MIT AI Risk Repository
Browse AI risks
594 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
"Relying on general-purpose AI products that fail to fulfil their intended function can lead to harm. For example, general- purpose AI systems can make up facts (‘hallucination’), generate erroneous computer code, or provide inaccurate medical information. This can lead to physical and psychological harms to consumers and reputational, financial and legal harms to individuals and organisations."
-
62.14.02 · Risk Sub-Category
Data-related (Lack of cross-organizational documentation)
"When sharing data between multiple organizations, documentation may be missing or inadequate, making it difficult for other organizations to understand it. For example, a lack of metadata or a change in schema by a collaborating party can result in an unusable dataset and wasted data collection efforts, or it can lead to misunderstandings about the dataset’s limitations, resulting in downstream risks related to its use [173]."
-
62.14.03 · Risk Sub-Category
Data-related (Manipulation of data by non-domain experts)
"Manipulating data (e.g., training data) carries a set of assumptions on how the data should appear and be used by those performing the manipulation. Common manipulations applied on data in the context of AI models include defining the ground truth label and merging different data formats or sources. People who have little or no expertise in the domain of the data performing such manipulations may render the data unusable or harmful to the development of the AI system [173]."
-
"Laws and other restrictions can limit or prohibit the use of some data for specific AI use cases."
-
"Laws and other regulations might limit the collection of certain types of data for specific AI use cases."
-
"Laws and other restrictions can limit or prohibit transferring data."
-
"Data contamination occurs when incorrect data is used for training. For example, data that is not aligned with model’s purpose or data that is already set aside for other development tasks such as testing and evaluation."
-
"Using undesirable output (for example, inaccurate, inappropriate, and user content) for retraining purposes can result in unexpected model behavior."
-
"Improper collection and preparation of training or tuning data includes data label errors and by using data with conflicting information or misinformation."
-
"Poor model accuracy occurs when a model’s performance is insufficient to the task it was designed for. Low accuracy might occur if the model is not correctly engineered, or there are changes to the model’s expected inputs."
-
72.03.00 · Risk Category
"Risks arising from operational failures, model misjudgments, or improper human operation of AI systems deployed in safety-critical infrastructure, where single points of failure can trigger cascading catastrophic consequences."
-
"With the wide application of generative AI, the ability to interact with AI efficiently and effectively has become one of the most important media literacies. Hence, it is imperative for generative AI users to learn and apply the principles of prompt engineering, which refers to a systematic process of carefully designing prompts or inputs to generative AI models to elicit valuable outputs. Due to the ambiguity of human languages, the interaction between humans and machines through prompts may lead to errors or misunderstandings. Hence, the quality of prompts is important. Another challenge i
-
48.12.00 · Risk Category
"Non-transparent or untraceable integration of upstream third-party components, including data that has been improperly obtained or not processed and cleaned due to increased automation from GAI; improper supplier vetting across the AI lifecycle; or other issues that diminish transparency or accountability for downstream users."
-
51.06.00 · Risk Category
"How can we build agent’s whose decisions we can understand? Con- nects explainable decisions (Berkeley) and informed oversight (MIRI)."
-
59.04.00 · Risk Category
"Throughout the development of an AI system, it is vital to document every decision and action taken. This is not only essential to optimize the development process itself but also required for the auditability of the AI system."
-
59.05.00 · Risk Category
"The transparency to end users of the AI system increases the user’s trust in the AI application. If not adequately integrated into the design, this might prevent the proper operation and cause potential misuse of the AI application."
-
62.18.00 · Risk Category
—
-
"Content might not be clearly disclosed as AI generated."
-
"Lack of model transparency is due to insufficient documentation of the model design, development, and evaluation process and the absence of insights into the inner workings of the model."
-
"The literature suggests that throughout the development of an AI we may go through several generations of agents which do not perform as expected [37] [43]. In this case, such agents may be placed into a suspended state, terminated, or deleted. Further, we could propose scenarios where research funding for a facility running such agents is exhausted, resulting in the inadvertent termination of a project. In these cases, is deletion or termination of AI programs (the moral patient) by a moral agent an act of murder? This, an example of Robot Ethics, raises issues of personhood which parallel r
-
"Large-scale harms to animals and the development of AI capable of suffering."
