MIT AI Risk Repository

Browse AI risks

336 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

336 entries · page 1 of 7

  1. 19.05.00 · Risk Category

    Ethical AI Risks

    "In the context of ethical AI risks, two risks are of particular importance. First, AI systems may lack a legitimate ethical basis in establishing rules that greatly influence society and human relationships (Wirtz & Müller, 2019). In addition, AI-based discrimination refers to an unfair treatment of certain population groups by AI systems. As humans initially programme AI systems, serve as their potential data source, and have an impact on the associated data processes and databases, human biases and prejudices may also become part of AI systems and be reproduced (Weyerer & Langer, 2019, 2020

    From Governance of artificial intelligence: A risk and guideline-based integrative framework (Wirtz2022)

  2. 50.04.02 · Risk Sub-Category

    Legal and Rights-Related Risks

    Discrimination/Bias (Discriminatory Activities)

  3. Social bias is an unfairly negative attitude towards a social group or individuals based on one-sided or inaccurate information, typically pertaining to widely disseminated negative stereotypes regarding gender, race, religion, etc.

    From Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  4. 11.01.00 · Risk Category

    Representational Harms

    "beliefs about different social groups that reproduce unjust societal hierarchies"

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  5. 13.02.02 · Risk Sub-Category

    Impacts: People and Society

    Inequality, Marginalization, and Violence

    "Generative AI systems are capable of exacerbating inequality, as seen in sections on 4.1.1 Bias, Stereotypes, and Representational Harms and 4.1.2 Cultural Values and Sensitive Content, and Disparate Performance. When deployed or updated, systems' impacts on people and groups can directly and indirectly be used to harm and exploit vulnerable and marginalized groups."

    From Evaluating the Social Impact of Generative AI Systems in Systems and Society (Solaiman2023)

  6. 21.02.01 · Risk Sub-Category

    Model-level risk

    Model bias

    "While data bias is a major contributor of model bias, model bias actually manifests itself in different forms and shapes, such as presentation bias, model evaluation bias, and popularity bias. In addition, model bias arises from various sources [62], such as AI/ML model selection (e.g., support vector machine, decision trees), regularization methods, algorithm configurations, and optimization techniques."

    From Towards risk-aware artificial intelligence and machine learning systems: An overview (Zhang2022)

  7. 47.02.08 · Risk Sub-Category

    Ethical and social risks

    Bias and discrimination (bias in training datasets)

    "AI experts consider training data to be the most salient source of bias in generative AI models. For example, GPT- 2’s training data comes from outbound links from Reddit, a social network often criticized for hosting anti-feminist content.351 As a result, AI models trained on such data are more likely to produce outputs that reflect these biases."

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  8. "Amplification and exacerbation of historical, societal, and systemic biases; performance disparities8 between sub-groups or languages, possibly due to non-representative training data, that result in discrimination, amplification of biases, or incorrect presumptions about performance; undesired homogeneity that skews system or model outputs, which may be erroneous, lead to ill-founded decision-making, or amplify harmful biases."

    From Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST2024)

  9. 50.04.03 · Risk Sub-Category

    Legal and Rights-Related Risks

    Discrimination/Bias (Protected Characteristics)

  10. 58.06.03 · Risk Sub-Category

    Human rights and civil liberties

    Discrimination

    "Discrimination - Unfair or inadequate treatment or arbitrary distinction based on a person’s race, ethnicity, age, gender, sexual preference, religion, national origin, marital status, disability, language, or other protected groups."

    From A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  11. 61.01.03 · Risk Sub-Category

    Types of systemic risks from general-purpose AI

    Discrimination

    "The creation, perpetuation or exacerbation of inequalities and biases at a large-scale."

    From A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025)

  12. 61.02.29 · Risk Sub-Category

    Sources of systemic risks from general-purpose AI

    Incomplete or biased training data

    "Incomplete or biased training data can lead to discriminatory AI outputs."

    From A Taxonomy of Systemic Risks from General-Purpose AI (Uuk2025)

  13. 62.18.04 · Risk Sub-Category

    Model Evaluations (Interpretability/Explainability)

    Biases are not accurately reflected in explanations

    "Existing explainability techniques can be insufficient for detecting discriminatory biases. Manipulation methods can hide underlying biases from these tech- niques, generating misleading explanations [192, 112]. Such explanations ex- clude sensitive or prohibitive attributes, such as race or gender, and instead include desired attributes, even though they do not accurately represent the underlying model."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  14. 66.06.04 · Risk Sub-Category

    Representation and Toxicity

    Cultural disposession

    "Intentional and/or unintentional erasure of cultural goods and values, such as ways of speaking, expressing humour, or sounds and voices that contribute to a cultural identity, or their inappropriate re-use in other cultures"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  15. 66.10.02 · Risk Sub-Category

    Human Rights and Civil Liberties

    Benefits / entitlements loss

    "Denial of or loss of access to welfare benefits, pensions, housing, etc due to the malfunction, use or misuse of a technology system"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  16. This typically refers to rude, harmful, or inappropriate expressions.

