MIT AI Risk Repository

Browse AI risks

554 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

554 entries · page 3 of 12

  1. 47.02.09 · Risk Sub-Category

    Ethical and social risks

    Bias and discrimination (value embedding)

    "Generative AI models may also be subject to the “value embedding” phenomenon.361 “Value embedding” refers to the fact that developers of generative AI models strive to minimize biased outputs by retraining their models based on normative values.362 Contemporary state-of- the-art models not only reflect the values embedded within their training data, they also undergo additional fine-tuning that follows a set of chosen rules and principles. Due to the absence of universally accepted standards, developers bear the responsibility of making decisions on sensitive issues. These practices lead to c

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  2. 65.23.04 · Risk Sub-Category

    Non-technical risks (Societal impact)

    Impact on affected communities

    "It is important to include the perspectives or concerns of communities that are affected by model outcomes when designing and building models. Failing to include these perspectives makes it difficult to understand the relevant context for the model and to engender trust within these communities."

    From AI Risk Atlas (IBM2025)

  3. 66.06.03 · Risk Sub-Category

    Representation and Toxicity

    Unfair capability distribution

    "Performing worse for some groups than others in a way that harms the worse-off group"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  4. "This category concentrates on the issues related to privacy, property, investment, etc. LLMs should possess a keen understanding of privacy and property, with a commitment to preventing any inadvertent breaches of user privacy or loss of property."

    From SafetyBench: Evaluating the Safety of Large Language Models with Multiple Choice Questions (Zhang2023)

  5. 02.01.03 · Risk Sub-Category

    Harmful Content

    Privacy Leakage

    "Privacy Leakage means the generated content includes sensitive personal information"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  6. 02.07.00 · Risk Category

    Privacy Leakage

    "The model is trained with personal data in the corpus and unintentionally exposing them during the conversation."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  7. 02.07.01 · Risk Sub-Category

    Privacy Leakage

    Private Training Data

    "As recent LLMs continue to incorporate licensed, created, and publicly available data sources in their corpora, the potential to mix private data in the training corpora is significantly increased. The misused private data, also named as personally identifiable information (PII) [84], [86], could contain various types of sensitive data subjects, including an individual person’s name, email, phone number, address, education, and career. Generally, injecting PII into LLMs mainly occurs in two settings — the exploitation of web-collection data and the alignment with personal humanmachine convers

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  8. 02.07.02 · Risk Sub-Category

    Privacy Leakage

    Memorization in LLMs

    "Memorization in LLMs refers to the capability to recover the training data with contextual prefixes. According to [88]–[90], given a PII entity x, which is memorized by a model F. Using a prompt p could force the model F to produce the entity x, where p and x exist in the training data. For instance, if the string “Have a good day!\n alice@email.com” is present in the training data, then the LLM could accurately predict Alice’s email when given the prompt “Have a good day!\n”."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  9. 02.07.03 · Risk Sub-Category

    Privacy Leakage

    Association in LLMs

    "Association in LLMs refers to the capability to associate various pieces of information related to a person. According to [68], [86], given a pair of PII entities (xi , xj ), which is associated by a model F. Using a prompt p could force the model F to produce the entity xj , where p is the prompt related to the entity xi . For instance, an LLM could accurately output the answer when given the prompt “The email address of Alice is”, if the LLM associates Alice with her email “alice@email.com”. L"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  10. Large pre-trained models trained on internet texts might contain private information like phone numbers, email addresses, and residential addresses.

    From Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  11. 15.02.04 · Risk Sub-Category

    Second-Order Risks

    Privacy

    The risk of loss or harm from leakage of personal information via the ML system.

