copyrighted information or other intellectual property might be included as a part of the prompt that is sent to the model.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":2,"subdomain":"2.1"},{"ev_id":"65.17.02","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Output risks (Explainability) ","risk_subcategory":"Untraceable attribution ","description":"\"The content of the training data used for generating the model’s output is not accessible.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.4"},{"ev_id":"65.21.02","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Non-technical risks (legal compliance)","risk_subcategory":"Legal accountability ","description":"\"Determining who is responsible for an AI model is challenging without good documentation and governance processes.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"65.21.03","quick_ref":"IBM2025","paper_title":"AI Risk Atlas ","level":"Risk Sub-Category","risk_category":"Non-technical risks (legal compliance)","risk_subcategory":"Generated content ownership and IP","description":"\"Legal uncertainty about the ownership and intellectual property rights of AI-generated content.\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.3"},{"ev_id":"66.01.00","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Category","risk_category":"Autonomy","risk_subcategory":"-","description":"\"Loss of or restrictions to the ability or rights of an individual, group or entity to make decisions and control their identity and/or output due to the use of misuse of a technology system or set of systems\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"66.01.03","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Autonomy","risk_subcategory":"Autonomy / agency loss","description":"\"Loss of an individual, group or organisation’s ability to make informed decisions or pursue goals\"","entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"66.03.02","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Misinformation Harms ","risk_subcategory":"Pollution of information ecosystems","description":"\"Contaminating publicly available information with false or inaccurate information (i.e., the generative tool's output is disseminated beyond the end user)\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":3,"subdomain":"3.2"},{"ev_id":"66.03.03","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Misinformation Harms ","risk_subcategory":"Erosion of trust in public information","description":"\"Eroding trust in public information and knowledge\"","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.2"},{"ev_id":"66.04.01","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Societal and Cultural","risk_subcategory":"Overburdening ecosystems","description":"\"Pollution of a space/ecosystem that is expected to be free of AI involvement/influence (e.g., creative material submission portals, job applications)\"","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.2"},{"ev_id":"66.04.02","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Societal and Cultural","risk_subcategory":"Breach of ethics / values / norms","description":"\"An actual or perceived violation or deviation from the established societal values, norms or ethical standards or principles\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"66.04.03","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Societal and Cultural","risk_subcategory":"Loss of creativity / critical thinking","description":"\"Devaluation and/or deterioration of human creativity, artistic expression, imagination, critical thinking or problem-solving skills\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.3"},{"ev_id":"66.04.06","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Societal and Cultural","risk_subcategory":"Job loss","description":"\"Replacement/displacement of human jobs by a technology system or set of systems, leading to increased unemployment, inequality, reduced consumer spending and social friction\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.2"},{"ev_id":"66.06.04","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Representation and Toxicity","risk_subcategory":"Cultural disposession","description":"\"Intentional and/or unintentional erasure of cultural goods and values, such as ways of speaking, expressing humour, or sounds and voices that contribute to a cultural identity, or their inappropriate re-use in other cultures\"","entity":"Other","intent":"Other","timing":"Other","domain":1,"subdomain":"1.1"},{"ev_id":"66.07.06","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Psychological","risk_subcategory":"Addiction","description":"\"Emotional or material dependence on technology or a technology system\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"66.08.01","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Financial and Business","risk_subcategory":"Financial / earnings loss","description":"\"Loss of money, income or value due to the use, misuse, or underperformance of a genAI application\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"66.09.06","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Privacy and Security","risk_subcategory":"Distortion","description":"\"disseminating false or misleading information about people\"","entity":"Other","intent":"Intentional","timing":"Other","domain":3,"subdomain":"3.1"},{"ev_id":"66.10.02","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Human Rights and Civil Liberties","risk_subcategory":"Benefits / entitlements loss","description":"\"Denial of or loss of access to welfare benefits, pensions, housing, etc due to the malfunction, use or misuse of a technology system\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":1,"subdomain":"1.1"},{"ev_id":"66.11.02","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Physical","risk_subcategory":"Bodily injury","description":"\"Physical pain, injury, illness, or disease suffered by an individual or group due to the malfunction, use or misuse of a technology system.