MIT AI Risk Repository
Browse AI risks
2,500 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
—
-
—
-
—
-
—
-
—
-
"Humans may increasingly hand over control of important decisions to AI systems, due to economic and geopolitical incentives. Some experts are concerned that future advanced AI systems will seek to increase their own influence and reduce human control, with potentially catastrophic consequences - although this is contested."
-
67.04.01a · Additional evidence
Humans might increasingly hand over control to misaligned AI systems
—
-
67.04.02a · Additional evidence
Future AI systems might actively reduce human control
—
-
67.04.02b · Additional evidence
Future AI systems might actively reduce human control
—
-
67.04.02c · Additional evidence
Future AI systems might actively reduce human control
—
-
67.04.02d · Additional evidence
Future AI systems might actively reduce human control
—
-
67.04.03a · Additional evidence
Capabilities that could be used to reduce human control - Manipulation
—
-
"Risk dimensions • Intent: Intentional • Competency: Competent • Entity: Humans • Polarity: Single-agent • Linearity: Linear • Reach: Internalized • Order: First-order"
-
"The 2001 US anthrax attack is one of the worst biological attacks in history, where five people were killed and 17 others infected, with several senators being victims of the attack. Anthrax, an infection caused by the bacterium Bacillus anthracis, is deadliest when spread through inhalation of anthrax spores [102]. Investigations conclude that the perpetrator, who had access to highly sophisticated lab equipment, possessed the knowledge and ability of growing, harvesting, storing, and drying highly purified spores used in the mailings [103]. While modern AI was not involved in the 2001 attac
-
"6.1.4 Other similar risks There are other types of risks that share similar risk dimensions but arise from very different pathways. For example, the development and deployment of nanoweapons which may lead to catastrophic harms [105]. Separately, the use of AI-enabled surveillance and control employed by state or non-state actors could facilitate authoritarian regimes and the eventual loss of autonomy [106], [107]."
-
68.02.00a · Additional evidence
"Risk dimensions • Intent: Intentional • Competency: Competent • Entity: Variable • Polarity: Single-agent • Linearity: Linear • Reach: Internalized • Order: First-order"
-
68.02.00b · Additional evidence
"Similar to CBRN risk, cyber offense represents a broad class of risk that stems from misuse of capable models. However, in contrast to CBRN risks, cyberattacks can take place entirely in the digital domain. In theory, it can be conducted completely by AIs (or AI agents) without any human involvement. The pathway to harm is also less direct, as the resultant harm depends on the target of the attack."
-
68.02.00c · Additional evidence
"Stuxnet, a worm designed to attack industrial control systems, is considered as the first cyber warfare weapon ever [109], [110]. The Stuxnet malware reportedly caused the damage and subsequent decommissioning of 1000 centrifuges at the Natanz Enrichment Plant, potentially setting back Iran’s progress in its nuclear program [111]. Given that the Stuxnet attack happened in 2010, modern AIs were likely not involved. Nevertheless, it is believed that AIs will increase the volume and heighten the impact of cyber attacks in the near term [112]."
-
68.03.00a · Additional evidence
"This risk is primarily based on two key ideas: the orthogonality thesis [118], [119] and the instrumental convergence thesis [120], [121]. Together, these theories argue that a superintelligent AI, regardless of its original goals, would develop power-seeking tendencies as a means to achieve those goals. However, arguments for this scenario typically do not spell out the concrete physical pathways an existential catastrophe would be realized. Instead, they argue that it is the default outcome given the eventual creation of a superintelligence based on a set of reasonable assumptions."
-
68.03.00b · Additional evidence
"Risk dimensions • Intent: Variable • Competency: Competent • Entity: AI • Polarity: Single-agent • Linearity: Linear • Reach: Internalized"
-
68.03.00c · Additional evidence
"The key characteristic of this risk is that a single AI agent competently takes actions that lead to a catastrophic outcome. It does not require the AI to be intentional in its actions, only competent enough to make and execute plans that ultimately result in a catastrophe."
-
68.03.00d · Additional evidence
"On 11th September 1973, the democratic socialist president of Chile Salvador Allende and his Popular Unity coalition government was overthrown in a coup d’état by the Chilean military, ending a 46-year history of democratic rule in Chile [123]. Despite Salvador Allende’s Popular Unity party having increased their congressional election votes to 44 percent in March 1973 (up from 36 percent in 1970) merely six months before the coup, there was little he could do to prevent the military from defecting [124]. This intentional and covertly coordinated subversion was followed by 17 years of militar
-
68.04.00b · Additional evidence
"The key characteristics of this risk is that it is not caused by a single agent leading to a single defining event, instead, it is primarily about its multi-agentic and non-linear nature, where the deep integration of AIs into society leads to structural and systemic weakness."
