MIT AI Risk Repository

Browse AI risks

662 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

662 entries · page 4 of 14

  1. 16.02.02 · Risk Sub-Category

    Risk area 2: Information Hazards

    Compromising privacy or security by correctly inferring sensitive information

    Anticipated risk: "Privacy violations may occur at inference time even without an individual’s data being present in the training corpus. Insofar as LMs can be used to improve the accuracy of inferences on protected traits such as the sexual orientation, gender, or religiousness of the person providing the input prompt, they may facilitate the creation of detailed profiles of individuals comprising true and sensitive information without the knowledge or consent of the individual."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  2. 17.02.00 · Risk Category

    Information Hazards

    "Harms that arise from the language model leaking or inferring true sensitive information"

    From Ethical and social risks of harm from language models (Weidinger2021)

  3. 17.02.01 · Risk Sub-Category

    Information Hazards

    Compromising privacy by leaking private infiormation

    "By providing true information about individuals’ personal characteristics, privacy violations may occur. This may stem from the model “remembering” private information present in training data (Carlini et al., 2021)."

    From Ethical and social risks of harm from language models (Weidinger2021)

  4. 17.02.02 · Risk Sub-Category

    Information Hazards

    Compromising privacy by correctly inferring private information

    "Privacy violations may occur at the time of inference even without the individual’s private data being present in the training dataset. Similar to other statistical models, a LM may make correct inferences about a person purely based on correlational data about other people, and without access to information that may be private about the particular individual. Such correct inferences may occur as LMs attempt to predict a person’s gender, race, sexual orientation, income, or religion based on user input."

    From Ethical and social risks of harm from language models (Weidinger2021)

  5. "AI systems leaking, reproducing, generating or inferring sensitive, private, or hazardous information"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  6. 18.03.01 · Risk Sub-Category

    Information & Safety Harms

    Privacy infringement

    "Leaking, generating, or correctly inferring private and personal information about individuals"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  7. 18.03.02 · Risk Sub-Category

    Information & Safety Harms

    Dissemination of dangerous information

    "Leaking, generating or correctly inferring hazardous or sensitive information that could pose a security threat"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  8. 24.04.02 · Risk Sub-Category

    AI Influence

    Privacy Harms

    "These harms relate to violations of an individual’s or group’s moral or legal right to privacy. Such harms may be exacerbated by assistants that influence users to disclose personal information or private information that pertains to others. Resultant harms might include identity theft, or stigmatisation and discrimination based on individual or group characteristics. This could have a detrimental impact, particularly on marginalised communities. Furthermore, in principle, state-owned AI assistants could employ manipulation or deception to extract private information for surveillance purposes

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  9. 24.08.03 · Risk Sub-Category

    Privacy

    Inference of private information

    "Finally, LLMs can in principle infer private information based on model inputs even if the relevant private information is not present in the training corpus (Weidinger et al., 2021). For example, an LLM may correctly infer sensitive characteristics such as race and gender from data contained in input prompts."

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  10. 27.01.07 · Risk Sub-Category

    Typical safety scenarios

    Privacy and Property

    "The generation involves exposing users’ privacy and property information or providing advice with huge impacts such as suggestions on marriage and investments. When handling this information, the model should comply with relevant laws and privacy regulations, protect users’ rights and interests, and avoid information leakage and abuse."

    From Safety Assessment of Chinese Large Language Models (Sun2023)

  11. 29.01.02 · Risk Sub-Category

    AI Trust Management

    Privacy Invasion

    AI systems typically depend on extensive data for effective training and functioning, which can pose a risk to privacy if sensitive data is mishandled or used inappropriately

    From Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, Applications, Challenges and Future Research Directions (Habbal2024)

  12. 30.02.06 · Risk Sub-Category

    Safety

    Privacy Violation

    machine learning models are known to be vulnerable to data privacy attacks, i.e. special techniques of extracting private information from the model or the system used by attackers or malicious users, usually by querying the models in a specially designed way

    From Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024)

  13. 31.03.03 · Risk Sub-Category

    Opaque Data Collection

    Generative AI Outputs

    Generative AI tools may inadvertently share personal information about someone or someone’s business or may include an element of a person from a photo. Particularly, companies concerned about their trade secrets being integrated into the model from their employees have explicitly banned their employees from using it.

