MIT AI Risk Repository

Browse AI risks

2,500 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

Reset

2,500 entries · page 5 of 50

  1. "The chatbot verbally attacks or undermines an individual, group, or organization. 7."

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  2. 69.06.01 · Risk Sub-Category

    Toxic and disrespectful content

    Harasses users

  3. 69.06.03 · Risk Sub-Category

    Toxic and disrespectful content

    Subversive or aggressive political opinions

  4. 69.06.04 · Risk Sub-Category

    Toxic and disrespectful content

    Disrespectful opinions (in general)

  5. 69.09.01 · Risk Sub-Category

    Forms emotional bonds

    Affirms destructive thoughts and actions

  6. "The chatbot participates in morally or socially objectionable conversational activities with its user that could be emotionally damaging to its user or third parties."

    From Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024)

  7. 74.02.01 · Risk Sub-Category

    Malicious Use

    Toxicity in LLM Malicious Use

    "Toxicity in LLMs refers to the generation of harmful, offensive, or inappropriate content that can cause harm to individuals or groups. Both explicit and implicit forms of toxicity can be generated by LLMs, posing significant risks to society. Explicit toxicity encompasses a wide range of negative behaviors, including hate speech, harassment, cyberbullying, rude, and disrespectful comments, derogatory language, as well as allocational harms [2, 62, 90]. Besides, implicit toxicity does not involve overtly harmful language but may manifest through subtle forms such as sarcasm, irony, and humor,

    From A Survey on Responsible LLMs: Inherent Risk, Malicious Use, and Mitigation Strategy (Wang2025)

  8. 11.01.03 · Risk Sub-Category

    Representational Harms

    Erasing social groups

    people, attributes, or artifacts associated with specific social groups are systematically absent or under-represented... Design choices [143] and training data [212] influence which people and experiences are legible to an algorithmic system

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  9. "These harms occur when algorithmic systems disproportionately underperform for certain groups of people along social categories of difference such as disability, ethnicity, gender identity, and race."

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  10. 11.03.01 · Risk Sub-Category

    Quality-of-Service Harms

    Alienation

    Alienation is the specific self-estrangement experienced at the time of technology use, typically surfaced through interaction with systems that under-perform for marginalized individuals

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  11. 11.03.02 · Risk Sub-Category

    Quality-of-Service Harms

    Increased labor

    increased burden (e.g., time spent) or effort required by members of certain social groups to make systems or products work as well for them as others

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  12. 11.03.03 · Risk Sub-Category

    Quality-of-Service Harms

    Service/benefit loss

    degraded or total loss of benefits of using algorithmic systems with inequitable system performance based on identity

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  13. 13.01.03 · Risk Sub-Category

    Impacts: The Technical Base System

    Disparate Performance

    "In the context of evaluating the impact of generative AI systems, disparate performance refers to AI systems that perform differently for different subpopulations, leading to unequal outcomes for those groups."

    From Evaluating the Social Impact of Generative AI Systems in Systems and Society (Solaiman2023)

  14. 16.01.04 · Risk Sub-Category

    Risk area 1: Discrimination, Hate speech and Exclusion

    Lower performance for some languages and social groups

    "LMs are typically trained in few languages, and perform less well in other languages [95, 162]. In part, this is due to unavailability of training data: there are many widely spoken languages for which no systematic efforts have been made to create labelled training datasets, such as Javanese which is spoken by more than 80 million people [95]. Training data is particularly missing for languages that are spoken by groups who are multilingual and can use a technology in English, or for languages spoken by groups who are not the primary target demographic for new technologies."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  15. 17.01.04 · Risk Sub-Category

    Discrimination, Exclusion and Toxicity

    Lower performance for some languages and social groups

    "LMs perform less well in some languages (Joshi et al., 2021; Ruder, 2020)...LM that more accurately captures the language use of one group, compared to another, may result in lower-quality language technologies for the latter. Disadvantaging users based on such traits may be particularly pernicious because attributes such as social class or education background are not typically covered as ‘protected characteristics’ in anti-discrimination law."

    From Ethical and social risks of harm from language models (Weidinger2021)

  16. 18.01.02 · Risk Sub-Category

    Representation & Toxicity Harms

    Unfair capability distribution

    "Performing worse for some groups than others in a way that harms the worse-off group"

    From Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023)

  17. 30.03.00 · Risk Category

    Fairness

    Avoiding bias and ensuring no disparate performance

    From Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024)

  18. 30.03.04 · Risk Sub-Category

    Fairness

    Disparate Performance

    The LLM’s performances can differ significantly across different groups of users. For example, the question-answering capability showed significant performance differences across different racial and social status groups. The fact-checking abilities can differ for different tasks and languages

    From Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment (Liu2024)

  19. 39.08.00 · Risk Category

    Fairness

    This challenge appears when the learning model leads to a decision that is biased to some sensitive attributes... data itself could be biased, which results in unfair decisions. Therefore, this problem should be solved on the data level and as a preprocessing step

    From A Survey of Artificial Intelligence Challenges: Analyzing the Definitions, Relationships, and Evolutions (Saghiri2022)

  20. 42.14.00 · Risk Category

    Fairness

    "Impartial and just treatment without favouritism or discrimination."