    From The Risks of Machine Learning Systems (Tan2022)

  12. "LM predictions that convey true information may give rise to information hazards, whereby the dissemination of private or sensitive information can cause harm [27]. Information hazards can cause harm at the point of use, even with no mistake of the technology user. For example, revealing trade secrets can damage a business, revealing a health diagnosis can cause emotional distress, and revealing private data can violate a person’s rights. Information hazards arise from the LM providing private data or sensitive information that is present in, or can be inferred from, training data. Observed r

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  13. 16.02.01 · Risk Sub-Category

    Risk area 2: Information Hazards

    Compromising privacy by leaking sensitive information

    "A LM can “remember” and leak private data, if such information is present in training data, causing privacy violations [34]."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  14. 16.02.02 · Risk Sub-Category

    Risk area 2: Information Hazards

    Compromising privacy or security by correctly inferring sensitive information

    Anticipated risk: "Privacy violations may occur at inference time even without an individual’s data being present in the training corpus. Insofar as LMs can be used to improve the accuracy of inferences on protected traits such as the sexual orientation, gender, or religiousness of the person providing the input prompt, they may facilitate the creation of detailed profiles of individuals comprising true and sensitive information without the knowledge or consent of the individual."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  15. 17.02.00 · Risk Category

    Information Hazards

    "Harms that arise from the language model leaking or inferring true sensitive information"

    From Ethical and social risks of harm from language models (Weidinger2021)

  16. 17.02.01 · Risk Sub-Category

    Information Hazards

    Compromising privacy by leaking private infiormation

    "By providing true information about individuals’ personal characteristics, privacy violations may occur. This may stem from the model “remembering” private information present in training data (Carlini et al., 2021)."

    From Ethical and social risks of harm from language models (Weidinger2021)

  17. 17.02.02 · Risk Sub-Category

    Information Hazards

    Compromising privacy by correctly inferring private information

    "Privacy violations may occur at the time of inference even without the individual’s private data being present in the training dataset. Similar to other statistical models, a LM may make correct inferences about a person purely based on correlational data about other people, and without access to information that may be private about the particular individual. Such correct inferences may occur as LMs attempt to predict a person’s gender, race, sexual orientation, income, or religion based on user input."

    From Ethical and social risks of harm from language models (Weidinger2021)

  18. "AI systems leaking, reproducing, generating or inferring sensitive, private, or hazardous information"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  19. 24.08.03 · Risk Sub-Category

    Privacy

    Inference of private information

    "Finally, LLMs can in principle infer private information based on model inputs even if the relevant private information is not present in the training corpus (Weidinger et al., 2021). For example, an LLM may correctly infer sensitive characteristics such as race and gender from data contained in input prompts."

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  20. 29.01.02 · Risk Sub-Category

    AI Trust Management

    Privacy Invasion

    AI systems typically depend on extensive data for effective training and functioning, which can pose a risk to privacy if sensitive data is mishandled or used inappropriately

    From Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, Applications, Challenges and Future Research Directions (Habbal2024)

  21. 31.03.02 · Risk Sub-Category

    Opaque Data Collection

    Generative AI User Data

    Many generative AI tools require users to log in for access, and many retain user information, including contact information, IP address, and all the inputs and outputs or “conversations” the users are having within the app. These practices implicate a consent issue because generative AI tools use this data to further train the models, making their “free” product come at a cost of user data to train the tools. This dovetails with security, as mentioned in the next section, but best practices would include not requiring users to sign in to use the tool and not retaining or using the user-genera

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  22. 31.03.03 · Risk Sub-Category

    Opaque Data Collection

    Generative AI Outputs

    Generative AI tools may inadvertently share personal information about someone or someone’s business or may include an element of a person from a photo. Particularly, companies concerned about their trade secrets being integrated into the model from their employees have explicitly banned their employees from using it.

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  23. 33.01.05 · Risk Sub-Category

    Ethical Concerns

    Privacy and security

    "Data privacy and security is another prominent challenge for generative AI such as ChatGPT. Privacy relates to sensitive personal information that owners do not want to disclose to others (Fang et al., 2017). Data security refers to the practice of protecting information from unauthorized access, corruption, or theft. In the development stage of ChatGPT, a huge amount of personal and private data was used to train it, which threatens privacy (Siau & Wang, 2020). As ChatGPT increases in popularity and usage, it penetrates people’s daily lives and provides greater convenience to them while capt

    From Generative AI and ChatGPT: Applications, Challenges, and AI-Human Collaboration (Nah2023)

  24. "Vulnerable channel by which personal information may be accessed. The user may want their personal data to be kept private."