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"66.11.04","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Physical","risk_subcategory":"Property damage","description":"\"Action(s) that lead directly or indirectly to the damage or destruction of tangible property eg. buildings, possessions, vehicles, robots\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"66.11.05","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Physical","risk_subcategory":"Personal Health Deterioation ","description":"\"Physical deterioration of an individual or animal over time in the form of disease, organ failure, prolonged hospital stay or death, etc\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"66.12.02","quick_ref":"Li2025","paper_title":"A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents","level":"Risk Sub-Category","risk_category":"Environment","risk_subcategory":"Excessive energy consumption","description":"\"Excessive energy use resulting in energy bottlenecks and shortages for communities, organisations and businesses\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"67.01.00","quick_ref":"DSIT2023","paper_title":"Capabilities and Risks from Frontier AI","level":"Risk Category","risk_category":"Societal harms ","risk_subcategory":null,"description":"\"There is a wide range of potential societal harms arising from the use of AI.152 This has sparked a debate around the ethics of AI, with a wide proliferation of ethical frameworks and principles.153 We focus here on only a few societal harms, but this is not to downplay the importance of others.\"","entity":"Other","intent":"Other","timing":"Other","domain":null,"subdomain":null},{"ev_id":"67.01.01","quick_ref":"DSIT2023","paper_title":"Capabilities and Risks from Frontier AI","level":"Risk Sub-Category","risk_category":"Societal harms ","risk_subcategory":"Degradation of the information environment","description":"\"Frontier AI can cheaply generate realistic content which can falsely portray people and events. There is potential risk of compromised decision-making by individuals and institutions who rely on inaccurate or misleading publicly available information, as well as lower overall trust in true information.\"","entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.2"},{"ev_id":"67.01.02","quick_ref":"DSIT2023","paper_title":"Capabilities and Risks from Frontier AI","level":"Risk Sub-Category","risk_category":"Societal harms ","risk_subcategory":"Labour market disruption","description":"\"Economists view disruption and displacement in labour markets as one of the risks through which rapid advances in AI may affect citizens and reduce social welfare.170\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.2"},{"ev_id":"67.04.00","quick_ref":"DSIT2023","paper_title":"Capabilities and Risks from Frontier AI","level":"Risk Category","risk_category":"Loss of control ","risk_subcategory":"-","description":"\"Humans may increasingly hand over control of important decisions to AI systems, due to economic and geopolitical incentives. Some experts are concerned that future advanced AI systems will seek to increase their own influence and reduce human control, with potentially catastrophic consequences - although this is contested.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":5,"subdomain":"5.2"},{"ev_id":"67.04.03","quick_ref":"DSIT2023","paper_title":"Capabilities and Risks from Frontier AI","level":"Risk Sub-Category","risk_category":"Loss of control ","risk_subcategory":"Capabilities that could be used to reduce human control - Manipulation ","description":"\"There is evidence that language models tend to respond as though they share the user’s stated views, and larger models do this more than smaller ones.276 The ability to predict people’s views and generate text that they will endorse could be useful for manipulation.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":7,"subdomain":"7.2"},{"ev_id":"68.02.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Cyber offense","risk_subcategory":null,"description":"\"Cyber risks, especially in the context of cyber offense, are an existing threat that may be exacerbated by AI. [108] demonstrated that teams of LLM agents can exploit zero-day vulnerabilities when given a description of the vulnerability and toy capture-the-flag problems. While cyber risks are not typically regarded as catastrophic, [3] argues that cyberwarfare is an underappreciated risk that poses a credible threat of catastrophic harm.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"68.04.