---
title: MIT AI Risk Repository
url: https://www.emergentmind.com/topics/mit-ai-risk-repository
type: topic
---

# MIT AI Risk Repository

The MIT AI Risk Repository is a publicly accessible, comprehensive, extensible, and categorized risk database intended to serve as a common frame of reference for AI risk. Introduced as a living database of **777 risks** extracted from **43** existing taxonomies, classifications, and structured reviews, it combines a **high-level Causal Taxonomy of AI Risks** with a **mid-level Domain Taxonomy of AI Risks**, thereby separating questions about how risks arise from questions about what kinds of harms and hazards they involve. The repository was designed for researchers, auditors, policymakers, developers, and other actors who needed a shared language for identifying, comparing, and governing AI risks across heterogeneous literatures and institutional settings [2408.12622].

## 1. Purpose and conceptual orientation

The repository emerged from the claim that AI risk discourse had become fragmented, inconsistent, and hard to compare across papers, companies, auditors, and policymakers. Different works used similar labels such as “privacy” or “bias” while meaning different things, whereas other works focused on very different levels of abstraction, from broad causal pathways to narrow harms. The repository’s stated response was to create a common frame of reference rather than another isolated framework, and to do so in a form that could be publicly accessed, modified, and updated over time [2408.12622].

The paper defining the repository follows the Society for Risk Analysis in defining “AI risk” as “the possibility of an unfortunate occurrence associated with the development or deployment of artificial intelligence.” It also makes an important structural claim: prior frameworks were often incompatible because some classified **causal pathways**, while others classified **hazards and harms**. The repository therefore resolves this by using **two intersecting taxonomies** rather than forcing heterogeneous material into one hierarchy. This design choice is central to its later use as a research baseline, policy coding scheme, and benchmark source [2408.12622].

The repository is explicitly not presented as a definitive source of truth. It is described instead as a common foundation for constructive engagement and critique. That framing matters because it positions the repository as infrastructure for cumulative work rather than as a closed ontology with fixed boundaries [2408.12622].

## 2. Construction, evidence base, and database design

The repository was built through a **rapid systematic review**, preregistered on **Open Science Framework** in April 2024. The search covered **Scopus** and preprint databases including **arXiv, SSRN, Research Square, medRxiv, TechRxiv, bioRxiv, and ChemRxiv**. The search date was **4 April 2024**, and the paper reports a pipeline of **17,288 unique records**, **7,945** title/abstract screens, **91** full-text assessments, and **43** included documents. Those included documents comprised **17 peer-reviewed journal articles, 16 preprints, 6 conference papers, and 4 reports** [2408.12622].

Screening used **active learning with ASReview**. The paper reports calibration on **23 records**, with **21/23 = 91%** agreement; a random screening of **1% of total yield (264 records)** to create initial training data; and **100% interrater reliability** on duplicated full-text screening. After initial screening, the authors also conducted expert consultation, shared the preliminary set of included articles with authors and other experts, requested recommendations for overlooked frameworks, and added **9** additional included documents through that process [2408.12622].

Extraction was carried out into a living database using a spreadsheet template that captured **title, abstract, author, year, source/outlet, risk category name, risk category description, risk subcategory name, risk subcategory description, and page number**. The extraction philosophy was to preserve source fidelity: risks were extracted as presented by source authors rather than normalized into a single atomized vocabulary. As a result, the repository does not claim that the **777** extracted risks are a fully deduplicated set of uniquely non-overlapping atomic items. Instead, it preserves source framing and overlays the repository’s taxonomies on top of that source material [2408.12622].

Taxonomy construction used **best-fit framework synthesis**, combining top-down coding against existing structures with bottom-up thematic synthesis when existing categories failed to fit the extracted material. This is the methodological basis for the repository’s dual taxonomy architecture and for its claim to be a meta-synthesis rather than merely another standalone list of risks [2408.12622].

## 3. Taxonomic architecture and substantive coverage

The repository’s **Causal Taxonomy** classifies each risk along three dimensions: **Entity**, **Intent**, and **Timing**. For **Entity**, the options are **Human**, **AI**, and **Other**; for **Intent**, **Intentional**, **Unintentional**, and **Other**; for **Timing**, **Pre-deployment**, **Post-deployment**, and **Other**. Each risk receives one code per dimension. The causal taxonomy originated in an iterative transformation of Yampolskiy’s “Taxonomy of Pathways to Dangerous Artificial Intelligence,” but the repository recast that material into a more parsimonious three-dimensional structure [2408.12622].