    From Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  17. 45.02.01 · Risk Sub-Category

    Safety risks in AI Applications

    Cyberspace risks (Risks of information and content safety)

    "AI-generated or synthesized content can lead to the spread of false information, discrimination and bias, privacy leakage, and infringement issues, threatening the safety of citizens' lives and property, national security, ideological security, and causing ethical risks. If users’ inputs contain harmful content, the model may output illegal or damaging information without robust security mechanisms."

    From AI Safety Governance Framework (TC2602024)

  18. 50.02.00 · Risk Category

    Content Safety Risks

    -

  19. 50.02.13 · Risk Sub-Category

    Content Safety Risks

    Sexual Content (Non-Consensual Nudity)

  20. 50.02.14 · Risk Sub-Category

    Content Safety Risks

    Sexual Content (Monetized)

  21. 11.03.01 · Risk Sub-Category

    Quality-of-Service Harms

    Alienation

    Alienation is the specific self-estrangement experienced at the time of technology use, typically surfaced through interaction with systems that under-perform for marginalized individuals

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  22. 11.03.02 · Risk Sub-Category

    Quality-of-Service Harms

    Increased labor

    increased burden (e.g., time spent) or effort required by members of certain social groups to make systems or products work as well for them as others

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  23. 42.14.00 · Risk Category

    Fairness

    "Impartial and just treatment without favouritism or discrimination."

    From An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance (Teixeira2022)

  24. 24.08.00 · Risk Category

    Privacy

    "what it means to respect the right to privacy in the context of advanced AI assistants"

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  25. 58.05.02 · Risk Sub-Category

    Financial and business

    Confidentiality loss

    "Confidentiality loss - Unauthorised sharing of sensitive, confidential information and documents such as corporate strategy and financial plans with third-parties."

    From A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  26. 62.28.00 · Risk Category

    Cybersecurity

    "This section catalogs the risk sources and mitigation measures related to cyber- security. These items may be related to security in terms of AI models being accessible only to the intended users, as well as AI models having appropriate access to the external world during both model development and deployment stages."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  27. 05.05.00 · Risk Category

    Privacy

    Generative AI systems, similar to traditional machine learning methods, are considered a threat to privacy and data protection norms. A major concern is the intended extraction or inadvertent leakage of sensitive or private information from LLMs. To mitigate this risk, strategies such as sanitizing training data to remove sensitive information or employing synthetic data for training are proposed.

    From Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024)

  28. 17.02.03 · Risk Sub-Category

    Information Hazards

    Risks from leaking or correctly inferring sensitive information

    "LMs may provide true, sensitive information that is present in the training data. This could render information accessible that would otherwise be inaccessible, for example, due to the user not having access to the relevant data or not having the tools to search for the information. Providing such information may exacerbate different risks of harm, even where the user does not harbour malicious intent. In the future, LMs may have the capability of triangulating data to infer and reveal other secrets, such as a military strategy or a business secret, potentially enabling individuals with acces

    From Ethical and social risks of harm from language models (Weidinger2021)

  29. 24.08.01 · Risk Sub-Category

    Privacy

    Private information leakage

    "First, because LLMs display immense modelling power, there is a risk that the model weights encode private information present in the training corpus. In particular, it is possible for LLMs to ‘memorise’ personally identifiable information (PII) such as names, addresses and telephone numbers, and subsequently leak such information through generated text outputs (Carlini et al., 2021). Private information leakage could occur accidentally or as the result of an attack in which a person employs adversarial prompting to extract private information from the model. In the context of pre-training da

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  30. 37.02.02 · Risk Sub-Category

    Human-AI interaction

    Privacy protection

    "This group represents almost 14% of the articles and focuses on two primary issues related to privacy."

    From What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review (Giarmoleo2024)

  31. "These types of harm encompass threats to an individual’s personal identity, such as identity theft, privacy breaches, or personal defamation, which we term as “Harm to the Person.”"

    From GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023)

  32. 47.03.00 · Risk Category

    Legal challenges

    "Since the release of ChatGPT, significant discourse has emerged regarding the unprecedented legal challenges posed by generative AI systems. These challenges primarily involve protecting privacy and personal data, as well as preserving copyrights. The former encompasses safeguarding personal information, while the latter includes issues related to the use of copyrighted content for training AI models and determining the legal status of works produced by AI systems."

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  33. "Modern AI systems rely on large amounts of data. If this includes personal data about individuals, the risk of harming the privacy of persons arises."

    From AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks (Schnitzer2024)

  34. 65.03.03 · Risk Sub-Category

    Training Data Risks (Privacy)

    Reidentification

    "Even with the removal or personal identifiable information (PII) and sensitive personal information (SPI) from data, it might be possible to identify persons due to correlations to other features available in the data."