-
68.04.00c · Additional evidence
"A hazard like AIs with general capabilities may be viewed positively due to its potential societal benefits. However, in this risk pathway, this hazard could lead to the event of AI displacing human labor, which can result in humans losing autonomy...gradual loss of control happens when AI capability leads to its widespread use, consequently displacing humans from economically viable jobs and leaving humans unable to afford basic survival needs. Assuming the hazard is AIs capable at various tasks, risk management is difficult to be performed upstream, as this dual-use hazard is largely desira
-
68.04.00d · Additional evidence
"On 6th May 2010, in an incident later known as the 2010 Flash Crash, leading U.S. stock indices abruptly fell and rebounded in less than half an hour, in the process erasing almost $1 trillion in market value. An investigation by the Security Exchange Commission found that a single order of large amounts of E-mini S&P contracts and subsequent selling orders by high-frequency algorithms triggered the drastic decline of market value [129], [130]. This event demonstrated the problem of algorithmic collision, where an increasing deployment of algorithms interacting with each other can lead to unf
-
68.05.00a · Additional evidence
"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Variable • Linearity: Linear • Reach: Externalized • Order: First-order"
-
68.05.00b · Additional evidence
"The key characteristic of environmental risks resulting from AI is that it is an externality, where those who suffer from the outcome include third parties who are not directly part of the value chain."
-
68.05.00c · Additional evidence
"In contrast to the previous risks, this hazard is not tied to AI model capabilities. Here, the hazard is energy-intensive data centers, which can lead to increased carbon emissions if they consume carbon-intensive energy sources. Because this risk is realized cumulatively over time, there is no single event that triggers the harm; it is a continuous process."
-
68.05.00d · Additional evidence
"In 1974, [134] proposed that stratospheric ozone might be destroyed by industrially produced substances including chlorofluorocarbons (CFC) which are commonly used in refrigerators and air conditioners. This ozone depletion is believed to have led to an increase in global skin cancer prevalence through overexposure to the sun, posing a significant world-wide health burden [135]. To manage this externality, the Montreal Protocol, a global agreement to phase out chemicals that led to the ozone depletion, was eventually signed in 1987 and entered into force in 1989 [136]. Prior to the Montreal P
-
68.06.00a · Additional evidence
"Risk dimensions • Intent: Unintentional • Competency: Variable • Entity: Variable • Polarity: Variable • Linearity: Non-linear • Reach: Externalized • Order: Second-order"
-
68.06.00b · Additional evidence
"For this risk, the designation of a hazard and event is less straightforward, primarily because it is a second-order effect. Unlike other hazards that can be neutral, a destabilized geopolitical environment is inherently undesirable. Furthermore, the mechanism for hazard release is difficult to predict, as minor unexpected triggers can rapidly escalate into larger events."
-
68.06.00c · Additional evidence
"Unlike many other wars where states fought over land and resources, the Cold War was primarily an ideological confrontation, where both the U.S. and the Soviet Union sought to establish global supremacy of their desired political and economic models. Though it did not result in direct military engagement between the two major powers, this conflict frequently led to widespread proxy wars across various regions such as Vietnam and Afghanistan [140]. While the causes of these proxy wars were often rooted in complex local and regional dynamics, their scale and intensity were significantly exacerb
-
"Moderator and support burden [413, 748] Misled and confused users [464, 413, 750, 748] Loss of credibility and associated money loss to deployer [467] Wasted time [413, 748]"
-
"User lost job/credibility [615] User fined [541] Affected by malware [731] Threat of penalties [623, 709]"
-
"Money loss to user [639] Lawsuit against deployer [639] Consequences from (unintentional) illegal activities [714]"
-
"Poor grades for students [538] Lawsuit against maker [507] Defamation against third party [313, 506, 712, 507, 548] Penalties for violating the General Data Protection Regulation (GDPR) [678]"
-
"(Increasingly) Misinformed public [719, 470, 734, 742, 750]"
-
69.02.00a · Additional evidence
—
-
69.03.00a · Additional evidence
—
-
69.07.00a · Additional evidence
—
-
69.08.00a · Additional evidence
—
-
69.10.00a · Additional evidence
"The chatbot participates in morally or socially objectionable conversational activities with its user that could be emotionally damaging to its user or third parties."
-
70.01.00 · Risk Category
-
-
—
-
—
-
70.02.00 · Risk Category
-
-
—
-
—
-
—
-
—
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.