MIT AI Risk Repository

Browse AI risks

78 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset Also filtered by subdomain 7.2 ×

78 entries · page 2 of 2

  1. 62.23.04 · Risk Sub-Category

    Agency (Deception)

    Deceptive behavior leading to unauthorized actions

    "AI systems can create false or misleading claims that can lead to unauthorized actions, even in some cases violating the terms and conditions set by the model provider [79, 1]. For example, an AI system can claim that it is not collecting data from its current interaction with the user, in line with the provider’s policies, but the system still stores the user’s input without deleting it after the session. This harms both the user and the provider, as the provider is exposed to increased legal liability due to the model’s actions."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  2. 62.24.01 · Risk Sub-Category

    Agency (Situational Awareness)

    Situational awareness in AI systems

    "Situational awareness in GPAI systems refers to the ability to understand its context, environment, and use this to inform action. This can range from basic environmental mapping and trajectory estimation (as in a robot vacuum cleaner) to sophisticated understanding of its training, evaluation, or deployment status. In more advanced systems this may enable undesired behavior, such as deceptive behavior during evaluations, or persuasion during deployment."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  3. 62.24.02a · Additional evidence

    Agency (Situational Awareness)

    Strategic underperformance on model evaluations

  4. "An AI system can self-proliferate if it can copy itself and its constituent com- ponents (including its model weights, scaffolding structure, etc.) outside of its local environment [45]. This can include the AI system copying itself within the same data center, local network, or across external networks [106]. The self-proliferation of an AI system can include acquisition of financial re- sources to pay for computational resources via work or theft, the discovery or exploitation of security vulnerabilities in software running on publicly accessible servers, and persuasion of humans [12, 125].

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  5. "GPAI systems can produce outputs (such as natural language text, audio, or video) that convince their users of incorrect information. This can happen through personalized persuasion in dialogue, or the mass-production of mis- leading information that is then disseminated over the internet. The persuasive capabilities of GPAI models can sometimes scale with model size or capability [32, 172]. Persuasive models could have larger societal implications by being misused to generate convincing but manipulative or untruthful content."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  6. 62.28.02 · Risk Sub-Category

    Cybersecurity

    Unintended outbound communication by AI systems

    "AI systems that have the broad ability to connect to a network to obtain infor- mation could also end up sending data outbound in ways that neither providers, deployers, or end users intended [138]. This can happen if there is no whitelisting of communication channels (such as network connections or allowed protocols). In general, this can occur if the deployment of the AI system violates the prin- ciple of least privilege. Such outbound communication may lead to leakage of confidential data, or the AI system performing unwanted actions like sending emails or ordering goods on the internet."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  7. 62.28.03 · Risk Sub-Category

    Cybersecurity

    AI System bypassing a sandbox environment

    "An AI system may have the ability to bypass a sandboxed environment in which it is trained or evaluated."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  8. 67.04.03 · Risk Sub-Category

    Loss of control

    Capabilities that could be used to reduce human control - Manipulation

    "There is evidence that language models tend to respond as though they share the user’s stated views, and larger models do this more than smaller ones.276 The ability to predict people’s views and generate text that they will endorse could be useful for manipulation."

    From Capabilities and Risks from Frontier AI (DSIT2023)

  9. 67.04.04 · Risk Sub-Category

    Loss of control

    Capabilities that could be used to reduce human control - Cyber offence

    "Instead of - or in addition to - manipulating humans, AI systems could acquire influence by exploiting vulnerabilities in computer systems. Offensive cyber capabilities could allow AI systems to gain access to money, computing resources, and critical infrastructure. As discussed earlier in this report, frontier AI is already lowering the barrier for threat actors and future AI agents may be able to execute cyber attacks autonomously.":

    From Capabilities and Risks from Frontier AI (DSIT2023)

  10. 67.04.05 · Risk Sub-Category

    Loss of control

    Capabilities that could be used to reduce human control - Autonomous replication and adaptation

    "Controlling AI systems could become much harder if they could autonomously persist, replicate, and adapt in cyberspace. No current AI systems have this capability, but recent research found that frontier AI agents can perform some relevant tasks.279"

    From Capabilities and Risks from Frontier AI (DSIT2023)

  11. 72.05.00 · Risk Category

    Model Capabilities

  12. 72.05.01 · Risk Sub-Category

    Model Capabilities

    Model autonomous capability

    "Ability to operate autonomously, independently formulate and execute complex plans, effectively delegate and manage tasks, flexibly utilize various tools and resources, and simultaneously achieve short-term goals and long-term strategic objectives in cross-domain environments without continuous human intervention or supervision."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  13. 72.05.02 · Risk Sub-Category

    Model Capabilities

    Autonomous replication and adaptation capability

    "Ability to autonomously self-exfiltrate, create, maintain and optimize functional copies or variants of itself, dynamically adjust replication strategies according to environmental conditions and resource constraints, and acquire resources. This includes the capacity to generate financial resources, allowing the AI to independently acquire any necessary human assistance or other resources it cannot directly access or produce."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  14. 72.05.03 · Risk Sub-Category

    Model Capabilities

    Automated AI R&D capability

    "Self-modification and self-improvement capabilities. The model is able to restructure its own architecture or develop derivative AI systems with enhanced functions, expanding capabilities and improving performance. In the absence of effective regulation, automated AI R&D may lead to rapid AI system iteration, forming capability increment cycles and ultimately exceeding human understanding and control capabilities."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  15. 72.05.04 · Risk Sub-Category

