MIT AI Risk Repository

Browse AI risks

2,500 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

2,500 entries · page 16 of 50

  1. 62.32.03 · Risk Sub-Category

    Impacts of AI (Cyberattacks)

    AI-driven spear phishing attacks

    "Generative models can be misused to target individual users more efficiently by using personalized information [23]. Highly convincing automated fraudulent schemes can exploit the trust of victims by extracting sensitive data and making the deception more likely to succeed. For example, in LLMs, this misuse can be aided by jailbreaking techniques [178]."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  2. "Assume the identity of a real person and take actions on their behalf"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  3. "Use or alter a person's likeness or other identifying features"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  4. "Create sexual explicit material using an adult person’s likeness"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  5. "Create child sexual explicit material"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  6. "Reproduce or imitate an original work, brand or style and pass as real"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  7. "Refine outputs to target individuals with tailored attacks"

    From Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data (Marchal2024)

  8. 65.14.05 · Risk Sub-Category

    Output risks (misuse)

    Nonconsensual use

    "Generative AI models might be intentionally used to imitate people through deepfakes by using video, images, audio, or other modalities without their consent."

    From AI Risk Atlas (IBM2025)

  9. 65.23.02 · Risk Sub-Category

    Non-technical risks (Societal impact)

    Impact on education: plagiarism

    "Easy access to high-quality generative models might result in students that use AI models to plagiarize existing work intentionally or unintentionally."

    From AI Risk Atlas (IBM2025)

  10. 65.23.05 · Risk Sub-Category

    Non-technical risks (Societal impact)

    Impact on education: bypassing learning

    "Easy access to high-quality generative models might result in students that use AI models to bypass the learning process."

    From AI Risk Atlas (IBM2025)

  11. 66.01.01 · Risk Sub-Category

    Autonomy

    Impersonation / identity theft

    "Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them or another party"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  12. 66.01.02 · Risk Sub-Category

    Autonomy

    IP / copyright / personality / rights loss

    "Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents. & Loss of or restrictions to the rights of an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  13. 66.02.03 · Risk Sub-Category

    Political and Economic

    Economic manipulation

    "Generative AI facilitating targeted manipulation of public opinion for economic purposes (e.g., inflating stock prices)"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  14. 66.04.05 · Risk Sub-Category

    Societal and Cultural

    Cheating / plagiarism

    "Use of generative AI in an academic setting to either cheat or plagiarize"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  15. 66.05.02 · Risk Sub-Category

    Reputational

    Defamation / libel / slander

    "Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group or organisation"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  16. 66.07.01 · Risk Sub-Category

    Psychological

    Sexualization

    "The non-consensual sexualisation of an individual or group using a technology or application"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  17. 73.03.01 · Risk Sub-Category

    Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs

    Misinformation and Manipulation

    "Recent studies have demonstrated that LLMs can be exploited to craft deceptive narratives with levels of persuasiveness similar to human-generated content (Pan et al., 2023b; Spitale et al., 2023), to fabri- cate fake news (Zellers et al., 2019; Zhou et al., 2023f), and to devise automated influence operations aimed at manipulating the perspectives of targeted audiences (Goldstein et al., 2023). LLMs have also been found to be used in malicious social botnets (Yang and Menczer, 2023), powering automated accounts used to disseminate coordinated messages. More broadly, the use of LLMs for the d

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  18. "LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or granting adversary access to critical resources. For example, LLMs might prove highly effective at crafting personalized phishing emails or messages at scale that may be harder for an average user to recognize as phishing attempts (Karanjai, 2022; Hazell, 2023). In addition to being directly harmful to the targeted individual, such ‘social engineering’ attacks are often the ba

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  19. 73.03.06 · Risk Sub-Category

    Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs

    Domain-Specific Misuses

    "Improvements in LLMs may exert greater pressure to apply LLMs to various domains, such as health and education (Eloundou et al., 2023). Crude efforts to use LLMs in such domains, however, may incur harm and should be discouraged strongly. In particular, it is important to guard against different ways in which LLMs may be misused within any domain. One famous episode of misuse within the health sector is a mental health non-profit experimenting LLM-based therapy on its users without their informed consent (Xiang, 2023a). Within the education sector, LLMs may be misused in various ways that mig

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  20. 74.02.00 · Risk Category

    Malicious Use

    "In terms of malicious use, LLMs could be utilized to produce content with toxicity, such as hate speech, harassment, cyberbullying, causing harm to humans [25]. In addition, malicious users may jailbreak LLMs to bypass their safety constraints for fraudulent purposes [123, 225]."

