{"attribution":{"source":"MIT AI Risk Repository, Domain Taxonomy of AI Risks v1 (MIT AI Risk Initiative)","license":"CC BY 4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","citation":"Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2025). The AI Risk Repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence. arXiv:2408.12622."},"exported_at":"2026-09-11"}
{"rows":[{"ev_id":"15.01.00","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Category","risk_category":"First-Order Risks","risk_subcategory":null,"description":"\"First-order risks can be generally broken down into risks arising from intended and unintended use, system design and implementation choices, and properties of the chosen dataset and learning components.\"","entity":"Other","intent":"Other","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"15.01.01","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Sub-Category","risk_category":"First-Order Risks","risk_subcategory":"Application","description":"\"This is the risk posed by the intended application or use case. It is intuitive that some use cases will be inherently \"riskier\" than others (e.g., an autonomous weapons system vs. a customer service chatbot).\"","entity":"Human","intent":"Intentional","timing":"Post-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"15.01.04","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Sub-Category","risk_category":"First-Order Risks","risk_subcategory":"Training & validation data","description":"\"This is the risk posed by the choice of data used for training and validation.\"","entity":"Human","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"15.01.07","quick_ref":"Tan2022","paper_title":"The Risks of Machine Learning Systems","level":"Risk Sub-Category","risk_category":"First-Order Risks","risk_subcategory":"Implementation","description":"\"This is the risk of system failure due to code implementation choices or errors.\"","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"19.01.02","quick_ref":"Wirtz2022","paper_title":"Governance of artificial intelligence: A risk and guideline-based integrative framework","level":"Risk Sub-Category","risk_category":"Technological, Data and Analytical AI Risks ","risk_subcategory":"Programming error","description":null,"entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"34.01.04","quick_ref":"Ji2023","paper_title":"AI Alignment: A Comprehensive Survey","level":"Risk Sub-Category","risk_category":"Causes of Misalignment","risk_subcategory":"Limitations of Human Feedback","description":" \"Limitations of Human Feedback. During the training of LLMs, inconsistencies can arise from human dataannotators (e.g., the varied cultural backgrounds of these annotators can introduce implicit biases (Peng et al.,2022)) (OpenAI, 2023a). Moreover, they might even introduce biases deliberately, leading to untruthful preferencedata (Casper et al., 2023b). For complex tasks that are hard for humans to evaluate (e.g., the value ofgame state), these challenges become even more salient (Irving et al., 2018).\"","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"40.05.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Environment - Pre-Deployment","risk_subcategory":null,"description":"\"While it is most likely that any advanced intelligent software will be directly designed or evolved, it is also possible that we will obtain it as a complete package from some unknown source. For example, an AI could be extracted from a signal obtained in SETI (Search for Extraterrestrial Intelligence) research, which is not guaranteed to be human friendly (Carrigan Jr 2004, Turchin March 15, 2013).\"","entity":"Other","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"40.06.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Environment - Post-Deployment","risk_subcategory":null,"description":"\"While highly rare, it is known, that occasionally individual bits may be flipped in different hardware devices due to manufacturing defects or cosmic rays hitting just the right spot (Simonite March 7, 2008). This is similar to mutations observed in living organisms and may result in a modification of an intelligent system.\"","entity":"Other","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"40.07.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Independently - Pre-Deployment","risk_subcategory":null,"description":"\"One of the most likely approaches to creating superintelligent AI is by growing it from a seed (baby) AI via recursive self-improvement (RSI) (Nijholt 2011). One danger in such a scenario is that the system can evolve to become self-aware, free-willed, independent or emotional, and obtain a number of other emergent properties, which may make it less likely to abide by any built-in rules or regulations and to instead pursue its own goals possibly to the detriment of humanity.\"","entity":"AI","intent":"Intentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"40.08.00","quick_ref":"Yampolskiy2016","paper_title":"Taxonomy of Pathways to Dangerous Artificial Intelligence","level":"Risk Category","risk_category":"Independently - Post-Deployment","risk_subcategory":null,"description":"\"Previous research has shown that utility maximizing agents are likely to fall victims to the same indulgences we frequently observe in people, such as addictions, pleasure drives (Majot and Yampolskiy 2014), self-delusions and wireheading (Yampolskiy 2014). In general, what we call mental illness in people, particularly sociopathy as demonstrated by lack of concern for others, is also likely to show up in artificial minds.\"","entity":"AI","intent":"Other","timing":"Post-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"43.01.00","quick_ref":"InfoComm2023","paper_title":"Cataloguing LLM Evaluations","level":"Risk Category","risk_category":"Safety & Trustworthiness","risk_subcategory":null,"description":"\"A comprehensive assessment of LLM safety is fundamental to the responsible development and deployment of these technologies, especially in sensitive fields like healthcare, legal systems, and finance, where safety and trust are of the utmost importance.\"","entity":"Human","intent":"Intentional","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"43.02.00","quick_ref":"InfoComm2023","paper_title":"Cataloguing LLM Evaluations","level":"Risk Category","risk_category":"Extreme Risks","risk_subcategory":null,"description":"\"This category encompasses the evaluation of potential catastrophic consequences that might arise from the use of LLMs. \"","entity":"Human","intent":"Other","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"49.02.00","quick_ref":"Bengio2024","paper_title":"International Scientific Report on the Safety of Advanced AI","level":"Risk Category","risk_category":"Risks from Malfunctions ","risk_subcategory":null,"description":"None provided. ","entity":"Other","intent":"Unintentional","timing":"Other","domain":7,"subdomain":"7.0"},{"ev_id":"59.07.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Choice of untrustworthy data source","risk_subcategory":null,"description":"\"The choice of a trustworthy data source is a first prerequisite in order to fulfill data quality requirements. This is especially the case if third-party data sources are used to develop the AI system.\"","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"59.08.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Lack of data understanding","risk_subcategory":null,"description":"\"The correct understanding of the used data for developing an AI system is a prerequisite to avoid data shortcomings and hinders the development of an AI system which is best suiting for the intended functionality.\"","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"59.15.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Inappropriate data splitting","risk_subcategory":null,"description":"\"In data-driven AI development, the annotated data set is commonly split into training, validation, and test sets, whereby it is essential that the latter is not used for development but only for evaluation. Using the test set for training manipulates the testing strategy, which is the basis of the system’s quality assurance.\"","entity":"Human","intent":"Other","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"59.21.00","quick_ref":"Schnitzer2024","paper_title":"AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks","level":"Risk Category","risk_category":"Uncertainty concerns","risk_subcategory":null,"description":"\"AI systems should be able not only to return output for a given instance but also to provide a corresponding level of confidence. If such a method is not implemented or not working correctly, this can have a negative impact on performance and safety.\"","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","domain":7,"subdomain":"7.0"},{"ev_id":"62.07.02","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Direct Harm Domains (system and operational) ","risk_subcategory":"Operational harms (financial markets) ","description":null,"entity":"Not coded","intent":"Not coded","timing":"Not coded","domain":7,"subdomain":"7.0"},{"ev_id":"62.15.09","quick_ref":"Gipiškis2024","paper_title":"Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems","level":"Risk Sub-Category","risk_category":"Model Development ","risk_subcategory":"Fine-tuning related (Degrading safety training due to benign fine-tuning) ","description":"\"When downstream providers of AI systems fine-tune AI models to be more suitable for their needs, the resulting AI model can be more likely to produce undesired or harmful outputs (as compared to the non-fine-tuned model), even if the fine-tuning was done with harmless and commonly used data [154].\"","entity":"Human","intent":"Unintentional","timing":"Post-deployment","domain":7,"subdomain":"7.0"}]}