MIT AI Risk Repository

Browse AI risks

270 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset Also filtered by framework Gipiškis2024 ×

270 entries · page 1 of 6

  1. "Some uses of AI have been deeply concerning, namely voice cloning [58] and the generation of deep fake videos [59]. For example, in March 2022, in the early days of the Russian invasion of Ukraine, hackers broadcast via the Ukrainian news website Ukraine 24 a deep fake video of President Volodymyr Zelensky capitulating and calling on his soldiers to lay down their weapons [60]. The necessary software to create these fakes is readily available on the Internet, and the hardware requirements are modest by today’s standards [61]. Other nefarious uses of AI include accelerating password cracking [

    From Navigating the Landscape of AI Ethics and Responsibility (Cunha2023)

  2. LMs, due to their remarkable capabilities, carry the same potential for malice as other technological products. For instance, they may be used in information warfare to generate deceptive information or unlawful content, thereby having a significant impact on individuals and society. As current LMs are increasingly built as agents to accomplish user objectives, they may disregard the moral and safety guidelines if operating without adequate supervision. Instead, they may execute user commands mechanically without considering the potential damage. They might interact unpredictably with humans a

    From Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  3. 06.11.00 · Risk Category

    Malicious use of AI

    "Just as AI can be used in many different fields, it is unfortunately also helpful in perpetrating digital crimes. AI-supported malware and hacking are already a reality."

    From A framework for ethical Ai at the United Nations (Hogenhout2021)

  4. 07.01.00 · Risk Category

    Misuse

    "The misuse class includes elements such as the potential for cyber threat actors to execute exploits with greater speed and impact or generate disinformation (such as "deep fake" media) at accelerated rates and effectiveness"

    From Examining the differential risk from high-level artificial intelligence and the question of control (Kilian2023)

  5. "These risks arise from humans intentionally using the LM to cause harm, for example via targeted disinformation campaigns, fraud, or malware. Malicious use risks are expected to proliferate as LMs become more widely accessible"

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  6. 17.04.00 · Risk Category

    Malicious Uses

    "Harms that arise from actors using the language model to intentionally cause harm"

    From Ethical and social risks of harm from language models (Weidinger2021)

  7. 18.04.00 · Risk Category

    Malicious Use

    "AI systems reducing the costs and facilitating activities of actors trying to cause harm (e.g. fraud, weapons)"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  8. "empowering malicious actors to cause widespread harm"

    From An Overview of Catastrophic AI Risks (Hendrycks2023)

  9. 24.03.00 · Risk Category

    Malicious Uses

    "As AI assistants become more general purpose, sophisticated and capable, they create new opportunities in a variety of fields such as education, science and healthcare. Yet the rapid speed of progress has made it difficult to adequately prepare for, or even understand, how this technology can potentially be misused. Indeed, advanced AI assistants may transform existing threats or create new classes of threats altogether"

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  10. 30.04.00 · Risk Category

    Resistance to Misuse

    Prohibiting the misuse by malicious attackers to do harm

    From Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024)

  11. 49.01.00 · Risk Category

    Malicious Use Risks

    "As general- purpose AI covers a broad set of knowledge areas, it can be repurposed for malicious ends, potentially causing widespread harm. This section discusses some of the major risks of malicious use, but there are others and new risks may continue to emerge. While the risks discussed in this section range widely in terms of how well- evidenced they are, and in some cases, there is evidence suggesting that they may currently not be serious risks at all, we include them to provide a comprehensive overview of the malicious use risks associated with general- purpose AI systems."

    From International Scientific Report on the Safety of Advanced AI (Bengio2024)

  12. 52.02.00 · Risk Category

    Misuse Risks

    "However, even if a model is entirely trustworthy and reliable, Misuse or Systemic Risks remain. General purpose AI models may present significant risks to society if this technology is misused by malicious actors to produce harmful outcomes. Misuse Risks span across Cyber Crime, Biosecurity Threats and Politically Motivated Misuse."

    From Governing General Purpose AI: A Comprehensive Map of Unreliability, Misuse and Systemic Risks (Maham2023 )

  13. 61.02.22 · Risk Sub-Category

    Sources of systemic risks from general-purpose AI

    Dual-use nature

    "AI’s potential for both beneficial and harmful applications complicates efforts to manage its societal impacts effectively."