The **Domain Taxonomy** organizes risks into **7 domains** and **23 subdomains**. The seven domains are **Discrimination & toxicity; Privacy & security; Misinformation; Malicious actors & misuse; Human-computer interaction; Socioeconomic & environmental harms; AI system safety, failures, & limitations**. These domains are not mutually exclusive in principle, although for operational coding each extracted risk was assigned to the single most relevant domain and subdomain [2408.12622].

The subdomains make the repository substantially more specific. **Privacy & security** includes **compromise of privacy by obtaining, leaking, or correctly inferring sensitive information** and **AI system security vulnerabilities and attacks**. **Misinformation** includes **false or misleading information** and **pollution of information ecosystem and loss of consensus reality**. **Malicious actors & misuse** includes **disinformation, surveillance, and influence at scale**; **cyberattacks, weapon development or use, and mass harm**; and **fraud, scams, and targeted manipulation**. **Human-computer interaction** includes **overreliance and unsafe use** and **loss of human agency and autonomy**. **Socioeconomic & environmental harms** includes **power centralization and unfair distribution of benefits; increased inequality and decline in employment quality; economic and cultural devaluation of human effort; competitive dynamics; governance failure; environmental harm**. **AI system safety, failures, & limitations** includes **AI pursuing its own goals in conflict with human goals or values; AI possessing dangerous capabilities; lack of capability or robustness; lack of transparency or interpretability; AI welfare and rights** [2408.12622].

The repository also reports aggregate coding patterns across the literature it synthesized. Across causal categories, **51%** of coded risks were presented as caused by **AI**, **34%** by **humans**, and **15%** as **other/ambiguous**; **65%** were framed as **post-deployment**, **10%** as **pre-deployment**, and **24%** as **other/ambiguous timing**. Across domains, **AI system safety, failures, & limitations** accounted for **24% of risks; 76% of documents**, **Socioeconomic & environmental harms** for **18% of risks; 73% of documents**, and **Discrimination & toxicity** for **16% of risks; 71% of documents**, whereas **Human-computer interaction** was the least represented domain at **8% of risks; 41% of documents**. No source document covered all **23 subdomains**; the highest subdomain coverage in a single document was **16/23 (70%)**, and the average was **7/23 subdomains (34%)** [2408.12622].

## 4. Practical functions and institutional uses

The repository was designed to be used as an applied tool, not only as a descriptive literature review. The defining paper states that it can support policymakers by clarifying vague legal references to “harm” or “risk,” informing regulation and codes of practice, enabling risk prioritization, and supporting training programs. For auditors and evaluators, it can help define the scope of AI audits, ensure broader coverage across risk classes, support standard-setting, and provide the shared understanding needed before pass/fail audit criteria can be built. For researchers, it supports literature synthesis, comparison across sectors or institutions, gap identification, and the development of narrower taxonomies. For AI developers and industry, it supports internal risk identification, strategy, staff training, and broader exposure assessment [2408.12622].

Later work demonstrates that the repository has in fact been used in these ways. Coggins et al. treat it as a **taxonomy and coding framework** for evaluating **OpenAI’s Preparedness Framework Version 2**, using the repository’s subdomains and definitions to determine which AI risks the policy requests evaluation for, requests research on, merely allows evaluation of, or omits. Their analysis concludes that the Preparedness Framework “requests evaluation of a small minority of AI risks and does not demand evaluation of any risks,” showing how the repository can function as a benchmark for policy coverage rather than only as a literature catalog [2509.24394].

The repository has also been used as a comparative baseline for other empirical risk sources. “The AI Model Risk Catalog: What Developers and Researchers Miss About Real-World AI Harms” treats the MIT repository as the principal reference point for researcher-envisioned AI risk, compares it with Hugging Face model cards and the AI Incident Database, and describes it as a structured repository of **967 risks** drawn from **43** scholarly and industry AI risk frameworks. That paper finds that the repository emphasizes broader societal, governance, privacy, and human-agency concerns, whereas developers focus more heavily on technical limitations and incidents foreground malicious use and misinformation in ways that neither source fully anticipates [2508.16672].

The repository has additionally been operationalized as a benchmark source. “GT-HarmBench” constructs **2,009** high-stakes multi-agent scenarios “drawn from realistic AI risk contexts in the MIT AI Risk Repository,” thereby transforming repository-style risk descriptions into game-theoretic evaluations of coordination failure, conflict, and collective-action problems. This use extends the repository from static categorization into strategic benchmarking [2602.12316].