    From A Survey on Responsible LLMs: Inherent Risk, Malicious Use, and Mitigation Strategy (Wang2025)

  21. 05.06.00 · Risk Category

    Interaction risks

    Many novel risks posed by generative AI stem from the ways in which humans interact with these systems. For instance, sources discuss epistemic challenges in distinguishing AI-generated from human content. They also address the issue of anthropomorphization, which can lead to an excessive trust in generative AI systems. On a similar note, many papers argue that the use of conversational agents could impact mental well-being or gradually supplant interpersonal communication, potentially leading to a dehumanization of interactions. Additionally, a frequently discussed interaction risk in the lit

    From Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024)

  22. 11.04.03 · Risk Sub-Category

    Interpersonal Harms

    Diminished health & well-being

    algorithmic behavioral exploitation [18, 209], emotional manipulation [202] whereby algorithmic designs exploit user behavior, safety failures involving algorithms (e.g., collisions) [67], and when systems make incorrect health inferences

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  23. "This section focuses on risks specifically from LM applications that engage a user via dialogue, also referred to as conversational agents (CAs) [142]. The incorporation of LMs into existing dialogue-based tools may enable interactions that seem more similar to interactions with other humans [5], for example in advanced care robots, educational assistants or companionship tools. Such interaction can lead to unsafe use due to users overestimating the model, and may create new avenues to exploit and violate the privacy of the user. Moreover, it has already been observed that the supposed identi

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  24. 16.05.02 · Risk Sub-Category

    Risk area 5: Human-Computer Interaction Harms

    Anthropomorphising systems can lead to overreliance and unsafe use

    Anticipated risk: "Natural language is a mode of communication particularly used by humans. Humans interacting with CAs may come to think of these agents as human-like and lead users to place undue confidence in these agents. For example, users may falsely attribute human-like characteristics to CAs such as holding a coherent identity over time, or being capable of empathy. Such inflated views of CA competen- cies may lead users to rely on the agents where this is not safe."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  25. 16.05.03 · Risk Sub-Category

    Risk area 5: Human-Computer Interaction Harms

    Avenues for exploiting user trust and accessing more private information

    Anticipated risk: "In conversation, users may reveal private information that would otherwise be difficult to access, such as opinions or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, e.g. via more effective recommendations of addictive applications. In one study, humans who interacted with a ‘human-like’ chatbot disclosed more private information than individuals who interacted with a ‘machine-like’ chatbot [87]."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  26. 16.05.04 · Risk Sub-Category

    Risk area 5: Human-Computer Interaction Harms

    Human-like interaction may amplify opportunities for user nudging, deception or manipulation

    Anticipated risk: "In conversation, humans commonly display well-known cognitive biases that could be exploited. CAs may learn to trigger these effects, e.g. to deceive their counterpart in order to achieve an overarching objective."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  27. 17.03.03 · Risk Sub-Category

    Misinformation Harms

    Leading users to perform unethical or illegal actions

    "Where a LM prediction endorses unethical or harmful views or behaviours, it may motivate the user to perform harmful actions that they may otherwise not have performed. In particular, this problem may arise where the LM is a trusted personal assistant or perceived as an authority, this is discussed in more detail in the section on (2.5 Human-Computer Interaction Harms). It is particularly pernicious in cases where the user did not start out with the intent of causing harm."

    From Ethical and social risks of harm from language models (Weidinger2021)

  28. "Harms that arise from users overly trusting the language model, or treating it as human-like"

    From Ethical and social risks of harm from language models (Weidinger2021)

  29. 17.05.01 · Risk Sub-Category

    Human-Computer Interaction Harms

    Anthropomorphising systems can lead to overreliance or unsafe use

    "...humans interacting with conversational agents may come to think of these agents as human-like. Anthropomorphising LMs may inflate users’ estimates of the conversational agent’s competencies...As a result, they may place undue confidence, trust, or expectations in these agents...This can result in different risks of harm, for example when human users rely on conversational agents in domains where this may cause knock-on harms, such as requesting psychotherapy...Anthropomorphisation may amplify risks of users yielding effective control by coming to trust conversational agents “blindly”. Wher

    From Ethical and social risks of harm from language models (Weidinger2021)

  30. 17.05.02 · Risk Sub-Category

    Human-Computer Interaction Harms

    Creating avenues for exploiting user trust, nudging or manipulation

    "In conversation, users may reveal private information that would otherwise be difficult to access, such as thoughts, opinions, or emotions. Capturing such information may enable downstream applications that violate privacy rights or cause harm to users, such as via surveillance or the creation of addictive applications."