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"Gradual or accumulative loss of control risks can be described as risks resulting from the accumulation of less severe disruptions that gradually weakens systemic resilience until a critical event triggers a catastrophe [12], [127].\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"68.04.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Multi-agent • Linearity: Non-linear • Reach: Internalized • Order: Variable\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"68.05.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"AI models are often trained using large amounts of computation. This process is very energy intensive, potentially leading to significant greenhouse emissions depending on the energy sources [132]. Experts believe drastically increasing carbon emissions could accelerate climate change, which may constitute a catastrophic risk [133].\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"68.06.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Geopolitical risk","risk_subcategory":null,"description":"\"As AI is increasingly seen as a powerful technology, countries are racing to develop it ahead of their geopolitical rivals, a competition that could lead to geopolitical tensions [138], [139]... The emphasis of this risk is on harms that result from second-order effects, where geopolitical instabilities result from the race to develop AI, rather than on the direct consequences of the deployment or use of AI itself.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.4"},{"ev_id":"69.01.05","quick_ref":"Stanley2024","paper_title":"Emerging Risks and Mitigations for Public Chatbots: LILAC v1","level":"Risk Sub-Category","risk_category":"False information","risk_subcategory":"Spreads and self-perpetuates mis/disinformation","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":3,"subdomain":"3.1"},{"ev_id":"69.09.04","quick_ref":"Stanley2024","paper_title":"Emerging Risks and Mitigations for Public Chatbots: LILAC v1","level":"Risk Sub-Category","risk_category":"Forms emotional bonds ","risk_subcategory":"Over-reliance/addiction","description":null,"entity":"Other","intent":"Other","timing":"Other","domain":5,"subdomain":"5.1"},{"ev_id":"70.01.02","quick_ref":"Perlo2025","paper_title":"Embodied AI: Emerging Risks and Opportunities for Policy Action","level":"Risk Sub-Category","risk_category":"Physical Risks ","risk_subcategory":"Accidental harm","description":"\"Automation in sectors ranging from manufacturing to healthcare has and will increasingly put humans into close contact with EAI systems [7]. This interaction increases the risk of accidental physical harm. Though accidental harm has been a longstanding issue in industrial robotics, increased AI capabilities could exacerbate this risk; several recent reports document an increase in industrial injuries following the introduction of AI-controlled robots [66–68].\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"70.04.02","quick_ref":"Perlo2025","paper_title":"Embodied AI: Emerging Risks and Opportunities for Policy Action","level":"Risk Sub-Category","risk_category":"Social Risks ","risk_subcategory":"Lack of accountability and liability","description":"\"Determining responsibility when EAI causes harm requires new accountability and liability frameworks that address the complexities of highly autonomous physical systems. Human users may disagree with decisions taken by expert EAI systems, raising significant questions of delegation and responsibility [108]. Lack of EAI accountability could lead to confusion for users and breakdowns in traditional justice systems [109].\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.5"},{"ev_id":"70.04.03","quick_ref":"Perlo2025","paper_title":"Embodied AI: Emerging Risks and Opportunities for Policy Action","level":"Risk Sub-Category","risk_category":"Social Risks ","risk_subcategory":"Lack of transparency, explainability, and trust","description":"\"Understanding how AI reaches conclusions or why AI systems perform specific actions motivates an entire branch of interpretability research [111], but physical embodiment raises the stakes for understanding these systems. For example, transparency of planned actions and explainability of decision-making is crucial when an AV suddenly changes lanes. A lack of transparency and explainability could lead to a lack of trust, which could become a critical and socially destabilizing issue with the widespread deployment of EAI [112–114].\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.4"},{"ev_id":"70.04.04","quick_ref":"Perlo2025","paper_title":"Embodied AI: Emerging Risks and Opportunities for Policy Action","level":"Risk Sub-Category","risk_category":"Social Risks ","risk_subcategory":"Unhealthy or dangerous human-EAI relationships","description":"\"Constant access to and interaction with EAI systems could foster dangerous human dependence or romantic attachment [115]. People may depend on EAI systems for physical pleasure [116]. The physical presence and human-like features of EAI systems may significantly amplify the dependency issues already observed with conversational AI [117, 118]. People may easily fall in love with EAI systems, only to be distraught when these systems are altered or have their memories reset [119].