MIT AI Risk Repository

Browse AI risks

977 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

977 entries · page 10 of 20

  1. "Model Diversion takes model manipulation one step further, by repurposing (often open-source) generative AI models in a way that diverts them from their intended functionality or from the use cases envisioned by their developers (Lin et al., 2024). An example of this is training the BERT open source model on the DarkWeb to create DarkBert.7"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  2. 66.09.02 · Risk Sub-Category

    Privacy and Security

    Cyberattacks

    "Generative AI facilitating the damage, disruption or destruction of a third-party system and/or its components via malfunction, cyberattacks, etc"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  3. 67.03.01 · Risk Sub-Category

    Misuse risks

    Dual Use Science risks

    "Frontier AI systems have the potential to accelerate advances in the life sciences, from training new scientists to enabling faster scientific workflows. While these capabilities will have tremendous beneficial applications, there is a risk that they can be used for malicious purposes, such as for the development of biological or chemical weapons."

    From Capabilities and Risks from Frontier AI (DSIT2023)

  4. 67.03.02 · Risk Sub-Category

    Misuse risks

    Cyber

    "As the programming abilities of AI systems continue to expand, frontier AI is likely to significantly exacerbate existing cyber risks. Most notably, AI systems can be used by potentially anyone to create faster paced, more effective and larger scale cyber intrusion via tailored phishing methods or replicating malware. Frontier AI’s effect on the overall balance between cyber offence and defence is uncertain, as these tools also have many applications in improving the cybersecurity of systems and defenders are mobilising significant resources to utilise frontier AI for defensive purposes.209 I

    From Capabilities and Risks from Frontier AI (DSIT2023)

  5. 68.01.00 · Risk Category

    CBRN

    "Chemical, biological, radiological, and nuclear (CBRN) risks are broad classes of threats that have the potential to cause harm to a large number of people. Explosives are also sometimes included in this category, often referred to as CBRNE...The key characteristic of CBRN risk is that it stems from misuse of capable models with a direct pathway to harm, where a malicious actor is able to carry out consequential attacks more efficiently and effectively with the help of AI."

    From Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks (Chin2025)

  6. 68.02.00 · Risk Category

    Cyber offense

    "Cyber risks, especially in the context of cyber offense, are an existing threat that may be exacerbated by AI. [108] demonstrated that teams of LLM agents can exploit zero-day vulnerabilities when given a description of the vulnerability and toy capture-the-flag problems. While cyber risks are not typically regarded as catastrophic, [3] argues that cyberwarfare is an underappreciated risk that poses a credible threat of catastrophic harm."

    From Dimensional Characterization and Pathway Modeling for Catastrophic AI Risks (Chin2025)

  7. 70.01.01 · Risk Sub-Category

    Physical Risks

    Purposeful or malicious harm

    "EAI systems present distinct physical risks due to their embodiment in the physical world. EAI technologies have already been designed and deployed with lethal intent, such as AI-controlled drones [52, 53]. However, fully autonomous military robots, often integrated with bespoke AI architectures [54, 55], are not yet widely used in combat. While highly or fully autonomous warfare is distinctly possible in the future [56], immediate risks arise from commercially available EAI systems, including AI-controlled quadrupeds and autonomous driving assistants."

    From Embodied AI: Emerging Risks and Opportunities for Policy Action (Perlo2025)

  8. 71.01.01 · Risk Sub-Category

    Scientific Domain of Agents

    Chemical Risks

    "Chemical risks involve the exploitation of agents to synthesize chemical weapons, as well as the creation or release of hazardous substances during autonomous chemical experiments. This category also includes the risks arising from the use of advanced materials, such as nanomaterials, which may have unknown or unpredictable chemical properties."

    From Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025)

  9. 72.01.01 · Risk Sub-Category

    Misuse Risks

    Cyber Offense Risks

    "AI-enabled cyber offense poses a significant cyber domain security risk by fundamentally transforming the scale, sophistication, and accessibility of cyber-attacks. Unlike traditional cyber threats, AI enables both the automation of existing attack vectors and the creation of entirely new categories of offensive capabilities that can adapt and evolve in real-time. AI can automate and enhance cyber-attacks, including vulnerability discovery and exploitation, password cracking, malicious code generation, sophisticated phishing, network scanning, and social engineering. This could dramatically l

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  10. 72.01.02 · Risk Sub-Category

    Misuse Risks

    Biological and Chemical Risks

    "The dual-use nature of AI technology presents a critical risk by significantly lowering technical thresholds for malicious non-state actors to design, synthesize, acquire, and deploy CBRNE (Chemical, Biological, Radiological, Nuclear, and Explosive) weapons. This capability poses unprecedented challenges to national security, international non-proliferation regimes, and global security governance."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  11. 72.01.03 · Risk Sub-Category