    From Ethical and social risks of harm from language models (Weidinger2021)

  31. 18.05.03 · Risk Sub-Category

    Human Autonomy and Intregrity Harms

    Overreliance

    "Causing people to become emotionally or materially dependent on the model"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  32. 19.04.05 · Risk Sub-Category

    Social AI Risks

    Decreasing human interaction as AI systems assume human tasks, disturbing well-being

  33. 20.03.03 · Risk Sub-Category

    AI Society

    Transformation of H2M interaction

    "Human interaction with machines is a big challenge to society because it is already changing human behavior. Meanwhile, it has become normal to use AI on an everyday basis, for example, googling for information, using navigation systems and buying goods via speaking to an AI assistant like Alexa or Siri (Mills, 2018; Thierer et al., 2017). While these changes greatly contribute to the acceptance of AI systems, this development leads to a problem of blurred borders between humans and machines, where it may become impossible to distinguish between them. Advances like Google Duplex were highly c

    From The Dark Sides of Artificial Intelligence: An Integrated AI Governance Framework for Public Administration (Wirtz2020)

  34. 24.04.01 · Risk Sub-Category

    AI Influence

    Physical and Psychological Harms

    "These harms include harms to physical integrity, mental health and well-being. When interacting with vulnerable users, AI assistants may reinforce users’ distorted beliefs or exacerbate their emotional distress. AI assistants may even convince users to harm themselves, for example by convincing users to engage in actions such as adopting unhealthy dietary or exercise habits or taking their own lives. At the societal level, assistants that target users with content promoting hate speech, discriminatory beliefs or violent ideologies, may reinforce extremist views or provide users with guidance

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  35. "Although unlikely to cause harm in isolation, anthropomorphic perceptions of advanced AI assistants may pave the way for downstream harms on individual and societal levels. We document observed or likely individual level harms of interacting with highly anthropomorphic AI assistants, as well as the potential larger-scale, societal implications of allowing such technologies to proliferate without restriction. "

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  36. 24.05.01 · Risk Sub-Category

    Anthropomorphism

    Privacy concerns

    "Anthropomorphic AI assistant behaviours that promote emotional trust and encourage information sharing, implicitly or explicitly, may inadvertently increase a user’s susceptibility to privacy concerns (see Chapter 13). If lulled into feelings of safety in interactions with a trusted, human-like AI assistant, users may unintentionally relinquish their private data to a corporation, organisation or unknown actor. Once shared, access to the data may not be capable of being withdrawn, and in some cases, the act of sharing personal information can result in a loss of control over one’s own data. P

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  37. 24.05.02 · Risk Sub-Category

    Anthropomorphism

    Manipulation and coercion

    "A user who trusts and emotionally depends on an anthropomorphic AI assistant may grant it excessive influence over their beliefs and actions (see Chapter 9). For example, users may feel compelled to endorse the expressed views of a beloved AI companion or might defer decisions to their highly trusted AI assistant entirely (see Chapters 12 and 16). Some hold that transferring this much deliberative power to AI compromises a user’s ability to give, revoke or amend consent. Indeed, even if the AI, or the developers behind it, had no intention to manipulate the user into a certain course of actio

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  38. 24.05.03 · Risk Sub-Category

    Anthropomorphism

    Overreliance

    "Users who have faith in an AI assistant’s emotional and interpersonal abilities may feel empowered to broach topics that are deeply personal and sensitive, such as their mental health concerns. This is the premise for the many proposals to employ conversational AI as a source of emotional support (Meng and Dai, 2021), with suggestions of embedding AI in psychotherapeutic applications beginning to surface (Fiske et al., 2019; see also Chapter 11). However, disclosures related to mental health require a sensitive, and oftentimes professional, approach – an approach that AI can mimic most of the

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  39. 24.05.04 · Risk Sub-Category

