1Accountability and Transparency Risk26
2Data & Model Risk12
3Privacy & Security Risk77
S0032Training on Personal Data Without ConsentT07S0033Copyright Disputes Over Web-Scraped ContentT07S0034Secondary Use Beyond Collection PurposeT07S0035Implicit Collection and Opaque ConsentT07S0036Label Tampering AttackT08S0037Backdoor Trigger Sample ImplantationT08S0038Crowdsourced Annotation PoisoningT08S0039Poisoning of the Retrieval Knowledge BaseT08S0040Safety Alignment Broken During Fine-TuningT08S0041Gradient Poisoning in Distributed TrainingT08S0042Manipulation of Human Preference DataT08S0043Upstream Contamination of Automated Data PipelinesT08S0045Malicious Packages Entering the Development EnvironmentT12S0046Backdoored Models on Public PlatformsT12S0047Vulnerabilities in the Training Framework ItselfT12S0048Blind Spots from Missing Component InventoryT12S0049Exploitation of Deep Learning Framework VulnerabilitiesT12S0050Supply Chain Vulnerabilities in Preprocessing ToolsT12S0051Insecure Serialization FormatT13S0052Tampered Training Records Concealing ProblemsT13S0053Replacement of Fine-Tuning Layer FilesT13S0054Opaque Model Provenance ChainT13S0070Adversarial Perturbation of ImagesT09S0071Adversarial Audio and Hidden CommandsT09S0072Adversarial Text Evading DetectionT09S0073Physical-World Adversarial AttackT09S0074Cross-Modal MisdirectionT09S0075Universal Adversarial PerturbationT09S0076Cross-Model Transfer AttackT09S0077Coordinated Multimodal PerturbationT09S0078Functional Replication AttackT11S0088Unencrypted Model Weights LeakedT11S0089Removal of Model MarkersT11S0090Weight Tampering During TransmissionT13S0091Model Substitution at DeploymentT13S0092Hijacking of the Update ChannelT13S0093Inference Interface Without Access ControlT14S0094Unpatched Container Image VulnerabilitiesT14S0095Overly Permissive Cloud Service ConfigurationT14S0096Inference Endpoint as an Internal PivotT14S0097Multi-Tenant Isolation FailureT14S0106Data Leakage Through Model MemorizationT06S0107Membership Inference Revealing ParticipationT06S0108Attribute Inference Revealing Undisclosed TraitsT06S0109Conversation Content Leaking Across UsersT06S0110Reconstruction Risk from Vector RepresentationsT06S0111Identity Inference by Correlating Fragmented DataT06S0112Excessive Collection and Retention of Interaction DataT06S0113Model Inversion Reconstructing Training DataT06S0114Confidential Information Inadvertently Disclosed in PromptsT06S0115Cross-Border Transfer Violating Localization RequirementsT07S0116Disputes Over Authenticity and Attribution of Generated ContentT07S0117Difficulty Exercising Data Subject RightsT07S0118Direct Prompt Injection Bypassing SafeguardsT10S0119Indirect Prompt Injection Hijacking the SystemT10S0120System Instruction DisclosureT10S0121Multi-Step Inducement Attack ChainT10S0122Tool Invocation Manipulated by InjectionT10S0123Covert Goal HijackingT10S0124Multimodal Hidden Instruction InjectionT10S0125Cumulative Context PoisoningT10S0126Retrieval Injection Hijacking OutputT10S0127Capability Theft Through Query DistillationT11S0128Side-Channel Inference of Model InformationT11S0129Side-Channel Risk on Shared Computing PlatformsT12S0130Residual Data in Shared Hardware MemoryT14S0131Service Logs Exposing Sensitive InputsT14S0132Inference Resource Exhaustion AttackT15S0133Hijacking of Computing ResourcesT15S0134Crafted Inputs Amplifying Computational CostT15S0135Autonomous Process Entering an Infinite LoopT15S0136Node Failure Triggering Cascading CollapseT15S0137Cost Amplification AttackT15S0138Single-Supplier Dependency as a Point of FailureT15S0140Autonomous System Accessing Files Beyond AuthorizationT14S0141Unauthorized Outbound Connections by an Autonomous SystemT14S0205Data Persisting in Models Beyond Retention LimitsT07
4Fairness and Discrimination Risk17
5Reliability and Security Risk10
6AI Interaction and Application Risk48
S0055Systemic Risk from Model HomogeneityT21S0087Difficulty of Multi-System Safety ValidationT21S0150Generation of Hate Content Targeting GroupsT20S0151Generation of Virtual Content Harmful to MinorsT20S0152Generated Content Reinforcing StereotypesT19S0153Non-Consensual Synthetic Intimate ImageryT20S0154Automated Generation of Harassment ContentT20S0155Production of Extremist ContentT19S0156Operational Guidance for Illegal ActivityT20S0158Large-Scale Contamination by False InformationT20S0159Professional Over-Reliance on System JudgmentT19S0160Over-Reliance on Risk Assessment ToolsT19S0161Generated Code Adopted Without Developer ReviewT19S0162Over-Reliance on Tools in LearningT19S0163Failure of Human-Machine HandoverT19S0164System Guiding Users Toward Improper ConductT19S0165Anthropomorphism Producing Misplaced TrustT19S0166Harm from Health and Psychological AdviceT19S0167Automation Bias Causing Anomalies to Be OverlookedT19S0168Synthetic Identity FraudT20S0169Mass Production of False ContentT20S0170Highly Customized Phishing AttackT20S0171Lowered Barriers to Dangerous KnowledgeT20S0172Automation of Academic FraudT20S0173Large-Scale Automated SurveillanceT20S0174Misuse of Scientific Reasoning CapabilityT20S0175Precision Social EngineeringT20S0176Manipulation of Elections and Political ProcessesT20S0177Distribution of Non-Consensual Synthetic Intimate ImageryT20S0178Automated Cyber AttackT20S0179Conflicting Objectives Across SystemsT21S0180Information Desynchronization Between SystemsT21S0181Cascading Amplification of ErrorsT21S0182Insufficient Security in Inter-System ProtocolsT21S0183Tacit Coordination Among Autonomous SystemsT21S0184Escalation Through System Interaction in Critical DomainsT21S0185Covert Communication Between SystemsT21S0186Multiple Systems Converging on Collective SuboptimumT21S0187Recommendation Mechanisms Affecting Autonomy of ChoiceT22S0188Process Design Eliminating Human VetoT22S0193Erosion of Professional SkillsT22S0194Emotional Attachment and Psychological ImpactT22S0195Echo Chamber Effects and PolarizationT22S0196Obstruction of Capability DevelopmentT22S0197Impact on Cultural Expression and IdentityT22S0198Changing Patterns of Interpersonal InteractionT22S0199Persuasive Capability and Behavioral ManipulationT22S0200Blurred Authenticity and Cognitive DisorientationT22
7Sustainability and Well-being Risk18