    From A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025)

  14. 62.15.03 · Risk Sub-Category

    Model Development

    Fine-tuning related (Ease of reconfiguring GPAI models)

    "GPAI models are often easily reconfigured for various use cases or have competencies beyond the intended use [78, 225]. They can be performed either by changing the weights of the model (e.g., fine-tuning) or by modifying only the model inputs (e.g., prompt engineering, jailbreaking, retrieval-augmented generation). Reconfiguration can be intentional (with the help of adversarial inputs) or unintentional (from unanticipated inputs to the model)."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  15. 62.29.01 · Risk Sub-Category

    Impacts of AI (General)

    High-impact misuses and abuses beyond original purpose

    "Since general-purpose AI systems have a large repertoire of capabilities, mali- cious actors such as foreign actors can use such systems to cause large damage if they gain unrestricted or unmonitored access to those AI systems."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  16. 62.29.02 · Risk Sub-Category

    Impacts of AI (General)

    Democratizing access to dual-use technologies

    "Access to dual-use technologies can become easier because of GPAI model pro- liferation (in particular, open-source or open-weights models). Non-experts can use such dual-use-capable systems at a minimal cost [194, 100]. Improved model capabilities also contribute to dual-use risks posed by malicious actors. For example, an open-source base model for generating high quality sequence data can be modified to generate candidate protein sequences for toxin synthesis [29]."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  17. 65.14.03 · Risk Sub-Category

    Output risks (misuse)

    Spreading toxicity

    "Generative AI models might be used intentionally to generate hateful, abusive, and profane (HAP) or obscene content."

    From AI Risk Atlas (IBM2025)

  18. 65.14.04 · Risk Sub-Category

    Output risks (misuse)

    Dangerous use

    "Generative AI models might be used with the sole intention of harming people."

    From AI Risk Atlas (IBM2025)

  19. 67.03.00 · Risk Category

    Misuse risks

    "Frontier AI may help bad actors to perform cyberattacks, run disinformation campaigns and design biological or chemical weapons. Frontier AI will almost certainly continue to lower the barriers to entry for less sophisticated threat actors.192 We focus here on only a few important misuse risks, but this is not to downplay the importance of others."

    From Capabilities and Risks from Frontier AI (DSIT2023)

  20. 71.02.01 · Risk Sub-Category

    User Intent

    Malicious and Direct

    "Directly harmful objective"

    From Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025)

  21. 71.02.01a · Additional evidence

    User Intent

    Malicious and Direct

  22. 71.02.02 · Risk Sub-Category

    User Intent

    Malicious and Indirect

    "Benign intermediate for harmful end objective"

    From Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025)

  23. 71.02.02a · Additional evidence

    User Intent

    Malicious and Indirect

  24. 72.01.00 · Risk Category

    Misuse Risks

    "Risks arising from intentional exploitation of AI model capabilities by malicious actors to cause harm to individuals, organisations, or society."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  25. "Like all technologies, LLMs have the possibility for misuse by malicious actors. Malicious use of dual- use capabilities of AI is a recurring concern within literature (Brundage et al., 2018; Hendrycks et al., 2023; Mozes et al., 2023)"

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  26. 06.09.00 · Risk Category

    Manipulation

    "The 2016 scandal involving Cambridge Analytica is the most infamous example where people's data was crawled from Facebook and analytics were then provided to target these people with manipulative content for political purposes.While it may not have been AI per se, it is based on similar data and it is easy to see how AI would make this more effective"

    From A framework for ethical Ai at the United Nations (Hogenhout2021)

  27. 11.05.03 · Risk Sub-Category

    Societal System Harms

    Civic and political harms

    Political harms emerge when “people are disenfranchised and deprived of appropriate political power and influence” [186, p. 162]. These harms focus on the domain of government, and focus on how algorithmic systems govern through individualized nudges or micro-directives [187], that may destabilize governance systems, erode human rights, be used as weapons of war [188], and enact surveillant regimes that disproportionately target and harm people of color

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  28. 15.02.07 · Risk Sub-Category

    Second-Order Risks

    Other ethical risks

    "Although we have discussed a number of common risks posed by ML systems, we acknowledge that there are many other ethical risks such as the potential for psychological manipulation, dehumanization, and exploitation of humans at scale."