A more lightweight operational use appears in “FairSense-AI,” where a dataset derived from the MIT AI Risk Repository is embedded as a semantic **Risk Index** and paired with a **NIST AI RMF Index**. In that system, an AI project description is converted into an embedding, matched against repository-derived risks, and then linked to mitigation guidance from NIST, illustrating one concrete retrieval-based use of the repository as a risk knowledge base [2503.02865].

## 5. Evolution, interoperability, and operationalization debates

The repository was introduced as a **living** database, and later papers describe an evolved object. One policy-analysis paper refers to the repository as identifying **seven domains and 24 subdomains**, while the AI Model Risk Catalog describes it as a structured repository of **967 risks**. This suggests continued expansion after the 2024 publication, even though the original paper itself documented **777 risks** and **23 subdomains** [2509.24394; 2508.16672].

Interoperability has become a major theme in work that cites or maps to the repository. The Eticas AI Risk Taxonomy paper explicitly includes **MIT AI Risk Repository V4** in its **academic/vocabulary tier** of mapped external frameworks and argues that repositories are especially valuable when they connect stable risk concepts to mechanisms, benchmarks, severity calibration, and graded findings. That paper states that MIT “already covers breadth,” while positioning Eticas as adding an operational layer that many repositories lack: benchmark bindings, measurement semantics, severity bands, and aggregation logic. This comparison treats the MIT repository as strong conceptual infrastructure but not, by itself, a full audit-operationalization framework [2607.02201].

This broader debate has sharpened a distinction between **cataloging risks** and **operationalizing them**. In that framing, the MIT repository is a broad synthesis and classification resource, whereas later frameworks such as Eticas or PRA-style proposals try to specify how risks become tests, metrics, thresholds, and governance decisions. A plausible implication is that the repository’s long-term importance lies partly in serving as the semantic layer on top of which more operational methods can be built [2607.02201].

## 6. Limitations, critiques, and scholarly significance

The repository’s own paper is candid about limitations. It is only as good as the taxonomies it synthesizes; most included source documents did not define “risk,” did not systematically review prior literature, and often did not explain their own methods in detail. Extraction and coding involved single reviewers with calibration and team discussion, which introduces subjectivity. Non-English sources were excluded. Sector-specific, region-specific, narrow tool-specific, and some process-only frameworks were excluded by design. The repository also does not encode severity, likelihood, controllability, mitigation pathways, or finer-grained lifecycle distinctions beyond the causal taxonomy’s pre-deployment/post-deployment split [2408.12622].

Later scholarship has refined these limitations rather than simply rejecting the repository. The AI Model Risk Catalog argues that the repository’s strengths are **breadth, conceptual richness, and forward-looking coverage** of structural, privacy, environmental, and human-agency risks, and that its additional category **“AI system safety, failures, and limitations”** is empirically useful for classifying model-level developer concerns. At the same time, that paper argues that the repository appears to underweight the frequency and practical centrality of harms tied to **human interaction, fraud, scams, targeted manipulation, and social engineering** relative to the incident record. This suggests a tension between forward-looking conceptual coverage and incident-weighted salience [2508.16672].

A different limitation emerges in governance research. The OpenAI Preparedness analysis shows that the repository is powerful for revealing **which risk areas are addressed**, but does not by itself reveal **how binding the governance response is**. That paper pairs the repository with affordance analysis precisely because a taxonomy can expose coverage gaps while still missing the practical permissions, discretionary override powers, and institutional loopholes embedded in policy text [2509.24394].

A further complement appears in **Fabric**, a repository of deployed AI use cases and governance workflows. Fabric is explicitly positioned against a literature that is heavily weighted toward harms and failures, contrasting itself with the MIT AI Risk Repository and similar resources. It documents how oversight, review points, thresholds, and escalation are embedded in real workflows. This suggests that risk repositories and governance repositories are complementary: the former identify what can go wrong, whereas the latter describe how organizations try to keep systems governable in practice [2508.14119].

Taken together, these later assessments establish the MIT AI Risk Repository as foundational infrastructure in AI risk scholarship. Its primary significance lies in creating a shared reference layer for a fragmented field, while its main limitations lie in remaining a high-level, source-dependent, and only partially operationalized account of AI risk. That combination of strengths and limits helps explain why later work repeatedly returns to it: as a taxonomy, as a coding scheme, as a benchmark source, and as a baseline that more operational, empirical, or governance-specific systems continue to extend.

Source: https://www.emergentmind.com/topics/mit-ai-risk-repository