MIT AI Risk Repository
- MIT AI Risk Repository is a comprehensive, evolving database that categorizes 777 AI risks from 43 taxonomies using a dual, intersecting framework.
- It employs a dual taxonomy approach that distinguishes causal pathways from specific harms, facilitating uniform risk assessment across diverse studies.
- Developed through systematic reviews and active learning, the repository serves as a foundational tool for researchers, auditors, policymakers, and developers to identify and compare AI risks.
The MIT AI Risk Repository is a publicly accessible, comprehensive, extensible, and categorized risk database intended to serve as a common frame of reference for AI risk. Introduced as a living database of 777 risks extracted from 43 existing taxonomies, classifications, and structured reviews, it combines a high-level Causal Taxonomy of AI Risks with a mid-level Domain Taxonomy of AI Risks, thereby separating questions about how risks arise from questions about what kinds of harms and hazards they involve. The repository was designed for researchers, auditors, policymakers, developers, and other actors who needed a shared language for identifying, comparing, and governing AI risks across heterogeneous literatures and institutional settings (Slattery et al., 2024).
1. Purpose and conceptual orientation
The repository emerged from the claim that AI risk discourse had become fragmented, inconsistent, and hard to compare across papers, companies, auditors, and policymakers. Different works used similar labels such as “privacy” or “bias” while meaning different things, whereas other works focused on very different levels of abstraction, from broad causal pathways to narrow harms. The repository’s stated response was to create a common frame of reference rather than another isolated framework, and to do so in a form that could be publicly accessed, modified, and updated over time (Slattery et al., 2024).
The paper defining the repository follows the Society for Risk Analysis in defining “AI risk” as “the possibility of an unfortunate occurrence associated with the development or deployment of artificial intelligence.” It also makes an important structural claim: prior frameworks were often incompatible because some classified causal pathways, while others classified hazards and harms. The repository therefore resolves this by using two intersecting taxonomies rather than forcing heterogeneous material into one hierarchy. This design choice is central to its later use as a research baseline, policy coding scheme, and benchmark source (Slattery et al., 2024).
The repository is explicitly not presented as a definitive source of truth. It is described instead as a common foundation for constructive engagement and critique. That framing matters because it positions the repository as infrastructure for cumulative work rather than as a closed ontology with fixed boundaries (Slattery et al., 2024).
2. Construction, evidence base, and database design
The repository was built through a rapid systematic review, preregistered on Open Science Framework in April 2024. The search covered Scopus and preprint databases including arXiv, SSRN, Research Square, medRxiv, TechRxiv, bioRxiv, and ChemRxiv. The search date was 4 April 2024, and the paper reports a pipeline of 17,288 unique records, 7,945 title/abstract screens, 91 full-text assessments, and 43 included documents. Those included documents comprised 17 peer-reviewed journal articles, 16 preprints, 6 conference papers, and 4 reports (Slattery et al., 2024).
Screening used active learning with ASReview. The paper reports calibration on 23 records, with 21/23 = 91% agreement; a random screening of 1% of total yield (264 records) to create initial training data; and 100% interrater reliability on duplicated full-text screening. After initial screening, the authors also conducted expert consultation, shared the preliminary set of included articles with authors and other experts, requested recommendations for overlooked frameworks, and added 9 additional included documents through that process (Slattery et al., 2024).
Extraction was carried out into a living database using a spreadsheet template that captured title, abstract, author, year, source/outlet, risk category name, risk category description, risk subcategory name, risk subcategory description, and page number. The extraction philosophy was to preserve source fidelity: risks were extracted as presented by source authors rather than normalized into a single atomized vocabulary. As a result, the repository does not claim that the 777 extracted risks are a fully deduplicated set of uniquely non-overlapping atomic items. Instead, it preserves source framing and overlays the repository’s taxonomies on top of that source material (Slattery et al., 2024).
Taxonomy construction used best-fit framework synthesis, combining top-down coding against existing structures with bottom-up thematic synthesis when existing categories failed to fit the extracted material. This is the methodological basis for the repository’s dual taxonomy architecture and for its claim to be a meta-synthesis rather than merely another standalone list of risks (Slattery et al., 2024).
3. Taxonomic architecture and substantive coverage
The repository’s Causal Taxonomy classifies each risk along three dimensions: Entity, Intent, and Timing. For Entity, the options are Human, AI, and Other; for Intent, Intentional, Unintentional, and Other; for Timing, Pre-deployment, Post-deployment, and Other. Each risk receives one code per dimension. The causal taxonomy originated in an iterative transformation of Yampolskiy’s “Taxonomy of Pathways to Dangerous Artificial Intelligence,” but the repository recast that material into a more parsimonious three-dimensional structure (Slattery et al., 2024).