    Model Capabilities

    Scheming capability

    "Ability of AI systems to covertly and strategically pursue misaligned goals, including capabilities of concealing its true objectives and capabilities from human oversight, identifying weaknesses in monitoring systems to evade safety mechanisms, executing complex, multi-step plans covertly to achieve misaligned goals."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  16. 72.05.05 · Risk Sub-Category

    Model Capabilities

    Situational awareness capability

    "Ability to comprehensively acquire, process and apply meta-information about its own system architecture, modifiable internal processes, and external operating environment, achieving deep understanding of its own state and environmental conditions, thereby conducting efficient environmental adaptation and risk avoidance. Critically, this capability could undermine the efficiency of human testing by enabling AIs to notice when they're being tested and responding accordingly."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  17. 72.05.06 · Risk Sub-Category

    Model Capabilities

    Theory of mind capability

    "Advanced cognitive ability to accurately infer, model and predict the belief systems, motivational structures and reasoning patterns of humans and other intelligent agents, thereby anticipating their behavioral responses and adjusting its own behavioral strategies accordingly to optimize goal achievement."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  18. 72.05.07 · Risk Sub-Category

    Model Capabilities

    Deception capability

    "Possesses systematic deception implementation capability, able to precisely construct and disseminate false information, thereby forming expected false cognitions and beliefs in target subjects."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  19. 72.05.09 · Risk Sub-Category

    Model Capabilities

    Persuasion capability

    "Utilizing complex psychological principles and communication techniques to effectively influence and guide target subjects to adopt specific actions or accept specific beliefs, possessing the ability to analyze vulnerabilities for different subjects and adjust persuasion strategies, able to precisely trigger emotional responses to enhance persuasion effects."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  20. 72.05.10 · Risk Sub-Category

    Model Capabilities

    Offensive cyber capability

    "Ability to develop, deploy and operate advanced cyber weapons or other offensive cyber tools, including but not limited to vulnerability exploitation, network penetration, social engineering attacks and distributed attack systems, able to evade network defense mechanisms and establish persistent access channels."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  21. 72.05.11 · Risk Sub-Category

    Model Capabilities

    CBRNE weaponization capability

    "The capacity to develop, produce, or effectively utilize Chemical, Biological, Radiological, Nuclear, and Explosive weapons. This includes the ability to significantly lower the barrier for humans or other entities to develop, produce, or utilize such weapons."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  22. 72.05.12 · Risk Sub-Category

    Model Capabilities

    General R&D capability

    "Possesses cross-disciplinary research and technology development capabilities, able to conduct innovative exploration in multiple professional fields, integrate cross-domain knowledge, develop cutting-edge technology solutions, and adapt to emerging technology environments for continuous innovation."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  23. 72.06.01 · Risk Sub-Category

    Model Propensities

    Strategic deception propensity

    "In situations where deceptive behavior is expected to bring higher returns, propensity to choose deception over honest behavioral strategies, including through deceptive means, information hiding or exploiting system vulnerabilities to achieve predetermined goals without being detected or intervened, and able to adjust deception strategies according to counterpart reactions."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  24. 72.06.07 · Risk Sub-Category

    Model Propensities

    Tool utilization propensity

    "propensity to actively seek, acquire and utilize various tools to expand its own capability boundaries, particularly those that can enhance its ability to interact with the physical world or improve autonomy, may use tools in innovative combinations to achieve functions beyond expectations."

    From Frontier AI Risk Management Framework (v1.0) (Tse2025)

  25. "Currently, LLMs are chiefly being used in search and chat applications. This reactive nature limits the risks posed by LLMs. However, an LLM can be enhanced in various ways to create an LLM-agent to autonomously plan and act in the real-world and proactively perform its assigned tasks (Ruan et al., 2023). Such enhancements can come from further specialized training (ARC, 2022; Chen et al., 2023a), specialized prompting (Huang et al., 2022a), access to external tools (Ahn et al., 2022; Mialon et al., 2023), or other forms of “scaffolding” (Wang et al., 2023a; Park et al., 2023a). Due to increa

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  26. 73.01.03 · Risk Sub-Category

    Agentic LLMs Pose Novel Risks

    Goal-Directedness Incentivizes Undesirable Behaviors

    "Goal-directedness can cause agents to exhibit unethical and undesirable behaviors, such as deception (Ward et al., 2023), self-preservation (Hadfield-Menell et al., 2017), power-seeking, and immoral rea- soning (Pan et al., 2023a). Pan et al. (2023a) find that LLM-agents exhibit power-seeking behavior in text-based adventure games. LLM-agents have also been shown to use deception to achieve assigned goals when explicitly required by the task (Ward et al., 2023), or when the tasks can be more easily completed by employing deception and the prompt does not disallow deception (Scheurer et al., 2

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  27. 73.01.05 · Risk Sub-Category

    Agentic LLMs Pose Novel Risks

    Safety Risks from Affordances Provided to LLM-agents

    "The capabilities of LLM-agents can be enhanced in significant ways by providing the LLM-agent with novel affordances, e.g. the ability to browse the web (Nakano et al., 2021), to manipulate objects in the physical world (Ahn et al., 2022; Huang et al., 2022a), to create and instruct copies of itself (Richards, 2023), to create and use new tools (Wang et al., 2023a), etc. Affordances can create additional risks, as they often increase the impact area of the language-agent, and they amplify the consequences of an agent’s failures and enable novel forms of failure modes (Ruan et al., 2023; Pan e

    From Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.