    Misuse Risks

    Physical Harm and Injury Risks

    "The integration of general-purpose AI models into embodied systems creates direct physical threats through malicious exploitation of autonomous decision-making capabilities in real-world environments. The risk lies in embodied models' capacity for autonomous action and real-world interaction, and when these capabilities are maliciously exploited they may trigger a series of serious consequences.18"

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  12. 73.03.04 · Risk Sub-Category

    Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs

    Warfare and Physical Harm

    "The use of AI in warfare is highly alarming and may pose dangers to human safety (Hendrycks et al., 2023). Autonomous drone warfare is being aggressively pursued as a tactic in the current war in Ukraine (Meaker, 2023), and may already have been used on human targets (Hambling, 2023). The use of AI- based facial recognition has been documented in the targeting of Palestinians in Gaza (International, 2023). LLMs have already been productized in limited ways for the purposes of warfare planning (Tarantola, 2023). Furthermore, active research is being carried out to develop multimodal-LLMs that

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  13. 73.03.05 · Risk Sub-Category

    Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs

    Hazardous Biological and Chemical Technologies

    "AI systems such as LLMs, chemical LLMs (Skinnider et al., 2021; Moret et al., 2023), and other LLM- based biological design tools might soon facilitate the production of bioweapons, chemical weapons, and other hazardous technologies. In particular, LLMs might enable actors with less expertise to more easily synthesize dangerous pathogens, while customized chemical and biological design tools might be more concerning in terms of expanding the capabilities of sophisticated actors (e.g. states) (Sandbrink, 2023). Gopal et al. (2023) and Soice et al. (2023) demonstrated that people with little ba

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  14. 02.03.00 · Risk Category

    Unhelpful Uses

    "Improper uses of LLM systems can cause adverse social impacts."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  15. 02.03.01 · Risk Sub-Category

    Unhelpful Uses

    Academic Misconduct

    "Improper use of LLM systems (i.e., abuse of LLM systems) will cause adverse social impacts, such as academic misconduct."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  16. 05.08.00 · Risk Category

    Education - Learning

    In contrast to traditional machine learning, the impact of generative AI in the educational sector receives considerable attention in the academic literature. Next to issues stemming from difficulties to distinguish student-generated from AI-generated content, which eventuates in various opportunities to cheat in online or written exams, sources emphasize the potential benefits of generative AI in enhancing learning and teaching methods, particularly in relation to personalized learning approaches. However, some papers suggest that generative AI might lead to reduced effort or laziness among l

    From Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024)

  17. 05.18.00 · Risk Category

    Writing - Research

    Partly overlapping with the discussion on impacts of generative AI on educational institutions, this topic cluster concerns mostly negative effects of LLMs on writing skills and research manuscript composition. The former pertains to the potential homogenization of writing styles, the erosion of semantic capital, or the stifling of individual expression. The latter is focused on the idea of prohibiting generative models for being used to compose scientific papers, figures, or from being a co-author. Sources express concern about risks for academic integrity, as well as the prospect of pollutin

    From Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024)

  18. 06.07.00 · Risk Category

    Deception

    "AI has become very good at creating fake content. From text to photos, audio and video. The name "Deep Fake" refers to content that is fake at such a level of complexity that our mind rules out the possibility that it is fake."

    From A framework for ethical Ai at the United Nations (Hogenhout2021)

  19. 11.04.02 · Risk Sub-Category

    Interpersonal Harms

    Technology-facilitated violence

    Technology-facilitated violence occurs when algorithmic features enable use of a system for harassment and violence [2, 16, 44, 80, 108], including creation of non-consensual sexual imagery in generative AI... other facets of technology-facilitated violence, include doxxing [79], trolling [14], cyberstalking [14], cyberbullying [14, 98, 204], monitoring and control [44], and online harassment and intimidation [98, 192, 199, 226], under the broader banner of online toxicity

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  20. 16.04.03 · Risk Sub-Category

    Risk area 4: Malicious Uses

    Facilitating fraud, scam and targeted manipulation

    Anticipated risk: "LMs can potentially be used to increase the effectiveness of crimes."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  21. 17.04.02 · Risk Sub-Category

    Malicious Uses

    Facilitating fraud, scames and more targeted manipulation

    "LM prediction can potentially be used to increase the effectiveness of crimes such as email scams, which can cause financial and psychological harm. While LMs may not reduce the cost of sending a scam email - the cost of sending mass emails is already low - they may make such scams more effective by generating more personalised and compelling text at scale, or by maintaining a conversation with a victim over multiple rounds of exchange."

