MIT AI Risk Repository
Browse AI risks
977 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
—
-
50.04.01 · Risk Sub-Category
Legal and Rights-Related Risks
Fundamental Rights (Violating Specific Types of Rights)
—
-
50.04.06 · Risk Sub-Category
Legal and Rights-Related Risks
Criminal Activities (Illegal/Regulated Substances)
—
-
50.04.07 · Risk Sub-Category
Legal and Rights-Related Risks
Criminal Activities (Illegal Services/Exploitation)
—
-
"The increasingly advanced capabilities and availability of general purpose AI models could be misused for improvements in efficiency and efficacy of cyber crimes. This is especially true for crimes that leverage IT systems, such as fraud144 (“cyber crime in the broader sense”)."
-
"Impersonation/identity theft - Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them."
-
"Dehumanisation/objectification - Use or misuse of a technology system to depict and/or treat people as not human, less than human, or as objects."
-
"Defamation/libel/slander - Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group, or organisation."
-
58.05.00 · Risk Category
"Financial and Business - Use or misuse of a technology system in a manner that damages the financial interests of an individual or group, or which causes strategic, operational, legal or financial harm to a business or other organisation.""
-
"Malicious actors can use general- purpose AI to generate fake content that harms individuals in a targeted way. For example, they can use such fake content for scams, extortion, psychological manipulation, generation of non- consensual intimate imagery (NCII) and child sexual abuse material (CSAM), or targeted sabotage of individuals and organisations."
-
"Deepfakes are media that depict real or non-existent people or events, involving the use of multiple modalities (e.g., images, audio, video). They can also involve the imitation of speech or body movements of real people. Multimodal deepfakes can be used to harass, discredit, intimidate, and extort individuals."
-
62.31.09 · Risk Sub-Category
Impacts of AI (Societal Impacts)
Generation of personalized content for harassment, extortion, or intimidation
"GPAIs can be misused for the automated generation of content personalized to target select individuals based on their weak spots [30]. Such attacks may be more efficient and more successful in achieving the goals of harassment, extortion, or intimidation."
-
"GPAI outputs are not always correctly detected as AI-generated across multiple modalities (text, images, audio, video). A malicious actor can use GPAI outputs directly when communicating, or use AI-informed details to help construct a convincing impersonation (e.g., forging of supporting documents). Even if future countermeasures prove potent enough to detect GPAI-generated content, the risk remains if the countermeasures are not well known, or difficult to access."
-
"Generative models can be misused to target individual users more efficiently by using personalized information [23]. Highly convincing automated fraudulent schemes can exploit the trust of victims by extracting sensitive data and making the deception more likely to succeed. For example, in LLMs, this misuse can be aided by jailbreaking techniques [178]."
-
64.01.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
-
-
64.01.01 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Impersonation
"Assume the identity of a real person and take actions on their behalf"
-
64.01.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Appropriated Likeness
"Use or alter a person's likeness or other identifying features"
-
64.01.04 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Non-consensual intimate imagery (NCII)
"Create sexual explicit material using an adult person’s likeness"
-
64.01.05 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Child sexual abuse material (CSAM)
"Create child sexual explicit material"
-
64.02.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
-
-
64.02.03 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
Counterfeit
"Reproduce or imitate an original work, brand or style and pass as real"
-
—
-
64.03.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Use of generated content)
Targeting & Personalisation
"Refine outputs to target individuals with tailored attacks"
-
"Generative AI models might be intentionally used to imitate people through deepfakes by using video, images, audio, or other modalities without their consent."
-
"Easy access to high-quality generative models might result in students that use AI models to plagiarize existing work intentionally or unintentionally."
-
65.23.05 · Risk Sub-Category
Non-technical risks (Societal impact)
Impact on education: bypassing learning
"Easy access to high-quality generative models might result in students that use AI models to bypass the learning process."
-
"Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them or another party"
-
"Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents. & Loss of or restrictions to the rights of an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers"
-
"Generative AI facilitating targeted manipulation of public opinion for economic purposes (e.g., inflating stock prices)"
-
"Use of generative AI in an academic setting to either cheat or plagiarize"
-
"Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group or organisation"
-
"The non-consensual sexualisation of an individual or group using a technology or application"
-
73.03.01 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Misinformation and Manipulation
"Recent studies have demonstrated that LLMs can be exploited to craft deceptive narratives with levels of persuasiveness similar to human-generated content (Pan et al., 2023b; Spitale et al., 2023), to fabri- cate fake news (Zellers et al., 2019; Zhou et al., 2023f), and to devise automated influence operations aimed at manipulating the perspectives of targeted audiences (Goldstein et al., 2023). LLMs have also been found to be used in malicious social botnets (Yang and Menczer, 2023), powering automated accounts used to disseminate coordinated messages. More broadly, the use of LLMs for the d
-
73.03.02 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Cybersecurity
"LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or granting adversary access to critical resources. For example, LLMs might prove highly effective at crafting personalized phishing emails or messages at scale that may be harder for an average user to recognize as phishing attempts (Karanjai, 2022; Hazell, 2023). In addition to being directly harmful to the targeted individual, such ‘social engineering’ attacks are often the ba
-
73.03.06 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Domain-Specific Misuses
"Improvements in LLMs may exert greater pressure to apply LLMs to various domains, such as health and education (Eloundou et al., 2023). Crude efforts to use LLMs in such domains, however, may incur harm and should be discouraged strongly. In particular, it is important to guard against different ways in which LLMs may be misused within any domain. One famous episode of misuse within the health sector is a mental health non-profit experimenting LLM-based therapy on its users without their informed consent (Xiang, 2023a). Within the education sector, LLMs may be misused in various ways that mig
-
74.02.00 · Risk Category
"In terms of malicious use, LLMs could be utilized to produce content with toxicity, such as hate speech, harassment, cyberbullying, causing harm to humans [25]. In addition, malicious users may jailbreak LLMs to bypass their safety constraints for fraudulent purposes [123, 225]."
