MIT AI Risk Repository

Browse AI risks

3 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.

3 entries

  1. 24.03.01 · Risk Sub-Category

    Malicious Uses

    Offensive Cyber Operations (General)

    "Offensive cyber operations are malicious attacks on computer systems and networks aimed at gaining unauthorized access to, manipulating, denying, disrupting, degrading, or destroying the target system. These attacks can target the system’s network, hardware, or software. Advanced AI assistants can be a double-edged sword in cybersecurity, benefiting both the defenders and the attackers. They can be used by cyber defenders to protect systems from malicious intruders by leveraging information trained on massive amounts of cyber-threat intelligence data, including vulnerabilities, attack pattern

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  2. 24.03.03 · Risk Sub-Category

    Malicious Uses

    AI-Assisted Software Vulnerability Discovery

    "A common element in offensive cyber operations involves the identification and exploitation of system vulnerabilities to gain unauthorized access or control. Until recently, these activities required specialist programming knowledge. In the case of ‘zero-day’ vulnerabilities (flaws or weaknesses in software or an operating system that the creator or vendor is not aware of), considerable resources and technical creativity are typically required to manually discover such vulnerabilities, so their use is limited to well-resourced nation states or technically sophisticated advanced persistent thr

    From The Ethics of Advanced AI Assistants (Gabriel2024)

  3. 24.03.04 · Risk Sub-Category

    Malicious Uses

    Malicious Code Generation

    "Malicious code is a term for code—whether it be part of a script or embedded in a software system—designed to cause damage, security breaches, or other threats to application security. Advanced AI assistants with the ability to produce source code can potentially lower the barrier to entry for threat actors with limited programming abilities or technical skills to produce malicious code. Recently, a series of proof-of-concept attacks have shown how a benign-seeming executable file can be crafted such that, at every runtime, it makes application programming interface (API) calls to an AI assis

    From The Ethics of Advanced AI Assistants (Gabriel2024)

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.