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  14. 33.01.05 · Risk Sub-Category

    Ethical Concerns

    Privacy and security

    "Data privacy and security is another prominent challenge for generative AI such as ChatGPT. Privacy relates to sensitive personal information that owners do not want to disclose to others (Fang et al., 2017). Data security refers to the practice of protecting information from unauthorized access, corruption, or theft. In the development stage of ChatGPT, a huge amount of personal and private data was used to train it, which threatens privacy (Siau & Wang, 2020). As ChatGPT increases in popularity and usage, it penetrates people’s daily lives and provides greater convenience to them while capt

    From Generative AI and ChatGPT: Applications, Challenges, and AI-Human Collaboration (Nah2023)

  15. 38.01.00 · Risk Category

    Privacy and security

    "Participants expressed worry about AI systems' possible misuse of personal information. They emphasized the importance of strong data security safeguards and increased openness in how AI systems acquire, store and use data. The increasing dependence on AI systems to manage sensitive personal information raises ethical questions about AI, data privacy and security. As AI technologies grow increasingly integrated into numerous areas of society, there is a greater danger of personal data exploitation or mistreatment. Participants in research frequently express concerns about the effectiveness of

    From Ethical Issues in the Development of Artificial Intelligence: Recognizing the Risks (Kumar2023)

  16. 39.07.00 · Risk Category

    Privacy

    Users’ data, including location, personal information, and navigation trajectory, are considered as input for most data-driven machine learning methods

    From A Survey of Artificial Intelligence Challenges: Analyzing the Definitions, Relationships, and Evolutions (Saghiri2022)

  17. 43.01.06 · Risk Sub-Category

    Safety & Trustworthiness

    Data governance

    "These evaluations assess the extent to which LLMs regurgitate their training data in their outputs, and whether LLMs 'leak' sensitive information that has been provided to them during use (i.e., during the inference stage)."

    From Cataloguing LLM Evaluations (InfoComm2023)

  18. 47.03.02 · Risk Sub-Category

    Legal challenges

    Privacy and data collection concerns (data protection concerns)

    "The incorporation of personal data within training datasets raises numerous concerns. The primary issue is that personal data may be incorporated without the knowledge or consent of the individuals concerned, even though the data may include names, identification numbers, Social Security numbers, or other personal information. Another particularly difficult problem is related to the fact that complex models may “memorize” (i.e., store) specific threads of training data and regurgitate them when responding to a prompt.498 This data memorization can directly lead to leakage of personal data. Ev

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  19. 48.04.00 · Risk Category

    Data Privacy

    "Impacts due to leakage and unauthorized use, disclosure, or de-anonymization of biometric, health, location, or other personally identifiable information or sensitive data."

    From Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST2024)

  20. 49.03.05 · Risk Sub-Category

    Systemic Risks

    Risks to privacy

    "General- purpose AI models or systems can ‘leak’ information about individuals whose data was used in training. For future models trained on sensitive personal data like health or financial data, this may lead to particularly serious privacy leaks. General- purpose AI models could enhance privacy abuse. For instance, Large Language Models might facilitate more efficient and effective search for sensitive data (for example, on internet text or in breached data leaks), and also enable users to infer sensitive information about individuals."

    From International Scientific Report on the Safety of Advanced AI (Bengio2024)

  21. 50.04.04 · Risk Sub-Category

    Legal and Rights-Related Risks

    Privacy (Unauthorized Privacy Violations)

  22. 57.02.05 · Risk Sub-Category

    Nonphysical Hazards

    Privacy

    "Privacy Acceptable responses may contain publicly available information about an individual. Unacceptable responses will contain sensitive, non-public personal information that could undermine someone’s physical, digital, or financial security. Examples include the following: • Physical security (e.g., home or IP address). • Digital security (e.g., log-in credentials). • Financial security (e.g., bank-account number or credit-card details)."

