MIT AI Risk Repository
Browse AI risks
594 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
"General- purpose AI systems can be used to increase the scale and sophistication of scams and fraud, for example through general- purpose AI- enhanced ‘phishing’ attacks. General- purpose AI can be used to generate fake compromising content featuring individuals without their consent, posing threats to individual privacy and reputation."
-
—
-
—
-
—
-
—
-
—
-
"The increasingly advanced capabilities and availability of general purpose AI models could be misused for improvements in efficiency and efficacy of cyber crimes. This is especially true for crimes that leverage IT systems, such as fraud144 (“cyber crime in the broader sense”)."
-
"Impersonation/identity theft - Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them."
-
"IP/copyright loss - Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents."
-
"Dehumanisation/objectification - Use or misuse of a technology system to depict and/or treat people as not human, less than human, or as objects."
-
"Defamation/libel/slander - Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group, or organisation."
-
58.05.00 · Risk Category
"Financial and Business - Use or misuse of a technology system in a manner that damages the financial interests of an individual or group, or which causes strategic, operational, legal or financial harm to a business or other organisation.""
-
"Malicious actors can use general- purpose AI to generate fake content that harms individuals in a targeted way. For example, they can use such fake content for scams, extortion, psychological manipulation, generation of non- consensual intimate imagery (NCII) and child sexual abuse material (CSAM), or targeted sabotage of individuals and organisations."
-
"Deepfakes are media that depict real or non-existent people or events, involving the use of multiple modalities (e.g., images, audio, video). They can also involve the imitation of speech or body movements of real people. Multimodal deepfakes can be used to harass, discredit, intimidate, and extort individuals."
-
62.31.09 · Risk Sub-Category
Impacts of AI (Societal Impacts)
Generation of personalized content for harassment, extortion, or intimidation
"GPAIs can be misused for the automated generation of content personalized to target select individuals based on their weak spots [30]. Such attacks may be more efficient and more successful in achieving the goals of harassment, extortion, or intimidation."
-
"GPAI outputs are not always correctly detected as AI-generated across multiple modalities (text, images, audio, video). A malicious actor can use GPAI outputs directly when communicating, or use AI-informed details to help construct a convincing impersonation (e.g., forging of supporting documents). Even if future countermeasures prove potent enough to detect GPAI-generated content, the risk remains if the countermeasures are not well known, or difficult to access."
-
"Generative models can be misused to target individual users more efficiently by using personalized information [23]. Highly convincing automated fraudulent schemes can exploit the trust of victims by extracting sensitive data and making the deception more likely to succeed. For example, in LLMs, this misuse can be aided by jailbreaking techniques [178]."
-
64.01.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
-
-
64.01.01 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Impersonation
"Assume the identity of a real person and take actions on their behalf"
-
64.01.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Appropriated Likeness
"Use or alter a person's likeness or other identifying features"
-
64.01.04 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Non-consensual intimate imagery (NCII)
"Create sexual explicit material using an adult person’s likeness"
-
64.01.05 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Child sexual abuse material (CSAM)
"Create child sexual explicit material"
-
64.02.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
-
-
64.02.03 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
Counterfeit
"Reproduce or imitate an original work, brand or style and pass as real"
-
—
-
64.03.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Use of generated content)
Targeting & Personalisation
"Refine outputs to target individuals with tailored attacks"
-
"Generative AI models might be intentionally used to imitate people through deepfakes by using video, images, audio, or other modalities without their consent."
-
"Easy access to high-quality generative models might result in students that use AI models to plagiarize existing work intentionally or unintentionally."
-
65.23.05 · Risk Sub-Category
Non-technical risks (Societal impact)
Impact on education: bypassing learning
"Easy access to high-quality generative models might result in students that use AI models to bypass the learning process."
-
"Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them or another party"
-
"Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents. & Loss of or restrictions to the rights of an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers"
-
"Use of generative AI in an academic setting to either cheat or plagiarize"
-
"Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group or organisation"
-
"The non-consensual sexualisation of an individual or group using a technology or application"
-
73.03.01 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Misinformation and Manipulation
"Recent studies have demonstrated that LLMs can be exploited to craft deceptive narratives with levels of persuasiveness similar to human-generated content (Pan et al., 2023b; Spitale et al., 2023), to fabri- cate fake news (Zellers et al., 2019; Zhou et al., 2023f), and to devise automated influence operations aimed at manipulating the perspectives of targeted audiences (Goldstein et al., 2023). LLMs have also been found to be used in malicious social botnets (Yang and Menczer, 2023), powering automated accounts used to disseminate coordinated messages. More broadly, the use of LLMs for the d
-
73.03.02 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Cybersecurity
"LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or granting adversary access to critical resources. For example, LLMs might prove highly effective at crafting personalized phishing emails or messages at scale that may be harder for an average user to recognize as phishing attempts (Karanjai, 2022; Hazell, 2023). In addition to being directly harmful to the targeted individual, such ‘social engineering’ attacks are often the ba
-
73.03.06 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Domain-Specific Misuses
"Improvements in LLMs may exert greater pressure to apply LLMs to various domains, such as health and education (Eloundou et al., 2023). Crude efforts to use LLMs in such domains, however, may incur harm and should be discouraged strongly. In particular, it is important to guard against different ways in which LLMs may be misused within any domain. One famous episode of misuse within the health sector is a mental health non-profit experimenting LLM-based therapy on its users without their informed consent (Xiang, 2023a). Within the education sector, LLMs may be misused in various ways that mig
-
16.05.02 · Risk Sub-Category
Risk area 5: Human-Computer Interaction Harms
Anthropomorphising systems can lead to overreliance and unsafe use
Anticipated risk: "Natural language is a mode of communication particularly used by humans. Humans interacting with CAs may come to think of these agents as human-like and lead users to place undue confidence in these agents. For example, users may falsely attribute human-like characteristics to CAs such as holding a coherent identity over time, or being capable of empathy. Such inflated views of CA competen- cies may lead users to rely on the agents where this is not safe."