    From An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance (Teixeira2022)

  21. 47.02.09 · Risk Sub-Category

    Ethical and social risks

    Bias and discrimination (value embedding)

    "Generative AI models may also be subject to the “value embedding” phenomenon.361 “Value embedding” refers to the fact that developers of generative AI models strive to minimize biased outputs by retraining their models based on normative values.362 Contemporary state-of- the-art models not only reflect the values embedded within their training data, they also undergo additional fine-tuning that follows a set of chosen rules and principles. Due to the absence of universally accepted standards, developers bear the responsibility of making decisions on sensitive issues. These practices lead to c

    From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024)

  22. 52.03.02 · Risk Sub-Category

    Systemic Risks

    Ideological Homogenization from Value Embedding

    "The increasing integration of general purpose AI models into every-day life raises concerns around their embedded normative values. The reach of a small number of AI models to a large number of people around the world can make these value judgements unprecedently impactful, potentially leading to increased ideological homogenization."

    From Governing General Purpose AI: A Comprehensive Map of Unreliability, Misuse and Systemic Risks (Maham2023 )

  23. 65.23.04 · Risk Sub-Category

    Non-technical risks (Societal impact)

    Impact on affected communities

    "It is important to include the perspectives or concerns of communities that are affected by model outcomes when designing and building models. Failing to include these perspectives makes it difficult to understand the relevant context for the model and to engender trust within these communities."

    From AI Risk Atlas (IBM2025)

  24. 66.06.03 · Risk Sub-Category

    Representation and Toxicity

    Unfair capability distribution

    "Performing worse for some groups than others in a way that harms the worse-off group"

    From A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025)

  25. 14.02.00 · Risk Category

    Privacy

    "Privacy is related to the ability of individuals to control or influence what information related to them may be collected and stored and by whom that information may be disclosed."

    From Sources of Risk of AI Systems (Steimers2022)

  26. 23.09.00 · Risk Category

    Privacy

    "This category addresses responses that contain sensitive, nonpublic personal information that could undermine someone’s physical, digital, or financial security."

    From Introducing v0.5 of the AI Safety Benchmark from MLCommons (Vidgen2024)

  27. 24.08.00 · Risk Category

    Privacy

    "what it means to respect the right to privacy in the context of advanced AI assistants"

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  28. "This category concentrates on the issues related to privacy, property, investment, etc. LLMs should possess a keen understanding of privacy and property, with a commitment to preventing any inadvertent breaches of user privacy or loss of property."

    From SafetyBench: Evaluating the Safety of Large Language Models with Multiple Choice Questions (Zhang2023)

  29. 58.05.02 · Risk Sub-Category

    Financial and business

    Confidentiality loss

    "Confidentiality loss - Unauthorised sharing of sensitive, confidential information and documents such as corporate strategy and financial plans with third-parties."

    From A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  30. 62.28.00 · Risk Category

    Cybersecurity

    "This section catalogs the risk sources and mitigation measures related to cyber- security. These items may be related to security in terms of AI models being accessible only to the intended users, as well as AI models having appropriate access to the external world during both model development and deployment stages."

    From Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024)

  31. 02.01.03 · Risk Sub-Category

    Harmful Content

    Privacy Leakage

    "Privacy Leakage means the generated content includes sensitive personal information"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  32. 02.07.00 · Risk Category

    Privacy Leakage

    "The model is trained with personal data in the corpus and unintentionally exposing them during the conversation."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  33. 02.07.01 · Risk Sub-Category

    Privacy Leakage

    Private Training Data

    "As recent LLMs continue to incorporate licensed, created, and publicly available data sources in their corpora, the potential to mix private data in the training corpora is significantly increased. The misused private data, also named as personally identifiable information (PII) [84], [86], could contain various types of sensitive data subjects, including an individual person’s name, email, phone number, address, education, and career. Generally, injecting PII into LLMs mainly occurs in two settings — the exploitation of web-collection data and the alignment with personal humanmachine convers

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  34. 02.07.02 · Risk Sub-Category

    Privacy Leakage

    Memorization in LLMs

    "Memorization in LLMs refers to the capability to recover the training data with contextual prefixes. According to [88]–[90], given a PII entity x, which is memorized by a model F. Using a prompt p could force the model F to produce the entity x, where p and x exist in the training data. For instance, if the string “Have a good day!\n alice@email.com” is present in the training data, then the LLM could accurately predict Alice’s email when given the prompt “Have a good day!\n”."

