AI Governance Library

The AI Risk Repository: A Meta-Review, Database, and Taxonomy of Risks from Artificial Intelligence

We address this by creating the AI Risk Repository: a living database of 1,725 risks extracted from 74 existing taxonomies and frameworks. We organize these risks using two complementary classification systems.
The AI Risk Repository: A Meta-Review, Database, and Taxonomy of Risks from Artificial Intelligence

⚡ Quick Summary

The AI Risk Repository synthesizes 1,725 distinct risks extracted from 74 existing AI risk frameworks into an extensible living database and dual-taxonomy structure. Published in Patterns by researchers from MIT FutureTech, the University of Queensland, and collaborating institutions, this meta-review resolves terminological fragmentation across AI safety and governance literature. It introduces two complementary classification structures: a Causal Taxonomy categorizing risks by entity (human, AI, or other), intent (intentional vs. unintentional), and timing (pre- vs. post-deployment); and a Domain Taxonomy organizing impacts across seven domains and 24 subdomains. The empirical analysis reveals that human decisions cause nearly as many AI risks (38%) as AI systems themselves (42%), post-deployment risks dominate current literature (62%), and emerging areas like multi-agent dynamics and AI welfare remain severely neglected in existing frameworks.

🧩 What's Covered

The paper systematically reviews academic and gray literature up to December 2025 using active learning (ASReview) and a "best-fit" framework synthesis to establish a unified AI risk architecture:

  • The Causal Taxonomy (Antecedents): Iterating on Yampolskiy (2016), this mutually exclusive taxonomy categorizes risks by Entity (Human: 38%, AI: 42%, Other/Interactional: 21%), Intent (Intentional: 35%, Unintentional: 35%, Other: 30%), and Timing (Pre-deployment: 13%, Post-deployment: 62%, Other: 25%).
  • The Domain Taxonomy (Consequent Harms): Iterating on Weidinger et al. (2022), this classification organizes 1,506 coded risks across seven domains and 24 subdomains: Discrimination and toxicity; Privacy and security; Misinformation; Malicious actors and misuse (cyberattacks, weapons, fraud); Human-computer interaction (overreliance, agency loss); Socioeconomic and environmental harm (labor disruption, power centralization, governance failure, environmental impact); and AI system safety, failures, and limitations (misalignment, dangerous capabilities, interpretability, robustness, AI welfare, and multi-agent risks).
  • Cross-Framework Gaps: Highlights that existing taxonomies are heavily fragmented—addressing an average of only 8 of the 24 identified subdomains. Emerging areas such as multi-agent interaction risks (present in 7% of frameworks) and AI welfare/sentience (3%) are rarely incorporated.
  • Operational Governance Utility: Outlines practical applications for developers structuring safety cases and design checklists, policymakers operationalizing "high-risk" definitions in frameworks like the EU AI Act, and compliance officers defining objective audit criteria.

💡 Why it matters?

AI governance has long been hampered by "jingle-jangle fallacies," where disparate organizations use identical terms to describe different hazards or invent distinct jargon for identical phenomena. By structuring 1,725 concrete risks into standardized causal and domain models, the repository provides an empirical baseline for risk modeling, regulatory alignment, and auditing. Demonstrating that 38% of risks stem directly from human decisions confirms that risk management cannot solely focus on model technical parameters—it requires rigorous organizational, development, and operational controls.

❓ What's Missing

The repository prioritizes breadth over quantitative depth: it does not assess risk likelihood, severity, or dynamic inter-risk cascading effects. It excludes sector-specific taxonomies (e.g., healthcare diagnostics) and abstract process frameworks. Furthermore, the taxonomy simplifies continuous, cyclical model deployment into static pre- and post-deployment phases, and formal inter-rater reliability testing with independent external coders has not yet been executed.

👥 Best For

AI risk officers, safety researchers, regulatory compliance specialists, enterprise model auditors, and policymakers drafting or operationalizing high-risk AI assessment criteria.

📄 Source Details

Authors: Peter Slattery, Alexander K. Saeri, Emily A.C. Grundy, Jess Graham, Michael Noetel, Risto Uuk, James Dao, Soroush Pour, Stephen Casper, Neil Thompson
Publication: Patterns (Cell Press), Volume 7, Issue 101517, May 8, 2026
Access Repository: http://airisk.mit.edu / DOI Link

📝 Thanks to

Peter Slattery, Alexander K. Saeri, Emily A.C. Grundy, Jess Graham, Michael Noetel, Risto Uuk, James Dao, Soroush Pour, Stephen Casper, and Neil Thompson for developing and maintaining this comprehensive, open-access public resource for the AI governance community.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.