\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":5,"subdomain":"5.1"},{"ev_id":"70.04.05","quick_ref":"Perlo2025","paper_title":"Embodied AI: Emerging Risks and Opportunities for Policy Action","level":"Risk Sub-Category","risk_category":"Social Risks ","risk_subcategory":"Transformative effects ","description":"\"EAI deployment could fundamentally reshape society, particularly if the speed of technological development outpaces society’s ability to adapt [103, 120]. For example, EAI systems could provide physical threats of violence and mass surveillance capabilities to back up AI-enabled authoritarianism [121].\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":6,"subdomain":"6.5"},{"ev_id":"71.01.02","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"Scientific Domain of Agents","risk_subcategory":"Biological Risks ","description":"\"Biological risks encompass the dangerous modification of pathogens and unethical manipulation of genetic material, potentially leading to unforeseen biohazardous outcomes.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":4,"subdomain":"4.2"},{"ev_id":"71.01.03","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"Scientific Domain of Agents","risk_subcategory":"Radiological Risks ","description":"\"Radiological risks involve both immediate operational hazards, such as exposure incidents or containment failures during the automated handling of radioactive materials, and broader security concerns regarding the potential misuse of AI systems in nuclear research.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"71.01.04","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"Scientific Domain of Agents","risk_subcategory":"Physical (Mechanical ) Risks ","description":"\"Physical (mechanical) risks are associated with robotics and automated systems, which could lead to equipment malfunctions or physical harm in laboratory settings.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.3"},{"ev_id":"71.01.05","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"Scientific Domain of Agents","risk_subcategory":"Information Science Risks ","description":"\"These risks pertain to the misuse, misinterpretation, or leakage of data, which can lead to erroneous conclusions or the unintentional dissemination of sensitive information, such as private patient data or proprietary research. Recent research has demonstrated how LLMs can be exploited to generate malicious medical literature that poisons knowledge graphs, potentially manipulating downstream biomedical applications and compromising the integrity of medical knowledge discovery [28]. Such risks are pervasive across all scientific domains.\"","entity":"Other","intent":"Other","timing":"Post-deployment","domain":2,"subdomain":"2.1"},{"ev_id":"71.02.02","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"User Intent ","risk_subcategory":"Malicious and Indirect","description":"\"Benign intermediate for harmful end objective\"","entity":"Other","intent":"Intentional","timing":"Other","domain":4,"subdomain":"4.0"},{"ev_id":"71.02.03","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"User Intent ","risk_subcategory":"Unintended Consequences ","description":"\"Unpredictable and unforeseen outcomes from purposeful actions\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":null,"subdomain":null},{"ev_id":"71.03.01","quick_ref":"Tang2025","paper_title":"Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy","level":"Risk Sub-Category","risk_category":"Environment","risk_subcategory":"Nature ","description":"\"Short-term or long-term Negative effects on the natural environment\"","entity":"Other","intent":"Other","timing":"Other","domain":6,"subdomain":"6.6"},{"ev_id":"72.02.01","quick_ref":"Tse2025","paper_title":"Frontier AI Risk Management Framework (v1.0)","level":"Risk Sub-Category","risk_category":"Loss of Control Risks ","risk_subcategory":"Passive loss of control ","description":"\"...where humans gradually stop exercising meaningful oversight due to automation bias, the AI systems' inherent complexity, or competitive pressures\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"72.02.02a","quick_ref":"Tse2025","paper_title":"Frontier AI Risk Management Framework (v1.0)","level":"Additional evidence","risk_category":"Loss of Control Risks ","risk_subcategory":"Active loss of control ","description":null,"entity":"Other","intent":null,"timing":"Other","domain":null,"subdomain":null},{"ev_id":"72.03.02","quick_ref":"Tse2025","paper_title":"Frontier AI Risk Management Framework (v1.0)","level":"Risk Sub-Category","risk_category":"Accident Risks ","risk_subcategory":"Impact on Financial Stability","description":"\"The integration of general-purpose AI into high-frequency trading, market-making, or systemic risk management could exacerbate systemic risk by exhibiting unexpected behavioral patterns during market stress. Moreover, the concentration of a few homogeneous foundation models across financial institutions may foster correlated decision-making and herd-following behaviors. The widespread adoption of AI agents could also amplify volatility through emergent phenomena from multi-agent interactions.23 All of these could precipitate a cascading global-scale financial system instability, with potentia","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"72.04.00","quick_ref":"Tse2025","paper_title":"Frontier AI Risk Management Framework (v1.0)","level":"Risk Category","risk_category":"Systemic Risks ","risk_subcategory":null,"description":"\"Systemic risks emerge from widespread deployment of general-purpose AI beyond the risks directly posed by capabilities of individual models. These risks arise from structural mismatches between AI technology and existing social, economic, and institutional frameworks, creating vulnerabilities that transcend individual model-level interventions and require coordinated industry-wide and societal-level responses.