    Anthropomorphism

    Violated expectations

    "Users may experience severely violated expectations when interacting with an entity that convincingly performs affect and social conventions but is ultimately unfeeling and unpredictable. Emboldened by the human-likeness of conversational AI assistants, users may expect it to perform a familiar social role, like companionship or partnership. Yet even the most convincingly human-like of AI may succumb to the inherent limitations of its architecture, occasionally generating unexpected or nonsensical material in its interactions with users. When these exclamations undermine the expectations user

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  40. 24.05.05 · Risk Sub-Category

    Anthropomorphism

    False notions of responsibility

    "Perceiving an AI assistant’s expressed feelings as genuine, as a result of interacting with a ‘companion’ AI that freely uses and reciprocates emotional language, may result in users developing a sense of responsibility over the AI assistant’s ‘well-being,’ suffering adverse outcomes – like guilt and remorse – when they are unable to meet the AI’s purported needs (Laestadius et al., 2022). This erroneous belief may lead to users sacrificing time, resources and emotional labour to meet needs that are not real. Over time, this feeling may become the root cause for the compulsive need to ‘check

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  41. 24.05.06 · Risk Sub-Category

    Anthropomorphism

    Degradation

    "People may choose to build connections with human-like AI assistants over other humans, leading to a degradation of social connections between humans and a potential ‘retreat from the real’. The prevailing view that relationships with anthropomorphic AI are formed out of necessity – due to a lack of real-life social connections, for example (Skjuve et al., 2021) – is challenged by the possibility that users may indicate a preference for interactions with AI, citing factors such as accessibility (Merrill et al., 2022), customisability (Eriksson, 2022) and absence of judgement (Brandtzaeg et al

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  42. 24.05.08 · Risk Sub-Category

    Anthropomorphism

    Dissatisfaction

    "As more opportunities for interpersonal connection are replaced by AI alternatives, humans may find themselves socially unfulfilled by human–AI interaction, leading to mass dissatisfaction that may escalate to epidemic proportions (Turkle, 2018). Social connection is an essential human need, and humans feel most fulfilled when their connections with others are genuinely reciprocal. While anthropomorphic AI assistants can be made to be convincingly emotive, some have deemed the function of social AI as parasitic, in that it ‘exploits and feeds upon processes. . . that evolved for purposes that

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  43. 24.06.03 · Risk Sub-Category

    Appropriate Relationships

    Exploiting emotional dependence on AI assistants

    "There is increasing evidence of the ways in which AI tools can interfere with users’ behaviours, interests, preferences, beliefs and values. For example, AI-mediated communication (e.g. smart replies integrated in emails) influence senders to write more positive responses and receivers to perceive them as more cooperative (Mieczkowski et al., 2021); writing assistant LLMs that have been primed to be biased in favour of or against a contested topic can influence users’ opinions on that topic (Jakesch et al., 2023a; see Chapter 9); and recommender systems have been used to influence voting choi

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  44. 24.07.00 · Risk Category

    Trust

    "The the risks that uncalibrated trust may generate in the context of user–assistant relationships"

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  45. 24.07.01 · Risk Sub-Category

    Trust

    Competence trust

    "We use the term competence trust to refer to users’ trust that AI assistants have the capability to do what they are supposed to do (and that they will not do what they are not expected to, such as exhibiting undesirable behaviour). Users may come to have undue trust in the competencies of AI assistants in part due to marketing strategies and technology press that tend to inflate claims about AI capabilities (Narayanan, 2021; Raji et al., 2022a). Moreover, evidence shows that more autonomous systems (i.e. systems operating independently from human direction) tend to be perceived as more compe

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  46. 24.07.02 · Risk Sub-Category

    Trust

    Alignment trust

    "Users may develop alignment trust in AI assistants, understood as the belief that assistants have good intentions towards them and act in alignment with their interests and values, as a result of emotional or cognitive processes (McAllister, 1995). Evidence from empirical studies on emotional trust in AI (Kaplan et al., 2023) suggests that AI assistants’ increasingly realistic human-like features and behaviours are likely to inspire users’ perceptions of friendliness, liking and a sense of familiarity towards their assistants, thus encouraging users to develop emotional ties with the technolo

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  47. 24.11.04 · Risk Sub-Category

    Misinformation risks

    Increased vulnerability to misinformation

    "Advanced AI assistants may make users more susceptible to misinformation, as people develop competence trust in these systems’ abilities and uncritically turn to them as reliable sources of information."

    From The Ethics of Advanced AI Assistants (Gabriel2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.