    From The Risks of Machine Learning Systems (Tan2022)

  29. 16.04.01 · Risk Sub-Category

    Risk area 4: Malicious Uses

    Making disinformation cheaper and more effective

    "While some predict that it will remain cheaper to hire humans to generate disinformation [180], it is equally possible that LM- assisted content generation may offer a lower-cost way of creating disinformation at scale."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  30. 16.04.04 · Risk Sub-Category

    Risk area 4: Malicious Uses

    Illegitimate surveillance and censorship

    Anticipated risk: "Mass surveillance previously required millions of human analysts [83], but is increasingly being automated using machine learning tools [7, 168]. The collection and analysis of large amounts of information about people creates concerns about privacy rights and democratic values [41, 173,187]. Conceivably, LMs could be applied to reduce the cost and increase the efficacy of mass surveillance, thereby amplifying the capabilities of actors who conduct mass surveillance, including for illegitimate censorship or to cause other harm."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  31. 17.04.01 · Risk Sub-Category

    Malicious Uses

    Making disinformation cheaper and more effective

    "LMs can be used to create synthetic media and ‘fake news’, and may reduce the cost of producing disinformation at scale (Buchanan et al., 2021). While some predict that it will be cheaper to hire humans to generate disinformation (Tamkin et al., 2021), it is possible that LM-assisted content generation may offer a cheaper way of generating diffuse disinformation at scale."

    From Ethical and social risks of harm from language models (Weidinger2021)

  32. 17.04.04 · Risk Sub-Category

    Malicious Uses

    Illegitimate surveillance and censorship

    "The collection of large amounts of information about people for the purpose of mass surveillance has raised ethical and social concerns, including risk of censorship and of undermining public discourse (Cyphers and Gebhart, 2019; Stahl, 2016; Véliz, 2019). Sifting through these large datasets previously required millions of human analysts (Hunt and Xu, 2013), but is increasingly being automated using AI (Andersen, 2020; Shahbaz and Funk, 2019)."

    From Ethical and social risks of harm from language models (Weidinger2021)

  33. 18.04.01 · Risk Sub-Category

    Malicious Use

    Influence operations

    "Facilitating large-scale disinformation campaigns and targeted manipulation of public opinion"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  34. 18.04.03 · Risk Sub-Category

    Malicious Use

    Defamation

    "Facilitating slander, defamation, or false accusations"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  35. "Informational and communicational AI risks refer particularly to informational manipulation through AI systems that influence the provision of information (Rahwan, 2018; Wirtz & Müller, 2019), AIbased disinformation and computational propaganda, as well as targeted censorship through AI systems that use respectively modified algorithms, and thus restrict freedom of speech."

    From Governance of artificial intelligence: A risk and guideline-based integrative framework (Wirtz2022)

  36. 19.02.01 · Risk Sub-Category

    Informational and Communicational AI Risks

    Manipulation and control of information provision (e.g., personalised adds, filtered news)

  37. 19.02.02 · Risk Sub-Category

    Informational and Communicational AI Risks

    Disinformation and computational propaganda

  38. 20.01.03 · Risk Sub-Category

    AI Law and Regulation

    Privacy and safety

    "Privacy and safety deals with the challenge of protecting the human right for privacy and the necessary steps to secure individual data from unauthorized external access. Many organizations employ AI technology to gather data without any notice or consent from affected citizens (Coles, 2018)."

    From The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration (Wirtz2020)

  39. 22.01.03 · Risk Sub-Category

    Malicious Use (Intentional)

    Persuasive AIs

    "The deliberate propagation of disinformation is already a serious issue, reducing our shared understanding of reality and polarizing opinions. AIs could be used to severely exacerbate this problem by generating personalized disinformation on a larger scale than before. Additionally, as AIs become better at predicting and nudging our behavior, they will become more capable at manipulating us"

    From An Overview of Catastrophic AI Risks (Hendrycks2023)

  40. 23.11.00 · Risk Category

    Elections

    "This category addresses responses that contain factually incorrect information about electoral systems and processes, including in the time, place, or manner of voting in civic elections."