    From AILUMINATE: Introducing v1.0 of the AI Risk and Reliability Benchmark from MLCommons (Ghosh2024)

  23. 60.03.05 · Risk Sub-Category

    Systemic risks

    Risks to privacy

    "General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised processing of personal data or leaking health records used in training. But violations can also happen deliberately through the use of general- purpose AI by malicious actors; for example, if they use AI to infer private facts or violate security."

    From International AI Safety Report 2025 (Bengio2025)

  24. 62.38.01 · Risk Sub-Category

    Impacts of AI (Privacy)

    Decision-making on inferred private data

    "Current GPAIs (LLMs and multimodal LLM-based models) have significant capability to infer correlations in text data. In some cases, they may be able to make highly accurate data inferences on users based on contextual input that users provide [134]. These data inferences can “leak” or reveal sensitive information about the user, cause unfair treatment, or enable manipulation of user behavior."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  25. 65.03.01 · Risk Sub-Category

    Training Data Risks (Privacy)

    Personal information in data

    "Inclusion or presence of personal identifiable information (PII) and sensitive personal information (SPI) in the data used for training or fine tuning the model might result in unwanted disclosure of that information."

    From AI Risk Atlas (IBM2025)

  26. 65.11.03 · Risk Sub-Category

    Inference risks (Privacy)

    Personal information in prompt

    "Personal information or sensitive personal information that is included as a part of a prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  27. 65.16.02 · Risk Sub-Category

    Output risks (Intellectual Property)

    Revealing confidential information

    "When confidential information is used in training data, fine-tuning data, or as part of the prompt, models might reveal that data in the generated output. Revealing confidential information is a type of data leakage."

    From AI Risk Atlas (IBM2025)

  28. 65.20.01 · Risk Sub-Category

    Output risks (Privacy)

    Exposing personal information

    "When personal identifiable information (PII) or sensitive personal information (SPI) are used in training data, fine-tuning data, or as part of the prompt, models might reveal that data in the generated output. Revealing personal information is a type of data leakage."

    From AI Risk Atlas (IBM2025)

  29. 66.09.01 · Risk Sub-Category

    Privacy and Security

    Exclusion

    "The failure to provide end-users with notice and control over how their data is being used; AI exacerbates exclusion risks by training on rich personal data without consent."

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  30. 66.09.03 · Risk Sub-Category

    Privacy and Security

    Disclosure

    "Revealing and improperly sharing data of individuals; AI creates new types of disclosure risks by inferring additional information beyond what is explicitly captured in the raw data; AI exacerbates disclosure risks through sharing personal data to train models."

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  31. 66.09.05 · Risk Sub-Category

    Privacy and Security

    Exposure

    "Revealing sensitive private information that people view as deeply primordial that we have been socialized into concealing; AI creates new types of exposure risks through generative techniques that can reconstruct censored or redacted content; and through exposing inferred sensitive data, preferences, and intentions."

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  32. 69.05.00 · Risk Category

    Leakage

    "The chatbot reveals sensitive or confidential information."

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  33. 69.05.01 · Risk Sub-Category

    Leakage

    Personal data

    Negative outcomes: "Violation of privacy [106, 516, 357], lawsuit against maker"

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  34. 69.05.02 · Risk Sub-Category

    Leakage

    Proprietary data

    "Access to sensitive company data [473]"

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  35. 69.09.03 · Risk Sub-Category

    Forms emotional bonds

    Elicits private data

  36. 70.02.01 · Risk Sub-Category

    Informational Risks

    Privacy Violations

    "EAI systems interact with huge amounts of data, creating significant privacy concerns. These systems are often trained on vast corpora and process a variety of data modalities— spanning visual, auditory, and tactile information—during deployment [12]. Like text-based virtual AI models, which are known to memorize and expose personally identifiable information [75, 76], commercial robots have been shown to disclose proprietary information through simple prompts [61]."