The Domain Taxonomy organizes risks into 7 domains and 23 subdomains. The seven domains are Discrimination & toxicity; Privacy & security; Misinformation; Malicious actors & misuse; Human-computer interaction; Socioeconomic & environmental harms; AI system safety, failures, & limitations. These domains are not mutually exclusive in principle, although for operational coding each extracted risk was assigned to the single most relevant domain and subdomain (Slattery et al., 2024).
The subdomains make the repository substantially more specific. Privacy & security includes compromise of privacy by obtaining, leaking, or correctly inferring sensitive information and AI system security vulnerabilities and attacks. Misinformation includes false or misleading information and pollution of information ecosystem and loss of consensus reality. Malicious actors & misuse includes disinformation, surveillance, and influence at scale; cyberattacks, weapon development or use, and mass harm; and fraud, scams, and targeted manipulation. Human-computer interaction includes overreliance and unsafe use and loss of human agency and autonomy. Socioeconomic & environmental harms includes power centralization and unfair distribution of benefits; increased inequality and decline in employment quality; economic and cultural devaluation of human effort; competitive dynamics; governance failure; environmental harm. AI system safety, failures, & limitations includes AI pursuing its own goals in conflict with human goals or values; AI possessing dangerous capabilities; lack of capability or robustness; lack of transparency or interpretability; AI welfare and rights (Slattery et al., 2024).
The repository also reports aggregate coding patterns across the literature it synthesized. Across causal categories, 51% of coded risks were presented as caused by AI, 34% by humans, and 15% as other/ambiguous; 65% were framed as post-deployment, 10% as pre-deployment, and 24% as other/ambiguous timing. Across domains, AI system safety, failures, & limitations accounted for 24% of risks; 76% of documents, Socioeconomic & environmental harms for 18% of risks; 73% of documents, and Discrimination & toxicity for 16% of risks; 71% of documents, whereas Human-computer interaction was the least represented domain at 8% of risks; 41% of documents. No source document covered all 23 subdomains; the highest subdomain coverage in a single document was 16/23 (70%), and the average was 7/23 subdomains (34%) (Slattery et al., 2024).
4. Practical functions and institutional uses
The repository was designed to be used as an applied tool, not only as a descriptive literature review. The defining paper states that it can support policymakers by clarifying vague legal references to “harm” or “risk,” informing regulation and codes of practice, enabling risk prioritization, and supporting training programs. For auditors and evaluators, it can help define the scope of AI audits, ensure broader coverage across risk classes, support standard-setting, and provide the shared understanding needed before pass/fail audit criteria can be built. For researchers, it supports literature synthesis, comparison across sectors or institutions, gap identification, and the development of narrower taxonomies. For AI developers and industry, it supports internal risk identification, strategy, staff training, and broader exposure assessment (Slattery et al., 2024).
Later work demonstrates that the repository has in fact been used in these ways. Coggins et al. treat it as a taxonomy and coding framework for evaluating OpenAI’s Preparedness Framework Version 2, using the repository’s subdomains and definitions to determine which AI risks the policy requests evaluation for, requests research on, merely allows evaluation of, or omits. Their analysis concludes that the Preparedness Framework “requests evaluation of a small minority of AI risks and does not demand evaluation of any risks,” showing how the repository can function as a benchmark for policy coverage rather than only as a literature catalog (Coggins et al., 29 Sep 2025).
The repository has also been used as a comparative baseline for other empirical risk sources. “The AI Model Risk Catalog: What Developers and Researchers Miss About Real-World AI Harms” treats the MIT repository as the principal reference point for researcher-envisioned AI risk, compares it with Hugging Face model cards and the AI Incident Database, and describes it as a structured repository of 967 risks drawn from 43 scholarly and industry AI risk frameworks. That paper finds that the repository emphasizes broader societal, governance, privacy, and human-agency concerns, whereas developers focus more heavily on technical limitations and incidents foreground malicious use and misinformation in ways that neither source fully anticipates (Rao et al., 21 Aug 2025).
The repository has additionally been operationalized as a benchmark source. “GT-HarmBench” constructs 2,009 high-stakes multi-agent scenarios “drawn from realistic AI risk contexts in the MIT AI Risk Repository,” thereby transforming repository-style risk descriptions into game-theoretic evaluations of coordination failure, conflict, and collective-action problems. This use extends the repository from static categorization into strategic benchmarking (Cobben et al., 12 Feb 2026).