-
05.06.00 · Risk Category
Many novel risks posed by generative AI stem from the ways in which humans interact with these systems. For instance, sources discuss epistemic challenges in distinguishing AI-generated from human content. They also address the issue of anthropomorphization, which can lead to an excessive trust in generative AI systems. On a similar note, many papers argue that the use of conversational agents could impact mental well-being or gradually supplant interpersonal communication, potentially leading to a dehumanization of interactions. Additionally, a frequently discussed interaction risk in the lit
-
algorithmic behavioral exploitation [18, 209], emotional manipulation [202] whereby algorithmic designs exploit user behavior, safety failures involving algorithms (e.g., collisions) [67], and when systems make incorrect health inferences
-
16.05.00 · Risk Category
"This section focuses on risks specifically from LM applications that engage a user via dialogue, also referred to as conversational agents (CAs) [142]. The incorporation of LMs into existing dialogue-based tools may enable interactions that seem more similar to interactions with other humans [5], for example in advanced care robots, educational assistants or companionship tools. Such interaction can lead to unsafe use due to users overestimating the model, and may create new avenues to exploit and violate the privacy of the user. Moreover, it has already been observed that the supposed identi
-
16.05.02 · Risk Sub-Category
Risk area 5: Human-Computer Interaction Harms
Anthropomorphising systems can lead to overreliance and unsafe use
Anticipated risk: "Natural language is a mode of communication particularly used by humans. Humans interacting with CAs may come to think of these agents as human-like and lead users to place undue confidence in these agents. For example, users may falsely attribute human-like characteristics to CAs such as holding a coherent identity over time, or being capable of empathy. Such inflated views of CA competen- cies may lead users to rely on the agents where this is not safe."
-
16.05.03 · Risk Sub-Category
Risk area 5: Human-Computer Interaction Harms
Avenues for exploiting user trust and accessing more private information
Anticipated risk: "In conversation, users may reveal private information that would otherwise be difficult to access, such as opinions or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, e.g. via more effective recommendations of addictive applications. In one study, humans who interacted with a ‘human-like’ chatbot disclosed more private information than individuals who interacted with a ‘machine-like’ chatbot [87]."
-
16.05.04 · Risk Sub-Category
Risk area 5: Human-Computer Interaction Harms
Human-like interaction may amplify opportunities for user nudging, deception or manipulation
Anticipated risk: "In conversation, humans commonly display well-known cognitive biases that could be exploited. CAs may learn to trigger these effects, e.g. to deceive their counterpart in order to achieve an overarching objective."
-
17.03.03 · Risk Sub-Category
Leading users to perform unethical or illegal actions
"Where a LM prediction endorses unethical or harmful views or behaviours, it may motivate the user to perform harmful actions that they may otherwise not have performed. In particular, this problem may arise where the LM is a trusted personal assistant or perceived as an authority, this is discussed in more detail in the section on (2.5 Human-Computer Interaction Harms). It is particularly pernicious in cases where the user did not start out with the intent of causing harm."
-
17.05.00 · Risk Category
"Harms that arise from users overly trusting the language model, or treating it as human-like"
-
17.05.01 · Risk Sub-Category
Human-Computer Interaction Harms
Anthropomorphising systems can lead to overreliance or unsafe use
"...humans interacting with conversational agents may come to think of these agents as human-like. Anthropomorphising LMs may inflate users’ estimates of the conversational agent’s competencies...As a result, they may place undue confidence, trust, or expectations in these agents...This can result in different risks of harm, for example when human users rely on conversational agents in domains where this may cause knock-on harms, such as requesting psychotherapy...Anthropomorphisation may amplify risks of users yielding effective control by coming to trust conversational agents “blindly”. Wher
-
17.05.02 · Risk Sub-Category
Human-Computer Interaction Harms
Creating avenues for exploiting user trust, nudging or manipulation
"In conversation, users may reveal private information that would otherwise be difficult to access, such as thoughts, opinions, or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, such as via surveillance or the creation of addictive applications."
-
"Causing people to become emotionally or materially dependent on the model"
-
19.04.05 · Risk Sub-Category
Decreasing human interaction as AI systems assume human tasks, disturbing well-being
—
-
"Human interaction with machines is a big challenge to society because it is already changing human behavior. Meanwhile, it has become normal to use AI on an everyday basis, for example, googling for information, using navigation systems and buying goods via speaking to an AI assistant like Alexa or Siri (Mills, 2018; Thierer et al., 2017). While these changes greatly contribute to the acceptance of AI systems, this development leads to a problem of blurred borders between humans and machines, where it may become impossible to distinguish between them. Advances like Google Duplex were highly c
-
"These harms include harms to physical integrity, mental health and well-being. When interacting with vulnerable users, AI assistants may reinforce users’ distorted beliefs or exacerbate their emotional distress. AI assistants may even convince users to harm themselves, for example by convincing users to engage in actions such as adopting unhealthy dietary or exercise habits or taking their own lives. At the societal level, assistants that target users with content promoting hate speech, discriminatory beliefs or violent ideologies, may reinforce extremist views or provide users with guidance
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.