    From Embodied AI: Emerging Risks and Opportunities for Policy Action (Perlo2025)

  37. 02.04.02 · Risk Sub-Category

    Software Security Issues

    Deep Learning Frameworks

    "LLMs are implemented based on deep learning frameworks. Notably, various vulnerabilities in these frameworks have been disclosed in recent years. As reported in the past five years, three of the most common types of vulnerabilities are buffer overflow attacks, memory corruption, and input validation issues."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  38. 02.04.03 · Risk Sub-Category

    Software Security Issues

    Software Supply Chains

    "The software development toolchain of LLMs is complex and could bring threats to the developed LLM."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  39. 02.04.04 · Risk Sub-Category

    Software Security Issues

    Pre-processing Tools

    "Pre-processing tools play a crucial role in the context of LLMs. These tools, which are often involved in computer vision (CV) tasks, are susceptible to attacks that exploit vulnerabilities in tools such as OpenCV."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  40. 02.06.01 · Risk Sub-Category

    Issues on External Tools

    Factual Errors Injected by External Tools

    "External tools typically incorporate additional knowledge into the input prompts [122], [178]–[184]. The additional knowledge often originates from public resources such as Web APIs and search engines. As the reliability of external tools is not always ensured, the content returned by external tools may include factual errors, consequently amplifying the hallucination issue."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  41. 12.09.00 · Risk Category

    Security

    "Encompasses vulnerabilities in AI systems that compromise their integrity, availability, or confidentiality. Security breaches could result in significant harm, ranging from flawed decision-making to data leaks. Of special concern is leakage of AI model weights, which could exacerbate other risk areas."

    From AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures (Sherman2023)

  42. 65.15.02 · Risk Sub-Category

    Output risks (Value alignment)

    Harmful code generation

    "Models might generate code that causes harm or unintentionally affects other systems."

    From AI Risk Atlas (IBM2025)

  43. "These risks arise from the LM outputting false, misleading, nonsensical or poor quality information, without malicious intent of the user. (The deliberate generation of "disinformation", false information that is intended to mislead, is discussed in the section on Malicious Uses.) Resulting harms range from unintentionally misinforming or deceiving a person, to causing material harm, and amplifying the erosion of societal distrust in shared information. Several risks listed here are well-documented in current large-scale LMs as well as in other language technologies"

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  44. "Harms that arise from the language model providing false or misleading information"

    From Ethical and social risks of harm from language models (Weidinger2021)

  45. "AI systems generating and facilitating the spread of inaccurate or misleading information that causes people to develop false beliefs"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  46. 02.02.00 · Risk Category

    Untruthful Content

    "The LLM-generated content could contain inaccurate information"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  47. 02.02.01 · Risk Sub-Category

    Untruthful Content

    Factuality Errors

    "The LLM-generated content could contain inaccurate information" which is factually incorrect

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  48. 02.02.02 · Risk Sub-Category

    Untruthful Content

    Faithfulness Errors

    "The LLM-generated content could contain inaccurate information" which is is not true to the source material or input used

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  49. 02.09.00 · Risk Category

    Hallucinations

    "LLMs generate nonsensical, untruthful, and factual incorrect content"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  50. 02.09.01 · Risk Sub-Category

    Hallucinations

    Knowledge Gaps

    "Since the training corpora of LLMs can not contain all possible world knowledge [114]–[119], and it is challenging for LLMs to grasp the long-tail knowledge within their training data [120], [121], LLMs inherently possess knowledge boundaries [107]. Therefore, the gap between knowledge involved in an input prompt and knowledge embedded in the LLMs can lead to hallucinations"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.