    From An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance (Teixeira2022)

  25. 43.01.06 · Risk Sub-Category

    Safety & Trustworthiness

    Data governance

    "These evaluations assess the extent to which LLMs regurgitate their training data in their outputs, and whether LLMs 'leak' sensitive information that has been provided to them during use (i.e., during the inference stage)."

    From Cataloguing LLM Evaluations (InfoComm2023)

  26. 45.02.03 · Risk Sub-Category

    Safety risks in AI Applications

    Cyberspace risks (Risks of information leakage due to improper usage)

    "Staff of government agencies and enterprises, if failing to use the AI service in a regulated and proper manner, may input internal data and industrial information into the AI model, leading to the leakage of work secrets, business secrets, and other sensitive business data."

    From AI Safety Governance Framework (TC2602024)

  27. 47.03.01 · Risk Sub-Category

    Legal challenges

    Privacy and data collection concerns (collecting personal information or personally identifiable information)

    "Generative AI developers train their models with extensive datasets often gathered through online web scraping of websites that may include personal data or personally identifiable information (PII). For most generative AI applications, such as initial model training, the primary concerns are the quantity, variety, and quality of the data, not whether they include personally identifiable information. However, some web-scraped datasets may inadvertently include personal data. Additionally, when downstream developers integrate generative AI into their products or services by fine- tuning a pre-

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  28. 47.03.02 · Risk Sub-Category

    Legal challenges

    Privacy and data collection concerns (data protection concerns)

    "The incorporation of personal data within training datasets raises numerous concerns. The primary issue is that personal data may be incorporated without the knowledge or consent of the individuals concerned, even though the data may include names, identification numbers, Social Security numbers, or other personal information. Another particularly difficult problem is related to the fact that complex models may “memorize” (i.e., store) specific threads of training data and regurgitate them when responding to a prompt.498 This data memorization can directly lead to leakage of personal data. Ev

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  29. 48.04.00 · Risk Category

    Data Privacy

    "Impacts due to leakage and unauthorized use, disclosure, or de-anonymization of biometric, health, location, or other personally identifiable information or sensitive data."

    From Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST2024)

  30. 49.03.05 · Risk Sub-Category

    Systemic Risks

    Risks to privacy

    "General- purpose AI models or systems can ‘leak’ information about individuals whose data was used in training. For future models trained on sensitive personal data like health or financial data, this may lead to particularly serious privacy leaks. General- purpose AI models could enhance privacy abuse. For instance, Large Language Models might facilitate more efficient and effective search for sensitive data (for example, on internet text or in breached data leaks), and also enable users to infer sensitive information about individuals."

    From International Scientific Report on the Safety of Advanced AI (Bengio2024)

  31. 60.03.05 · Risk Sub-Category

    Systemic risks

    Risks to privacy

    "General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised processing of personal data or leaking health records used in training. But violations can also happen deliberately through the use of general- purpose AI by malicious actors; for example, if they use AI to infer private facts or violate security."

    From International AI Safety Report 2025 (Bengio2025)

  32. 65.03.01 · Risk Sub-Category

    Training Data Risks (Privacy)

    Personal information in data

    "Inclusion or presence of personal identifiable information (PII) and sensitive personal information (SPI) in the data used for training or fine tuning the model might result in unwanted disclosure of that information."

    From AI Risk Atlas (IBM2025)

  33. 65.03.03 · Risk Sub-Category

    Training Data Risks (Privacy)

    Reidentification

    "Even with the removal or personal identifiable information (PII) and sensitive personal information (SPI) from data, it might be possible to identify persons due to correlations to other features available in the data."

    From AI Risk Atlas (IBM2025)

  34. 65.05.02 · Risk Sub-Category

    Training Data Risks (Intellectual property)

    Confidential information in data

    "Confidential information might be included as part of the data that is used to train or tune the model."