-
63.06.00 · Risk Category
"Selection pressures (Section 3.3): some aspects of training and selection by those deploying and using AI agents can lead to undesirable behaviour;"
-
"Rigidity and Mistaken Commitments. Even when it is desirable to be able to make threats in order to deter socially harmful behaviour, doing so using AI agents effectively removes the human from the loop, which could prove disastrous in high-stakes contexts (e.g., a false positive in a nuclear sub- marine’s warning system; see also Case Study 11), or when irresponsible actors are enabled in making disproportionate or mistaken commitments."
-
"Swarm Attacks. The need for multi-agent security is foreshadowed by attacks today that benefit from the use of many decentralised agents, such as distributed denial-of-service attacks (Cisco, 2023; Yoachimik & Pacheco, 2024). Such attacks exploit the massive collective resources of individual low- resourced actors, chained into an attack that breaks the assumptions of bandwidth constraints on a single well-resourced agent."
-
47.02.00 · Risk Category
"Beyond the inherent risks associated with the technical characteristics of the technology, numerous additional risks emerge from the potential applications that technology enables. The deployment of AI by more or less well-intentioned individuals presents significant societal threats, several of which are outlined below. As the technology advances and its capabilities expand, these risks intensify."
-
53.04.02 · Risk Sub-Category
Indirect AI contributions to existential risks
Hazardous malicious uses
—
-
56.08.00 · Risk Category
—
-
56.09.00 · Risk Category
—
-
—
-
"Loss of life - Accidental or deliberate loss of life, including suicide, extinction or cessation, due to the use or misuse of a technology system."
-
"Financial/earnings loss - Loss of money, income or value due to the use or misuse of a technology system."
-
58.06.00 · Risk Category
"Human Rights and Civil Liberties - Use or misuse of a technology system in a manner that compromises fundamental human rights and freedoms."
-
"In contrast to technical AI hazards, socio-technical hazards also require hu- man input related to social and cultural aspects [45]. Human judgment must be employed when deciding on quantification and treatment methods. For instance, AI hazards concerning discrimination and privacy, which are abstract concepts lacking a uniform technical definition, further complicate a clear quantification of the associated risks. Although quantitative methods exist to assess and treat these AI hazards, they require coordination with social and cultural values [27]."
-
"The third axis of the taxonomy pertains to the level, which differentiates between the AI application and system levels, as they are defined in Section 3. Allocating an AI hazard to its level helps to determine the level at which an action is required. This consequently sets the basis for who is supposed to act."
-
"For instance, the main person responsible for an AI hazard manifesting on the AI system level would be the AI developer, whereas an AI hazard affecting the whole AI application requires a more diverse group, including domain experts."
-
"For instance, the main person responsible for an AI hazard manifesting on the AI system level would be the AI developer, whereas an AI hazard affecting the whole AI application requires a more diverse group, including domain experts."
-
61.02.16 · Risk Sub-Category
Sources of systemic risks from general-purpose AI
Conflicting objectives in design
"Designers and operators of AI may face conflicting objectives that compromise safety."
-
"A risk may be triggered by a human, where the AI serves merely as a tool, or by the AI acting autonomously with no human intervention, or it may involve a combination of both, with the human delegating some parts of decision-making to the AI. For risks where AI is the entity, these risks are exacerbated by an increase in the AI’s level of autonomy. To manage risks involving AI as the trigger, appropriate levels of human oversight can be built-in."
-
62.14.00 · Risk Category
-
-
62.16.00 · Risk Category
"This section catalogs the risk sources and risk management measures related to model evaluations (often called evals). We categorize them into the fol- lowing groups: general evaluations, benchmarking, red teaming, auditing, and interpretability/explainability. The subsection on general evaluations consists of items that are common to various evaluation techniques, while the other subsections are specific to their respective evaluation types."
-
64.03.01 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Use of generated content)
Scaling and Amplification
"Automate, amplify, or scale workflows"
-
"Physical injury to an individual or group, or damage to physical property due to the use of misuse of a technology system or set of systems"
-
"Accidental or deliberate loss of life, including suicide, extinction or cessation, due to the use or misuse of a technology system"
-
"Damage to the environment caused by the use or misuse of a technology system or set of systems"
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.