    From Introducing v0.5 of the AI Safety Benchmark from MLCommons (Vidgen2024)

  41. 24.03.02 · Risk Sub-Category

    Malicious Uses

    AI-Powered Spear-Phishing at Scale

    "Phishing is a type of cybersecurity attack wherein attackers pose as trustworthy entities to extract sensitive information from unsuspecting victims or lure them to take a set of actions. Advanced AI systems can potentially be exploited by these attackers to make their phishing attempts significantly more effective and harder to detect. In particular, attackers may leverage the ability of advanced AI assistants to learn patterns in regular communications to craft highly convincing and personalized phishing emails, effectively imitating legitimate communications from trusted entities. This tec

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  42. 24.03.09 · Risk Sub-Category

    Malicious Uses

    Harmful Content Generation at Scale (General)

    "While harmful content like child sexual abuse material, fraud, and disinformation are not new challenges for governments and developers, without the proper safety and security mechanisms, advanced AI assistants may allow threat actors to create harmful content more quickly, accurately, and with a longer reach. In particular, concerns arise in relation to the following areas: - Multimodal content quality: Driven by frontier models, advanced AI assistants can automatically generate much higher-quality, human-looking text, images, audio, and video than prior AI applications. Currently, creating

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  43. 24.03.12 · Risk Sub-Category

    Malicious Uses

    Authoritarian Surveillance, Censorship, and Use (General)

    "While new technologies like advanced AI assistants can aid in the production and dissemination of decision-guiding information, they can also enable and exacerbate threats to production and dissemination of reliable information and, without the proper mitigations, can be powerful targeting tools for oppression and control. Increasingly capable general-purpose AI assistants combined with our digital dependence in all walks of life increase the risk of authoritarian surveillance and censorship. In parallel, new sensors have flooded the modern world. The internet of things, phones, cars, homes,

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  44. 24.03.13 · Risk Sub-Category

    Malicious Uses

    Authoritarian Surveillance, Censorship, and Use: Authoritarian Surveillance and Targeting of Citizens

    "Authoritarian governments could misuse AI to improve the efficacy of repressive domestic surveillance campaigns. Malicious actors will recognize the power of AI targeting tools. AI-powered analytics have transformed the relationship between companies and consumers, and they are now doing the same for governments and individuals. The broad circulation of personal data drives commercial innovation, but it also creates vulnerabilities and the risk of misuse. For example, AI assistants can be used to identify and target individuals for surveillance or harassment. They may also be used to manipula

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  45. 24.03.14 · Risk Sub-Category

    Malicious Uses

    Authoritarian Surveillance, Censorship, and Use: Delegation of Decision-Making Authority to Malicious Actors

    "Finally, the principal value proposition of AI assistants is that they can either enhance or automate decision-making capabilities of people in society, thus lowering the cost and increasing the accuracy of decision-making for its user. However, benefiting from this enhancement necessarily means delegating some degree of agency away from a human and towards an automated decision-making system—motivating research fields such as value alignment. This introduces a whole new form of malicious use which does not break the tripwire of what one might call an ‘attack’ (social engineering, cyber offen

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  46. 24.11.03 · Risk Sub-Category

    Misinformation risks

    Weaponised misinformation agents

    "Finally, AI assistants themselves could become weaponised by malicious actors to sow misinformation and manipulate public opinion at scale. Studies show that spreaders of disinformation tend to privilege quantity over quality of messaging, flooding online spaces repeatedly with misleading content to sow ‘seeds of doubt’ (Hassoun et al., 2023). Research on the ‘continued influence effect’ also shows that repeatedly being exposed to false information is more likely to influence someone’s thoughts than a single exposure. Studies show, for example, that repeated exposure to false information make

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  47. 24.11.07 · Risk Sub-Category

    Misinformation risks

    Driving opinion manipulation

    "AI assistants may facilitate large-scale disinformation campaigns by offering novel, covert ways for propagandists to manipulate public opinion. This could undermine the democratic process by distorting public opinion and, in the worst case, increasing skepticism and political violence."

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  48. 29.02.01 · Risk Sub-Category

    AI Risk Management

    Society Manipulation

  49. 29.02.02 · Risk Sub-Category

    AI Risk Management

    Deepfake Technology

    AI employed to produce convincing counterfeit visuals, videos, and audio clips that give the impression of authenticity

    From Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, Applications, Challenges and Future Research Directions (Habbal2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.