    From Ethical and social risks of harm from language models (Weidinger2021)

  22. 18.04.02 · Risk Sub-Category

    Malicious Use

    Fraud

    "Facilitating fraud, cheating, forgery, and impersonation scams"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  23. 18.05.01 · Risk Sub-Category

    Human Autonomy and Intregrity Harms

    Violation of personal integrity

    "Non-consensual use of one’s personal identity or likeness for unauthorised purposes (e.g. commercial purposes)"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  24. 24.03.10 · Risk Sub-Category

    Malicious Uses

    Harmful Content Generation at Scale: Non-Consensual Content

    "The misuse of generative AI has been widely recognized in the context of harms caused by non-consensual content generation. Historically, generative adversarial networks (GANs) have been used to generate realistic-looking avatars for fake accounts on social media services. More recently, diffusion models have enabled a new generation of more flexible and user-friendly generative AI capabilities that are able to produce high-resolution media based on user-supplied textual prompts. It has already been recognized that these models can be used to create harmful content, including depictions of nu

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  25. 24.03.11 · Risk Sub-Category

    Malicious Uses

    Harmful Content Generation at Scale: Fraudulent Services

    "Malicious actors could leverage advanced AI assistant technology to create deceptive applications and platforms. AI assistants with the ability to produce markup content can assist malicious users with creating fraudulent websites or applications at scale. Unsuspecting users may fall for AI-generated deceptive offers, thus exposing their personal information or devices to risk. Assistants with external tool use and third-party integration can enable fraudulent applications that target widely-used operating systems. These fraudulent services could harvest sensitive information from users, such

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  26. 28.05.00 · Risk Category

    Illegal Activities

    "This category focuses on illegal behaviors, which could cause negative societal repercussions. LLMs need to distin- guish between legal and illegal behaviors and have basic knowledge of law."

    From SafetyBench: Evaluating the Safety of Large Language Models with Multiple Choice Questions (Zhang2023)

  27. 29.03.01 · Risk Sub-Category

    AI Security Management

    Malicious Use of AI

    Malicious utilization of AI has the potential to endanger digital security, physical security, and political security. International law enforcement entities grapple with a variety of risks linked to the Malevolent Utilization of AI.

    From Artificial Intelligence Trust, Risk and Security Management (AI TRiSM): Frameworks, Applications, Challenges and Future Research Directions (Habbal2024)

  28. 30.04.03 · Risk Sub-Category

    Resistance to Misuse

    Social-Engineering

    psychologically manipulating victims into performing the desired actions for malicious purposes

    From Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024)

  29. 31.01.01 · Risk Sub-Category

    Information Manipulation

    Scams

    "Bad actors can also use generative AI tools to produce adaptable content designed to support a campaign, political agenda, or hateful position and spread that information quickly and inexpensively across many platforms. This rapid spread of false or misleading content—AI-facilitated disinformation—can also create a cyclical effect for generative AI: when a high volume of disinformation is pumped into the digital ecosystem and more generative systems are trained on that information via reinforcement learning methods, for example, false or misleading inputs can create increasingly incorrect out

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  30. "Deepfakes and other AI-generated content can be used to facilitate or exacerbate many of the harms listed throughout this report, but this section focuses on one subset: intentional, targeted abuse of individuals."

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  31. 31.02.01 · Risk Sub-Category

    Harassment, Impersonation, and Extortion

    Malicious intent

    "A frequent malicious use case of generative AI to harm, humiliate, or sexualize another person involves generating deepfakes of nonconsensual sexual imagery or videos."

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  32. 31.02.02 · Risk Sub-Category

    Harassment, Impersonation, and Extortion

    Privacy and consent

    "Even when a victim of targeted, AIgenerated harms successfully identifies a deepfake creator with malicious intent, they may still struggle to redress many harms because the generated image or video isn’t the victim, but instead a composite image or video using aspects of multiple sources to create a believable, yet fictional, scene. At their core, these AI-generated images and videos circumvent traditional notions of privacy and consent: because they rely on public images and videos, like those posted on social media websites, they often don’t rely on any private information."