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"72.04.03","quick_ref":"Tse2025","paper_title":"Frontier AI Risk Management Framework (v1.0)","level":"Risk Sub-Category","risk_category":"Systemic Risks ","risk_subcategory":"Global AI Research and Development Divides:","description":"\"Asymmetric AI development capabilities between nations could exacerbate geopolitical tensions and create new forms of technological dependency. Countries lacking advanced AI capabilities may become increasingly dependent on foreign AI systems for critical functions, while AI-leading nations may gain disproportionate influence over global economic and security systems, potentially destabilizing international cooperation frameworks.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"73.01.02","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Agentic LLMs Pose Novel Risks ","risk_subcategory":"Natural Language Underspecifies Goals ","description":"\"For LLM-agents, both the goal and environment observations are typically specified in the prompt through natural language. While natural language may provide a richer and more natural means of specifying goals than alternatives such as hand-engineering objective functions, natural language still suffers from underspecification (Grice, 1975; Piantadosi et al., 2012). Furthermore, in practice, users may neglect fully specifying their goals, especially the information pertaining to elements of the environment that ought not to be changed (the classic frame problem (Shanahan, 2016)). Such undersp","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"73.02.00","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Category","risk_category":"Multi-Agent Safety Is Not Assured by Single-Agent Safety","risk_subcategory":null,"description":"\"A foremost lesson of game theory is that optimal decision-making within a single-agent setting (i.e. selfishly optimizing for an agent’s own utility) can produce sub-optimal outcomes in the presence of other strategic agents. Failing to account for the strategic nature of other agents can cause an agent to adopt strategies under which potentially everyone, including the agent itself, ends up worse off (Schelling, 1981; Harsanyi, 1995; Roughgarden, 2005; Nisan, 2007). Examples include collective action problems (or ‘social dilemmas’) such as arms races or the depletion of common resources, as ","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.6"},{"ev_id":"73.02.01","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Multi-Agent Safety Is Not Assured by Single-Agent Safety","risk_subcategory":"Foundationality May Cause Correlated Failures","description":"\"Another important characteristic of LLM development is foundationality — due to the expense of large- scale pretraining, many deployed instances share similar or identical learned components. Foundation- ality may both be a blessing and a curse. On the one hand, it may be possible to exploit the similarity in the design of LLM-agents to facilitate cooperation (Critch et al., 2022; Conitzer and Oesterheld, 2023; Oesterheld et al., 2023). On the other hand, foundationality may leave LLM-agents vulnerable to correlated failures both in terms of safety and capabilities due to increased output hom","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"73.02.02","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Multi-Agent Safety Is Not Assured by Single-Agent Safety","risk_subcategory":"Groups of LLM-Agents May Show Emergent Functionality","description":"\"Multi-agent learning, either through explicit finetuning or implicit in-context learning, may enable LLM-agents to influence each other during their interactions (Foerster et al., 2018). Under some environmental settings, this can create feedback loops that result in novel and emergent behaviors that would not manifest in the absence of multi-agent interactions (Hammond et al., 2024, Section 3.6).  Emergent functionality is a safety risk in two ways. Firstly, it may itself be dangerous (Shevlane et al., 2023). Secondly, it makes assurance harder as such emergent behaviors are difficult to pre","entity":"Other","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.6"},{"ev_id":"73.05.00","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Category","risk_category":"Socioeconomic Impacts of LLM May Be Highly Disruptive","risk_subcategory":null,"description":"\"The rapid evolution of LLMs brings significant socioeconomic opportunities and challenges, impacting the workforce, income inequality, education, and global economic development. Many of these challenges are systemic in nature, constituting what economists refer to as general equilibrium effects. These challenges do not arise directly from LLMs causing harm to users but rather from their indirect effects on the socioeconomic equilibrium.