{"attribution":{"source":"MIT AI Risk Repository, Domain Taxonomy of AI Risks v1 (MIT AI Risk Initiative)","license":"CC BY 4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","citation":"Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2025). The AI Risk Repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence. arXiv:2408.12622."},"exported_at":"2026-09-11"}
{"rows":[{"ev_id":"68.01.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"CBRN ","risk_subcategory":null,"description":"\"Chemical, biological, radiological, and nuclear (CBRN) risks are broad classes of threats that have the potential to cause harm to a large number of people. Explosives are also sometimes included in this category, often referred to as CBRNE...The key characteristic of CBRN risk is that it stems from misuse of capable models with a direct pathway to harm, where a malicious actor is able to carry out consequential attacks more efficiently and effectively with the help of AI.\"","entity":"Human","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"68.01.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"CBRN ","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Intentional • Competency: Competent • Entity: Humans • Polarity: Single-agent • Linearity: Linear • Reach: Internalized • Order: First-order\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.01.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"CBRN ","risk_subcategory":null,"description":"\"The 2001 US anthrax attack is one of the worst biological attacks in history, where five people were killed and 17 others infected, with several senators being victims of the attack. Anthrax, an infection caused by the bacterium Bacillus anthracis, is deadliest when spread through inhalation of anthrax spores [102]. Investigations conclude that the perpetrator, who had access to highly sophisticated lab equipment, possessed the knowledge and ability of growing, harvesting, storing, and drying highly purified spores used in the mailings [103]. While modern AI was not involved in the 2001 attac","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.01.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"CBRN ","risk_subcategory":null,"description":"\"6.1.4 Other similar risks There are other types of risks that share similar risk dimensions but arise from very different pathways. For example, the development and deployment of nanoweapons which may lead to catastrophic harms [105]. Separately, the use of AI-enabled surveillance and control employed by state or non-state actors could facilitate authoritarian regimes and the eventual loss of autonomy [106], [107].\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.02.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Cyber offense","risk_subcategory":null,"description":"\"Cyber risks, especially in the context of cyber offense, are an existing threat that may be exacerbated by AI. [108] demonstrated that teams of LLM agents can exploit zero-day vulnerabilities when given a description of the vulnerability and toy capture-the-flag problems. While cyber risks are not typically regarded as catastrophic, [3] argues that cyberwarfare is an underappreciated risk that poses a credible threat of catastrophic harm.\"","entity":"Other","intent":"Intentional","timing":"Post-deployment","domain":4,"subdomain":"4.2"},{"ev_id":"68.02.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Cyber offense ","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Intentional • Competency: Competent • Entity: Variable • Polarity: Single-agent • Linearity: Linear • Reach: Internalized • Order: First-order\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.02.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Cyber offense ","risk_subcategory":null,"description":"\"Similar to CBRN risk, cyber offense represents a broad class of risk that stems from misuse of capable models. However, in contrast to CBRN risks, cyberattacks can take place entirely in the digital domain. In theory, it can be conducted completely by AIs (or AI agents) without any human involvement. The pathway to harm is also less direct, as the resultant harm depends on the target of the attack.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.02.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Cyber offense ","risk_subcategory":null,"description":"\"Stuxnet, a worm designed to attack industrial control systems, is considered as the first cyber warfare weapon ever [109], [110]. The Stuxnet malware reportedly caused the damage and subsequent decommissioning of 1000 centrifuges at the Natanz Enrichment Plant, potentially setting back Iran’s progress in its nuclear program [111]. Given that the Stuxnet attack happened in 2010, modern AIs were likely not involved. Nevertheless, it is believed that AIs will increase the volume and heighten the impact of cyber attacks in the near term [112].\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.03.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Sudden loss of control ","risk_subcategory":null,"description":"\"Sudden loss of control, also known as an AI takeover [115], is a scenario where an AI rapidly achieves superintelligence through “fast takeoff” or recursive self-improvement. This poses an existential risk [116], [117].\"","entity":"AI","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.1"},{"ev_id":"68.03.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Sudden loss of control ","risk_subcategory":null,"description":"\"This risk is primarily based on two key ideas: the orthogonality thesis [118], [119] and the instrumental convergence thesis [120], [121]. Together, these theories argue that a superintelligent AI, regardless of its original goals, would develop power-seeking tendencies as a means to achieve those goals. However, arguments for this scenario typically do not spell out the concrete physical pathways an existential catastrophe would be realized. Instead, they argue that it is the default outcome given the eventual creation of a superintelligence based on a set of reasonable assumptions.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.03.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Sudden loss of control ","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Variable • Competency: Competent • Entity: AI • Polarity: Single-agent • Linearity: Linear • Reach: Internalized\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.03.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Sudden loss of control ","risk_subcategory":null,"description":"\"The key characteristic of this risk is that a single AI agent competently takes actions that lead to a catastrophic outcome. It does not require the AI to be intentional in its actions, only competent enough to make and execute plans that ultimately result in a catastrophe.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.03.00d","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Sudden loss of control ","risk_subcategory":null,"description":"\"On 11th September 1973, the democratic socialist president of Chile Salvador Allende and his Popular Unity coalition government was overthrown in a coup d’état by the Chilean military, ending a 46-year history of democratic rule in Chile [123]. Despite Salvador Allende’s Popular Unity party having increased their congressional election votes to 44 percent in March 1973 (up from 36 percent in 1970) merely six months before the coup, there was little he could do to prevent the military from defecting [124]. This intentional and covertly coordinated subversion was followed by 17 years of militar","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.04.