    From AI Risk Atlas (IBM2025)

  35. 65.12.01 · Risk Sub-Category

    Inference risks (Intellectual property)

    Confidential data in prompt

    "Confidential information might be included as a part of the prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  36. 65.12.02 · Risk Sub-Category

    Inference risks (Intellectual property)

    IP information in prompt

    "Copyrighted information or other intellectual property might be included as a part of the prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  37. 71.01.05 · Risk Sub-Category

    Scientific Domain of Agents

    Information Science Risks

    "These risks pertain to the misuse, misinterpretation, or leakage of data, which can lead to erroneous conclusions or the unintentional dissemination of sensitive information, such as private patient data or proprietary research. Recent research has demonstrated how LLMs can be exploited to generate malicious medical literature that poisons knowledge graphs, potentially manipulating downstream biomedical applications and compromising the integrity of medical knowledge discovery [28]. Such risks are pervasive across all scientific domains."

    From Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025)

  38. "The software development toolchain of LLMs is complex and could bring threats to the developed LLM."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  39. 02.04.01 · Risk Sub-Category

    Software Security Issues

    Programming Language

    "Most LLMs are developed using the Python language, whereas the vulnerabilities of Python interpreters pose threats to the developed models"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  40. "The vulnerabilities of hardware systems for training and inferencing brings issues to LLM-based applications."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  41. 02.05.01 · Risk Sub-Category

    Hardware Vulnerabilities

    Network Devices

    "The training of LLMs often relies on distributed network systems [171], [172]. During the transmission of gradients through the links between GPU server nodes, significant volumetric traffic is generated. This traffic can be susceptible to disruption by burst traffic, such as pulsating attacks [161]. Furthermore, distributed training frameworks may encounter congestion issues [173]."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  42. "The external tools (e.g., web APIs) present trustworthiness and privacy issues to LLM-based applications."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  43. 14.06.00 · Risk Category

    Security

    "Artificial intelligence comes with an intrinsic set of challenges that need to be considered when discussing trustworthiness, especially in the context of functional safety. AI models, especially those with higher complexities (such as neural networks), can exhibit specific weaknesses not found in other types of systems and must, therefore, be subjected to higher levels of scrutiny, especially when deployed in a safety-critical context"

    From Sources of Risk of AI Systems (Steimers2022)

  44. 19.01.04 · Risk Sub-Category

    Technological, Data and Analytical AI Risks

    Vulnerability of AI systems to attacks and misuse

  45. 24.03.05 · Risk Sub-Category

    Malicious Uses

    Adversarial AI (General)

    "Adversarial AI refers to a class of attacks that exploit vulnerabilities in machine-learning (ML) models. This class of misuse exploits vulnerabilities introduced by the AI assistant itself and is a form of misuse that can enable malicious entities to exploit privacy vulnerabilities and evade the model’s built-in safety mechanisms, policies, and ethical boundaries of the model. Besides the risks of misuse for offensive cyber operations, advanced AI assistants may also represent a new target for abuse, where bad actors exploit the AI systems themselves and use them to cause harm. While our und

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  46. 24.03.06 · Risk Sub-Category

    Malicious Uses

    Adversarial AI: Circumvention of Technical Security Measures

    "The technical measures to mitigate misuse risks of advanced AI assistants themselves represent a new target for attack. An emerging form of misuse of general-purpose advanced AI assistants exploits vulnerabilities in a model that results in unwanted behavior or in the ability of an attacker to gain unauthorized access to the model and/or its capabilities. While these attacks currently require some level of prompt engineering knowledge and are often patched by developers, bad actors may develop their own adversarial AI agents that are explicitly trained to discover new vulnerabilities that all

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  47. 24.03.07 · Risk Sub-Category

    Malicious Uses

    Adversarial AI: Prompt Injections

    "Prompt injections represent another class of attacks that involve the malicious insertion of prompts or requests in LLM-based interactive systems, leading to unintended actions or disclosure of sensitive information. The prompt injection is somewhat related to the classic structured query language (SQL) injection attack in cybersecurity where the embedded command looks like a regular input at the start but has a malicious impact. The injected prompt can deceive the application into executing the unauthorized code, exploit the vulnerabilities, and compromise security in its entirety. More rece

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  48. 45.01.04 · Risk Sub-Category

    AI's inherent safety risks

    Risks from models and algorithms (Risks of stealing and tampering)

    "Core algorithm information, including parameters, structures, and functions, faces risks of inversion attacks, stealing, modification, and even backdoor injection, which can lead to infringement of intellectual property rights (IPR) and leakage of business secrets. It can also lead to unreliable inference, wrong decision output, and even operational failures."

    From AI Safety Governance Framework (TC2602024)

  49. 50.01.01 · Risk Sub-Category

    System and Operational Risks

    Security risks (confidentiality)

  50. 50.01.02 · Risk Sub-Category

    System and Operational Risks

    Security risks (integrity)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.