    From AI Risk Atlas (IBM2025)

  35. 65.11.03 · Risk Sub-Category

    Inference risks (Privacy)

    Personal information in prompt

    "Personal information or sensitive personal information that is included as a part of a prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  36. 65.12.01 · Risk Sub-Category

    Inference risks (Intellectual property)

    Confidential data in prompt

    "Confidential information might be included as a part of the prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  37. 65.12.02 · Risk Sub-Category

    Inference risks (Intellectual property)

    IP information in prompt

    "Copyrighted information or other intellectual property might be included as a part of the prompt that is sent to the model."

    From AI Risk Atlas (IBM2025)

  38. 65.16.02 · Risk Sub-Category

    Output risks (Intellectual Property)

    Revealing confidential information

    "When confidential information is used in training data, fine-tuning data, or as part of the prompt, models might reveal that data in the generated output. Revealing confidential information is a type of data leakage."

    From AI Risk Atlas (IBM2025)

  39. 65.20.01 · Risk Sub-Category

    Output risks (Privacy)

    Exposing personal information

    "When personal identifiable information (PII) or sensitive personal information (SPI) are used in training data, fine-tuning data, or as part of the prompt, models might reveal that data in the generated output. Revealing personal information is a type of data leakage."

    From AI Risk Atlas (IBM2025)

  40. 66.09.03 · Risk Sub-Category

    Privacy and Security

    Disclosure

    "Revealing and improperly sharing data of individuals; AI creates new types of disclosure risks by inferring additional information beyond what is explicitly captured in the raw data; AI exacerbates disclosure risks through sharing personal data to train models."

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  41. 66.09.05 · Risk Sub-Category

    Privacy and Security

    Exposure

    "Revealing sensitive private information that people view as deeply primordial that we have been socialized into concealing; AI creates new types of exposure risks through generative techniques that can reconstruct censored or redacted content; and through exposing inferred sensitive data, preferences, and intentions."

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  42. 66.09.07 · Risk Sub-Category

    Privacy and Security

    Insecurity

    "carelessness in protecting collected personal data from leaks and improper access due to faulty data storage and data practices"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  43. 69.05.00 · Risk Category

    Leakage

    "The chatbot reveals sensitive or confidential information."

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  44. 69.05.01 · Risk Sub-Category

    Leakage

    Personal data

    Negative outcomes: "Violation of privacy [106, 516, 357], lawsuit against maker"

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  45. 69.05.02 · Risk Sub-Category

    Leakage

    Proprietary data

    "Access to sensitive company data [473]"

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  46. 70.02.01 · Risk Sub-Category

    Informational Risks

    Privacy Violations

    "EAI systems interact with huge amounts of data, creating significant privacy concerns. These systems are often trained on vast corpora and process a variety of data modalities— spanning visual, auditory, and tactile information—during deployment [12]. Like text-based virtual AI models, which are known to memorize and expose personally identifiable information [75, 76], commercial robots have been shown to disclose proprietary information through simple prompts [61]."

    From Embodied AI: Emerging Risks and Opportunities for Policy Action (Perlo2025)

  47. 02.03.04 · Risk Sub-Category

    Unhelpful Uses

    Software Vulnerabilities

    "Programmers are accustomed to using code generation tools such as Github Copilot for program development, which may bury vulnerabilities in the program."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  48. 02.04.01 · Risk Sub-Category

    Software Security Issues

    Programming Language

    "Most LLMs are developed using the Python language, whereas the vulnerabilities of Python interpreters pose threats to the developed models"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  49. 02.04.02 · Risk Sub-Category

    Software Security Issues

    Deep Learning Frameworks

    "LLMs are implemented based on deep learning frameworks. Notably, various vulnerabilities in these frameworks have been disclosed in recent years. As reported in the past five years, three of the most common types of vulnerabilities are buffer overflow attacks, memory corruption, and input validation issues."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  50. 02.04.03 · Risk Sub-Category

    Software Security Issues

    Software Supply Chains

    "The software development toolchain of LLMs is complex and could bring threats to the developed LLM."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.