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":null,"subdomain":null},{"ev_id":"73.05.01","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Socioeconomic Impacts of LLM May Be Highly Disruptive","risk_subcategory":"Effects on the Workforce","description":"\"Rapid advances in LLMs pose three distinct sets of challenges for workers’ incomes (Korinek and Stiglitz, 2019; Susskind, 2023). First, they are likely to accelerate the rate of job turnover and disruption —– affecting more workers, including more highly skilled workers, and making the adjustment process for society more difficult than what we were used to from prior technological advances...Second, although technological progress means that society may produce more wealth overall, there is a risk that the general-purpose nature of LLMs may lead to progress that is biased against labor, meani","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"73.05.03","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Socioeconomic Impacts of LLM May Be Highly Disruptive","risk_subcategory":"Global Economic Development","description":"\"Many of the themes and challenges that we discussed above come together when analyzing the socioeconomic effects on developing countries. The workforce of developing countries may suffer from a retrenchment of outsourcing as many simple cognitive tasks that used to be performed in developing countries — for example, in call centers –— can be automated with LLMs. This may adversely affect the economies of the poor countries (Georgieva, 2024).\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":6,"subdomain":"6.2"},{"ev_id":"73.06.00","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Category","risk_category":"Corporate power may impeded effective governance ","risk_subcategory":null,"description":"\"The increasing power and influence of large corporations may make effective governance difficult. There exists a power asymmetry between corporate entities profiting from LLMs and other social groups (e.g. civil society). State-of-the-art LLMs are developed by or in partnership with, some of the world’s largest private tech companies...This poses a risk of governance protocols related to LLMs becoming excessively favorable to tech companies, potentially leading to regulatory capture at the cost of the interests of other societal groups, particularly marginalized communities who have historica","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.1"},{"ev_id":"73.07.00","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Category","risk_category":"Jailbreaks and Prompt Injections Threaten Security of LLMs","risk_subcategory":null,"description":"\"LLMs are not adversarially robust and are vulnerable to security failures such as jailbreaks and prompt-injection attacks. While a number of jailbreak attacks have been proposed in the literature, the lack of standardized evaluation makes it difficult to compare them. We also do not have efficient white-box methods to evaluate adver- sarial robustness. Multi-modal LLMs may further allow novel types of jailbreaks via additional modalities. Finally, the lack of robust privilege levels within the LLM input means that jailbreaking and prompt-injection attacks may be particularly hard to eliminate","entity":"Other","intent":"Other","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"73.07.01","quick_ref":"Anwar2024","paper_title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","level":"Risk Sub-Category","risk_category":"Jailbreaks and Prompt Injections Threaten Security of LLMs","risk_subcategory":"Exploiting Limited Generalization of Safety Finetuning","description":"\"Safety tuning is performed over a much narrower distribution compared to the pretraining distribution. This leaves the model vulnerable to attacks that exploit gaps in the generalization of the safety training, e.g. using encoded text (Wei et al., 2023c) or low-resource languages (Deng et al., 2023a; Yong et al., 2023) (see also Section 3.2).\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":2,"subdomain":"2.2"},{"ev_id":"74.01.07","quick_ref":"Wang2025","paper_title":"A Survey on Responsible LLMs: Inherent Risk, Malicious Use, and Mitigation Strategy","level":"Risk Sub-Category","risk_category":"Inherent Risk ","risk_subcategory":"Value-related risks in LLMs","description":"\"As the general capabilities of LLM-empowered systems improve, the negative consequences and risks induced by these systems also get increasingly alarming accordingly, especially in high-stakes areas [28, 146]. Although they may not be intentionally introduced, severe problematic issues related to human values can be raised. Specifically, even before language models become extremely large, pre-trained language models have already exhibited a certain degree of value judgments. For example, Schramowski et al. [171] reveal the existence of the moral direction with the sentence embeddings of moral","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.1"}]}