-
17.05.01 · Risk Sub-Category
Human-Computer Interaction Harms
Anthropomorphising systems can lead to overreliance or unsafe use
"...humans interacting with conversational agents may come to think of these agents as human-like. Anthropomorphising LMs may inflate users’ estimates of the conversational agent’s competencies...As a result, they may place undue confidence, trust, or expectations in these agents...This can result in different risks of harm, for example when human users rely on conversational agents in domains where this may cause knock-on harms, such as requesting psychotherapy...Anthropomorphisation may amplify risks of users yielding effective control by coming to trust conversational agents “blindly”. Wher
-
"Causing people to become emotionally or materially dependent on the model"
-
"Users who have faith in an AI assistant’s emotional and interpersonal abilities may feel empowered to broach topics that are deeply personal and sensitive, such as their mental health concerns. This is the premise for the many proposals to employ conversational AI as a source of emotional support (Meng and Dai, 2021), with suggestions of embedding AI in psychotherapeutic applications beginning to surface (Fiske et al., 2019; see also Chapter 11). However, disclosures related to mental health require a sensitive, and oftentimes professional, approach – an approach that AI can mimic most of the
-
"Users may experience severely violated expectations when interacting with an entity that convincingly performs affect and social conventions but is ultimately unfeeling and unpredictable. Emboldened by the human-likeness of conversational AI assistants, users may expect it to perform a familiar social role, like companionship or partnership. Yet even the most convincingly human-like of AI may succumb to the inherent limitations of its architecture, occasionally generating unexpected or nonsensical material in its interactions with users. When these exclamations undermine the expectations user
-
"Perceiving an AI assistant’s expressed feelings as genuine, as a result of interacting with a ‘companion’ AI that freely uses and reciprocates emotional language, may result in users developing a sense of responsibility over the AI assistant’s ‘well-being,’ suffering adverse outcomes – like guilt and remorse – when they are unable to meet the AI’s purported needs (Laestadius et al., 2022). This erroneous belief may lead to users sacrificing time, resources and emotional labour to meet needs that are not real. Over time, this feeling may become the root cause for the compulsive need to ‘check
-
"People may choose to build connections with human-like AI assistants over other humans, leading to a degradation of social connections between humans and a potential ‘retreat from the real’. The prevailing view that relationships with anthropomorphic AI are formed out of necessity – due to a lack of real-life social connections, for example (Skjuve et al., 2021) – is challenged by the possibility that users may indicate a preference for interactions with AI, citing factors such as accessibility (Merrill et al., 2022), customisability (Eriksson, 2022) and absence of judgement (Brandtzaeg et al
-
"As more opportunities for interpersonal connection are replaced by AI alternatives, humans may find themselves socially unfulfilled by human–AI interaction, leading to mass dissatisfaction that may escalate to epidemic proportions (Turkle, 2018). Social connection is an essential human need, and humans feel most fulfilled when their connections with others are genuinely reciprocal. While anthropomorphic AI assistants can be made to be convincingly emotive, some have deemed the function of social AI as parasitic, in that it ‘exploits and feeds upon processes. . . that evolved for purposes that
-
"We use the term competence trust to refer to users’ trust that AI assistants have the capability to do what they are supposed to do (and that they will not do what they are not expected to, such as exhibiting undesirable behaviour). Users may come to have undue trust in the competencies of AI assistants in part due to marketing strategies and technology press that tend to inflate claims about AI capabilities (Narayanan, 2021; Raji et al., 2022a). Moreover, evidence shows that more autonomous systems (i.e. systems operating independently from human direction) tend to be perceived as more compe
-
"Users may develop alignment trust in AI assistants, understood as the belief that assistants have good intentions towards them and act in alignment with their interests and values, as a result of emotional or cognitive processes (McAllister, 1995). Evidence from empirical studies on emotional trust in AI (Kaplan et al., 2023) suggests that AI assistants’ increasingly realistic human-like features and behaviours are likely to inspire users’ perceptions of friendliness, liking and a sense of familiarity towards their assistants, thus encouraging users to develop emotional ties with the technolo
-
47.02.12 · Risk Sub-Category
Influence, overreliance and dependence (overreliance)
"Beyond being simply influenced, humans may become overreliant on generative AI. Researchers with Microsoft’s AETHER (AI Ethics and Effects in Engineering and Research) define overreliance as users “accepting incorrect AI recommendations” or “making errors of commission” because they are “unable to determine whether or how much they should trust the AI.”
-
47.02.13 · Risk Sub-Category
Influence, overreliance and dependence (emotional dependence)
"Humans might become dependent on generative AI tools in ways similar to their emotional dependence on other technologies, such as smartphones or social networks."
-
—
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.