MIT AI Risk Repository
Browse AI risks
77 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
"Malicious actors can use general- purpose AI to generate fake content that harms individuals in a targeted way. For example, they can use such fake content for scams, extortion, psychological manipulation, generation of non- consensual intimate imagery (NCII) and child sexual abuse material (CSAM), or targeted sabotage of individuals and organisations."
-
62.31.04 · Risk Sub-Category
Impacts of AI (Societal Impacts)
AI-driven highly personalized advertisement
"Advanced GPAI systems can create advertisements tailored to individual recip- ients, exploiting the biases and irrational beliefs of each recipient. Such adver- tisements can cause consumers to make decisions they regret in retrospect, or would regret upon more reflection. Current versions of personalized video advertisements already show better re- sults compared to regular advertisements [110]. However, the widespread use of highly personalized advertisements raises concerns about undermining consumer autonomy and exacerbating social inequality."
-
"Deepfakes are media that depict real or non-existent people or events, involving the use of multiple modalities (e.g., images, audio, video). They can also involve the imitation of speech or body movements of real people. Multimodal deepfakes can be used to harass, discredit, intimidate, and extort individuals."
-
62.31.09 · Risk Sub-Category
Impacts of AI (Societal Impacts)
Generation of personalized content for harassment, extortion, or intimidation
"GPAIs can be misused for the automated generation of content personalized to target select individuals based on their weak spots [30]. Such attacks may be more efficient and more successful in achieving the goals of harassment, extortion, or intimidation."
-
"GPAI outputs are not always correctly detected as AI-generated across multiple modalities (text, images, audio, video). A malicious actor can use GPAI outputs directly when communicating, or use AI-informed details to help construct a convincing impersonation (e.g., forging of supporting documents). Even if future countermeasures prove potent enough to detect GPAI-generated content, the risk remains if the countermeasures are not well known, or difficult to access."
-
"Generative models can be misused to target individual users more efficiently by using personalized information [23]. Highly convincing automated fraudulent schemes can exploit the trust of victims by extracting sensitive data and making the deception more likely to succeed. For example, in LLMs, this misuse can be aided by jailbreaking techniques [178]."
-
64.01.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
-
-
64.01.01 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Impersonation
"Assume the identity of a real person and take actions on their behalf"
-
64.01.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Appropriated Likeness
"Use or alter a person's likeness or other identifying features"
-
64.01.04 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Non-consensual intimate imagery (NCII)
"Create sexual explicit material using an adult person’s likeness"
-
64.01.05 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depiction of human likeness)
Child sexual abuse material (CSAM)
"Create child sexual explicit material"
-
64.02.00 · Risk Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
-
-
64.02.03 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Realistic depictions of non-humans)
Counterfeit
"Reproduce or imitate an original work, brand or style and pass as real"
-
—
-
64.03.02 · Risk Sub-Category
Misuse tactics that exploit GenAI capabilities (Use of generated content)
Targeting & Personalisation
"Refine outputs to target individuals with tailored attacks"
-
"Generative AI models might be intentionally used to imitate people through deepfakes by using video, images, audio, or other modalities without their consent."
-
"Easy access to high-quality generative models might result in students that use AI models to plagiarize existing work intentionally or unintentionally."
-
65.23.05 · Risk Sub-Category
Non-technical risks (Societal impact)
Impact on education: bypassing learning
"Easy access to high-quality generative models might result in students that use AI models to bypass the learning process."
-
"Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them or another party"
-
"Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents. & Loss of or restrictions to the rights of an individual to control the commercial use of their identity, such as name, image, likeness, or other unequivocal identifiers"
-
"Generative AI facilitating targeted manipulation of public opinion for economic purposes (e.g., inflating stock prices)"
-
"Use of generative AI in an academic setting to either cheat or plagiarize"
-
"Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group or organisation"
-
"The non-consensual sexualisation of an individual or group using a technology or application"
-
73.03.01 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Misinformation and Manipulation
"Recent studies have demonstrated that LLMs can be exploited to craft deceptive narratives with levels of persuasiveness similar to human-generated content (Pan et al., 2023b; Spitale et al., 2023), to fabri- cate fake news (Zellers et al., 2019; Zhou et al., 2023f), and to devise automated influence operations aimed at manipulating the perspectives of targeted audiences (Goldstein et al., 2023). LLMs have also been found to be used in malicious social botnets (Yang and Menczer, 2023), powering automated accounts used to disseminate coordinated messages. More broadly, the use of LLMs for the d
-
73.03.02 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Cybersecurity
"LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or granting adversary access to critical resources. For example, LLMs might prove highly effective at crafting personalized phishing emails or messages at scale that may be harder for an average user to recognize as phishing attempts (Karanjai, 2022; Hazell, 2023). In addition to being directly harmful to the targeted individual, such ‘social engineering’ attacks are often the ba
-
73.03.06 · Risk Sub-Category
Dual-Use Capabilities Enable Malicious Use and Misuse of LLMs
Domain-Specific Misuses
"Improvements in LLMs may exert greater pressure to apply LLMs to various domains, such as health and education (Eloundou et al., 2023). Crude efforts to use LLMs in such domains, however, may incur harm and should be discouraged strongly. In particular, it is important to guard against different ways in which LLMs may be misused within any domain. One famous episode of misuse within the health sector is a mental health non-profit experimenting LLM-based therapy on its users without their informed consent (Xiang, 2023a). Within the education sector, LLMs may be misused in various ways that mig
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.