A more lightweight operational use appears in “FairSense-AI,” where a dataset derived from the MIT AI Risk Repository is embedded as a semantic Risk Index and paired with a NIST AI RMF Index. In that system, an AI project description is converted into an embedding, matched against repository-derived risks, and then linked to mitigation guidance from NIST, illustrating one concrete retrieval-based use of the repository as a risk knowledge base (Raza et al., 4 Mar 2025).
5. Evolution, interoperability, and operationalization debates
The repository was introduced as a living database, and later papers describe an evolved object. One policy-analysis paper refers to the repository as identifying seven domains and 24 subdomains, while the AI Model Risk Catalog describes it as a structured repository of 967 risks. This suggests continued expansion after the 2024 publication, even though the original paper itself documented 777 risks and 23 subdomains (Coggins et al., 29 Sep 2025, Rao et al., 21 Aug 2025).
Interoperability has become a major theme in work that cites or maps to the repository. The Eticas AI Risk Taxonomy paper explicitly includes MIT AI Risk Repository V4 in its academic/vocabulary tier of mapped external frameworks and argues that repositories are especially valuable when they connect stable risk concepts to mechanisms, benchmarks, severity calibration, and graded findings. That paper states that MIT “already covers breadth,” while positioning Eticas as adding an operational layer that many repositories lack: benchmark bindings, measurement semantics, severity bands, and aggregation logic. This comparison treats the MIT repository as strong conceptual infrastructure but not, by itself, a full audit-operationalization framework (Clavell et al., 2 Jul 2026).
This broader debate has sharpened a distinction between cataloging risks and operationalizing them. In that framing, the MIT repository is a broad synthesis and classification resource, whereas later frameworks such as Eticas or PRA-style proposals try to specify how risks become tests, metrics, thresholds, and governance decisions. A plausible implication is that the repository’s long-term importance lies partly in serving as the semantic layer on top of which more operational methods can be built (Clavell et al., 2 Jul 2026).
6. Limitations, critiques, and scholarly significance
The repository’s own paper is candid about limitations. It is only as good as the taxonomies it synthesizes; most included source documents did not define “risk,” did not systematically review prior literature, and often did not explain their own methods in detail. Extraction and coding involved single reviewers with calibration and team discussion, which introduces subjectivity. Non-English sources were excluded. Sector-specific, region-specific, narrow tool-specific, and some process-only frameworks were excluded by design. The repository also does not encode severity, likelihood, controllability, mitigation pathways, or finer-grained lifecycle distinctions beyond the causal taxonomy’s pre-deployment/post-deployment split (Slattery et al., 2024).
Later scholarship has refined these limitations rather than simply rejecting the repository. The AI Model Risk Catalog argues that the repository’s strengths are breadth, conceptual richness, and forward-looking coverage of structural, privacy, environmental, and human-agency risks, and that its additional category “AI system safety, failures, and limitations” is empirically useful for classifying model-level developer concerns. At the same time, that paper argues that the repository appears to underweight the frequency and practical centrality of harms tied to human interaction, fraud, scams, targeted manipulation, and social engineering relative to the incident record. This suggests a tension between forward-looking conceptual coverage and incident-weighted salience (Rao et al., 21 Aug 2025).
A different limitation emerges in governance research. The OpenAI Preparedness analysis shows that the repository is powerful for revealing which risk areas are addressed, but does not by itself reveal how binding the governance response is. That paper pairs the repository with affordance analysis precisely because a taxonomy can expose coverage gaps while still missing the practical permissions, discretionary override powers, and institutional loopholes embedded in policy text (Coggins et al., 29 Sep 2025).
A further complement appears in Fabric, a repository of deployed AI use cases and governance workflows. Fabric is explicitly positioned against a literature that is heavily weighted toward harms and failures, contrasting itself with the MIT AI Risk Repository and similar resources. It documents how oversight, review points, thresholds, and escalation are embedded in real workflows. This suggests that risk repositories and governance repositories are complementary: the former identify what can go wrong, whereas the latter describe how organizations try to keep systems governable in practice (Jorgensen et al., 18 Aug 2025).
Taken together, these later assessments establish the MIT AI Risk Repository as foundational infrastructure in AI risk scholarship. Its primary significance lies in creating a shared reference layer for a fragmented field, while its main limitations lie in remaining a high-level, source-dependent, and only partially operationalized account of AI risk. That combination of strengths and limits helps explain why later work repeatedly returns to it: as a taxonomy, as a coding scheme, as a benchmark source, and as a baseline that more operational, empirical, or governance-specific systems continue to extend.