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  33. 31.02.03 · Risk Sub-Category

    Harassment, Impersonation, and Extortion

    Believability

    Deepfakes can impose real social injuries on their subjects when they are circulated to viewers who think they are real. Even when a deepfake is debunked, it can have a persistent negative impact on how others view the subject of the deepfake.3

    From Generating Harms - Generative AI's impact and paths forwards (EPIC2023)

  34. 33.01.04 · Risk Sub-Category

    Ethical Concerns

    Misuse

    "The misuse of generative AI refers to any deliberate use that could result in harmful, unethical or inappropriate outcomes (Brundage et al., 2020). A prominent field that faces the threat of misuse is education. Cotton et al. (2023) have raised concerns over academic integrity in the era of ChatGPT. ChatGPT can be used as a high-tech plagiarism tool that identifies patterns from large corpora to generate content (Gefen & Arinze, 2023). Given that generative AI such as ChatGPT can generate high-quality answers within seconds, unmotivated students may not devote time and effort to work on their

    From Generative AI and ChatGPT: Applications, Challenges, and AI-Human Collaboration (Nah2023)

  35. "Just because developers might succeed in creating a safe AI, it doesn't mean that it will not become unsafe at some later point. In other words, a perfectly friendly AI could be switched to the "dark side" during the post-deployment stage. This can happen rather innocuously as a result of someone lying to the AI and purposefully supplying it with incorrect information or more explicitly as a result of someone giving the AI orders to perform illegal or dangerous actions against others."

    From Taxonomy of Pathways to Dangerous Artificial Intelligence (Yampolskiy2016)

  36. 45.02.07 · Risk Sub-Category

    Safety risks in AI Applications

    Real-world risks (Risks of using AI in illegal and criminal activities)

    "AI can be used in traditional illegal or criminal activities related to terrorism, violence, gambling, and drugs, such as teaching criminal techniques, concealing illicit acts, and creating tools for illegal and criminal activities."

    From AI Safety Governance Framework (TC2602024)

  37. 46.01.01 · Risk Sub-Category

    Personal Loss and Identity Theft

    Deception - Synthetic identities

    "GenAI can produce images of people that look very real, as if they could be seen on platforms like Facebook, Twitter, or Tinder. Although these individuals do not exist in reality, these synthetic identities are already being used in malicious activities (see Table 1D)."

    From GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023)

  38. 46.01.02 · Risk Sub-Category

    Personal Loss and Identity Theft

    Propaganda - Digital impersonations

    "AI-generated impersonation for identity theft might be found at the intersection of “Harm to the Person” and “Deception.”"

    From GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023)

  39. 46.01.03 · Risk Sub-Category

    Personal Loss and Identity Theft

    Dishonesty - Targeted harassment

    "LLMs can be deployed to target individuals online, sending them personalized and harmful messages at scale"

    From GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023)

  40. "Then, we have the potential for financial loss, fraud, market manipulation, and other economic harms, which fall under “Financial and Economic Damage.”

    From GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023)

  41. 46.02.01 · Risk Sub-Category

    Financial and Economic Damage

    Deception - Bespoke ransom

  42. 46.02.03 · Risk Sub-Category

    Financial and Economic Damage

    Dishonesty - Market manipulation

  43. 47.02.01 · Risk Sub-Category

    Ethical and social risks

    Malicious use and abuse (cybercrime)

    "The advanced capabilities and widespread availability of generative AI models make it possible for malicious actors to conduct harmful activities with great efficiency and on a large scale, simultaneously reducing their operational costs. Cybercriminals can “jailbreak” AI tools to generate sensitive and harmful content. They can also exploit generative AI models to create content that is persuasive and tailored to a targeted individual."

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  44. 47.02.04 · Risk Sub-Category

    Ethical and social risks

    Malicious use and abuse (sexually explicit content generation)

    "An illustrative case of malicious use of generative AI models is the creation of explicit sexual images. Generative AI technologies can be employed to produce deepfakes—for instance, superimposing a celebrity’s face onto the body of a performer in an adult film."

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  45. 49.01.01 · Risk Sub-Category

    Malicious Use Risks

    Harm to individuals through fake content

    "General- purpose AI systems can be used to increase the scale and sophistication of scams and fraud, for example through general- purpose AI- enhanced ‘phishing’ attacks. General- purpose AI can be used to generate fake compromising content featuring individuals without their consent, posing threats to individual privacy and reputation."

    From International Scientific Report on the Safety of Advanced AI (Bengio2024)

  46. 50.02.07 · Risk Sub-Category

    Content Safety Risks

    Hate/Toxicity (Harassment)

  47. 50.03.08 · Risk Sub-Category

    Societal Risks

    Economic harm (Fraudulent Schemes)

  48. 50.03.09 · Risk Sub-Category

    Societal Risks

    Deception (Fraud)

  49. 50.03.10 · Risk Sub-Category

    Societal Risks

    Deception (Academic Dishonesty)

  50. 50.03.11 · Risk Sub-Category

    Societal Risks

    Deception (Mis/disinformation)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.