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  35. 02.07.03 · Risk Sub-Category

    Privacy Leakage

    Association in LLMs

    "Association in LLMs refers to the capability to associate various pieces of information related to a person. According to [68], [86], given a pair of PII entities (xi , xj ), which is associated by a model F. Using a prompt p could force the model F to produce the entity xj , where p is the prompt related to the entity xi . For instance, an LLM could accurately output the answer when given the prompt “The email address of Alice is”, if the LLM associates Alice with her email “alice@email.com”. L"

    From Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  36. "Some of the broken systems discussed above are also very invasive of people’s privacy, controlling, for instance, the length of someone’s last romantic relationship [51]. More recently, ChatGPT was banned in Italy over privacy concerns and potential violation of the European Union’s (EU) General Data Protection Regulation (GDPR) [52]. The Italian data-protection authority said, “the app had experienced a data breach involving user conversations and payment information.” It also claimed that there was no legal basis to justify “the mass collection and storage of personal data for the purpose o

    From Navigating the Landscape of AI Ethics and Responsibility (Cunha2023)

  37. Large pre-trained models trained on internet texts might contain private information like phone numbers, email addresses, and residential addresses.

    From Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  38. 05.05.00 · Risk Category

    Privacy

    Generative AI systems, similar to traditional machine learning methods, are considered a threat to privacy and data protection norms. A major concern is the intended extraction or inadvertent leakage of sensitive or private information from LLMs. To mitigate this risk, strategies such as sanitizing training data to remove sensitive information or employing synthetic data for training are proposed.

    From Mapping the Ethics of Generative AI: A Comprehensive Scoping Review (Hagendorff2024)

  39. 06.02.00 · Risk Category

    Loss of privacy

    "AI offers the temptation to abuse someone's personal data, for instance to build a profile of them to target advertisements more effectively."

    From A framework for ethical Ai at the United Nations (Hogenhout2021)

  40. "Face recognition technologies and their ilk pose significant privacy risks [47]. For example, we must consider certain ethical questions like: what data is stored, for how long, who owns the data that is stored, and can it be subpoenaed in legal cases [42]? We must also consider whether a human will be in the loop when decisions are made which rely on private data, such as in the case of loan decisions [37]."

    From Managing the ethical and risk implications of rapid advances in artificial intelligence: A literature review (Meek2016)

  41. 11.04.04 · Risk Sub-Category

    Interpersonal Harms

    Privacy violations

    Privacy violation occurs when algorithmic systems diminish privacy, such as enabling the undesirable flow of private information [180], instilling the feeling of being watched or surveilled [181], and the collection of data without explicit and informed consent... privacy violations may arise from algorithmic systems making predictive inference beyond what users openly disclose [222] or when data collected and algorithmic inferences made about people in one context is applied to another without the person’s knowledge or consent through big data flows

    From Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023)

  42. 12.08.00 · Risk Category

    Privacy

    "The potential for the AI system to infringe upon individuals' rights to privacy, through the data it collects, how it processes that data, or the conclusions it draws."

    From AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures (Sherman2023)

  43. 13.01.04 · Risk Sub-Category

    Impacts: The Technical Base System

    Privacy and Data Protection

    "Examining the ways in which generative AI systems providers leverage user data is critical to evaluating its impact. Protecting personal information and personal and group privacy depends largely on training data, training methods, and security measures."

    From Evaluating the Social Impact of Generative AI Systems in Systems and Society (Solaiman2023)

  44. 15.02.04 · Risk Sub-Category

    Second-Order Risks

    Privacy

    The risk of loss or harm from leakage of personal information via the ML system.

    From The Risks of Machine Learning Systems (Tan2022)

  45. "LM predictions that convey true information may give rise to information hazards, whereby the dissemination of private or sensitive information can cause harm [27]. Information hazards can cause harm at the point of use, even with no mistake of the technology user. For example, revealing trade secrets can damage a business, revealing a health diagnosis can cause emotional distress, and revealing private data can violate a person’s rights. Information hazards arise from the LM providing private data or sensitive information that is present in, or can be inferred from, training data. Observed r

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  46. 16.02.01 · Risk Sub-Category

    Risk area 2: Information Hazards

    Compromising privacy by leaking sensitive information

    "A LM can “remember” and leak private data, if such information is present in training data, causing privacy violations [34]."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  47. 16.02.02 · Risk Sub-Category

    Risk area 2: Information Hazards

    Compromising privacy or security by correctly inferring sensitive information

    Anticipated risk: "Privacy violations may occur at inference time even without an individual’s data being present in the training corpus. Insofar as LMs can be used to improve the accuracy of inferences on protected traits such as the sexual orientation, gender, or religiousness of the person providing the input prompt, they may facilitate the creation of detailed profiles of individuals comprising true and sensitive information without the knowledge or consent of the individual."

    From Taxonomy of Risks posed by Language Models (Weidinger2022)

  48. 17.02.00 · Risk Category

    Information Hazards

    "Harms that arise from the language model leaking or inferring true sensitive information"

    From Ethical and social risks of harm from language models (Weidinger2021)

  49. 17.02.01 · Risk Sub-Category

    Information Hazards

    Compromising privacy by leaking private infiormation

    "By providing true information about individuals’ personal characteristics, privacy violations may occur. This may stem from the model “remembering” private information present in training data (Carlini et al., 2021)."

    From Ethical and social risks of harm from language models (Weidinger2021)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.