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"Gradual or accumulative loss of control risks can be described as risks resulting from the accumulation of less severe disruptions that gradually weakens systemic resilience until a critical event triggers a catastrophe [12], [127].\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"68.04.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Multi-agent • Linearity: Non-linear • Reach: Internalized • Order: Variable\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":5,"subdomain":"5.2"},{"ev_id":"68.04.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"The key characteristics of this risk is that it is not caused by a single agent leading to a single defining event, instead, it is primarily about its multi-agentic and non-linear nature, where the deep integration of AIs into society leads to structural and systemic weakness.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.04.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"A hazard like AIs with general capabilities may be viewed positively due to its potential societal benefits. However, in this risk pathway, this hazard could lead to the event of AI displacing human labor, which can result in humans losing autonomy...gradual loss of control happens when AI capability leads to its widespread use, consequently displacing humans from economically viable jobs and leaving humans unable to afford basic survival needs. Assuming the hazard is AIs capable at various tasks, risk management is difficult to be performed upstream, as this dual-use hazard is largely desira","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.04.00d","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Gradual loss of control","risk_subcategory":null,"description":"\"On 6th May 2010, in an incident later known as the 2010 Flash Crash, leading U.S. stock indices abruptly fell and rebounded in less than half an hour, in the process erasing almost $1 trillion in market value. An investigation by the Security Exchange Commission found that a single order of large amounts of E-mini S&P contracts and subsequent selling orders by high-frequency algorithms triggered the drastic decline of market value [129], [130]. This event demonstrated the problem of algorithmic collision, where an increasing deployment of algorithms interacting with each other can lead to unf","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.05.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"AI models are often trained using large amounts of computation. This process is very energy intensive, potentially leading to significant greenhouse emissions depending on the energy sources [132]. Experts believe drastically increasing carbon emissions could accelerate climate change, which may constitute a catastrophic risk [133].\"","entity":"Other","intent":"Unintentional","timing":"Pre-deployment","domain":6,"subdomain":"6.6"},{"ev_id":"68.05.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Variable • Linearity: Linear • Reach: Externalized • Order: First-order\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.05.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"The key characteristic of environmental risks resulting from AI is that it is an externality, where those who suffer from the outcome include third parties who are not directly part of the value chain.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.05.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"In contrast to the previous risks, this hazard is not tied to AI model capabilities. Here, the hazard is energy-intensive data centers, which can lead to increased carbon emissions if they consume carbon-intensive energy sources. Because this risk is realized cumulatively over time, there is no single event that triggers the harm; it is a continuous process.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.05.00d","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Environmental risk","risk_subcategory":null,"description":"\"In 1974, [134] proposed that stratospheric ozone might be destroyed by industrially produced substances including chlorofluorocarbons (CFC) which are commonly used in refrigerators and air conditioners. This ozone depletion is believed to have led to an increase in global skin cancer prevalence through overexposure to the sun, posing a significant world-wide health burden [135]. To manage this externality, the Montreal Protocol, a global agreement to phase out chemicals that led to the ozone depletion, was eventually signed in 1987 and entered into force in 1989 [136]. Prior to the Montreal P","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.06.00","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Risk Category","risk_category":"Geopolitical risk","risk_subcategory":null,"description":"\"As AI is increasingly seen as a powerful technology, countries are racing to develop it ahead of their geopolitical rivals, a competition that could lead to geopolitical tensions [138], [139]... The emphasis of this risk is on harms that result from second-order effects, where geopolitical instabilities result from the race to develop AI, rather than on the direct consequences of the deployment or use of AI itself.\"","entity":"Other","intent":"Unintentional","timing":"Other","domain":6,"subdomain":"6.4"},{"ev_id":"68.06.00a","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Geopolitical risk","risk_subcategory":null,"description":"\"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Variable • Linearity: Non-linear • Reach: Externalized • Order: Second-order\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.06.00b","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Geopolitical risk","risk_subcategory":null,"description":"\"For this risk, the designation of a hazard and event is less straightforward, primarily because it is a second-order effect. Unlike other hazards that can be neutral, a destabilized geopolitical environment is inherently undesirable. Furthermore, the mechanism for hazard release is difficult to predict, as minor unexpected triggers can rapidly escalate into larger events.\"","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null},{"ev_id":"68.06.00c","quick_ref":"Chin2025","paper_title":"Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks","level":"Additional evidence","risk_category":"Geopolitical risk","risk_subcategory":null,"description":"\"Unlike many other wars where states fought over land and resources, the Cold War was primarily an ideological confrontation, where both the U.S. and the Soviet Union sought to establish global supremacy of their desired political and economic models. Though it did not result in direct military engagement between the two major powers, this conflict frequently led to widespread proxy wars across various regions such as Vietnam and Afghanistan [140]. While the causes of these proxy wars were often rooted in complex local and regional dynamics, their scale and intensity were significantly exacerb","entity":null,"intent":null,"timing":null,"domain":null,"subdomain":null}]}