Named risks, not vague hazards.

Each entry here is a specific, recognised AI risk: what it is, why it matters, which controls mitigate it, which regulatory clauses reference it, and which external sources back it up. 48 risks across 9 categories, anchored to 14 standards and regulations. See how the taxonomy, severity model, and mapping philosophy work before diving into individual entries.

Severity by category.

A compact map of the whole library before you filter it.

CategorycriticalhighmediumlowTotal
Model & Application Security6410
Adversarial ML & Model Integrity1214
Data Protection & Privacy2215
Fairness, Bias & Impact314
Governance & Accountability336
Third-Party & Supply Chain224
Operational Resilience314
Transparency & Explainability123
Prohibited & High-Risk Practices718

Browse by list, category, or framework.

48 of 48 risks shown.

high · Adversarial ML & Model Integrity

Adversarial evasion attacks

Crafted adversarial input causes a model to misclassify or mis-generate, evading a downstream security or safety control.

medium · Adversarial ML & Model Integrity

Adversarial testing coverage gap

No structured adversarial testing exists for an AI system before or after deployment, leaving no empirical basis for its security assurance.

medium · Transparency & Explainability

AI literacy gap in the deploying organisation

Staff operating or relying on an AI system's output haven't been given the training needed to understand its limitations, leading to over-trust or misuse.

high · Operational Resilience

AI model drift and degradation

A deployed model's performance silently degrades over time as the input distribution shifts away from its training and validation data.

high · Operational Resilience

AI not mapped to important business services

AI components embedded in an important business service haven't been identified or mapped, so an AI failure isn't accounted for in the service's impact tolerance.

medium · Governance & Accountability

AI system lifecycle controls gap

AI systems lack defined lifecycle controls, so changes ship without a consistent governance checkpoint from requirements through decommissioning.

critical · Prohibited & High-Risk Practices

AI-driven social scoring

An AI system evaluates or classifies people over time based on social behaviour or inferred characteristics, leading to detrimental or unfavourable treatment.

critical · Data Protection & Privacy

Automated decision-making without safeguards

AI is used to make solely-automated decisions with legal or similarly significant effects on individuals, without the safeguards UK GDPR requires.

critical · Prohibited & High-Risk Practices

Biometric categorisation of sensitive attributes

A biometric categorisation system infers race, political opinions, trade union membership, religious belief, or sexual orientation.

medium · Data Protection & Privacy

Cross-border AI data transfer risk

Personal data processed by an AI system, including via a cloud or model provider, is transferred outside the UK without an adequate transfer mechanism.

high · Model & Application Security

Data and model poisoning

Training, fine-tuning, or embedding data is deliberately manipulated to introduce vulnerabilities, backdoors, or bias into a model.

high · Fairness, Bias & Impact

Disparate impact monitoring gap

No structured monitoring exists to detect disparate outcomes across protected characteristics once an AI system is in production.

high · Model & Application Security

Excessive agency in autonomous agents

An agent is granted more permission, tool access, or autonomy than the task requires.

critical · Prohibited & High-Risk Practices

Exploitation of vulnerable groups by AI

An AI system exploits vulnerabilities due to age, disability, or social or economic situation to distort behaviour and cause significant harm.

medium · Model & Application Security

Hidden context exposure

Content the operator assumed was hidden from the user, such as retrieval context, RAG schemas, or policy logic, is exposed or inferred through the model, beyond just the system prompt.

high · Model & Application Security

Improper output handling

AI-generated output is passed to a downstream interpreter, renderer, or system call without validation, enabling injection-style attacks beyond the model itself.

medium · Governance & Accountability

Inadequate AI resourcing and competence

AI systems are adopted without provisioning the compute, tooling, data quality controls, or trained personnel needed to operate them safely.

high · Third-Party & Supply Chain

Inadequate AI vendor due diligence

An AI vendor is onboarded without due diligence proportionate to how material the service is, including its own AI-specific risk controls.

high · Transparency & Explainability

Inadequate explainability for affected individuals

An AI-driven decision materially affecting a person can't be explained to them in a way they can meaningfully understand or challenge.

medium · Fairness, Bias & Impact

Inadequate fairness testing before deployment

An AI system used in a high-risk domain is deployed without pre-deployment testing for disparate performance or outcomes across demographic groups.

high · Governance & Accountability

Inadequate human oversight design

An AI system's human-oversight mechanism exists on paper but isn't actually usable or effective in practice.

critical · Prohibited & High-Risk Practices

Individual criminal risk profiling

An AI system assesses the risk that an individual will commit a criminal offence based solely on profiling or personality traits.

high · Model & Application Security

LLM application supply chain vulnerabilities

Vulnerable or unvetted components — base models, adapters, datasets, plugins, deployment platforms — enter an LLM application through its supply chain.

high · Model & Application Security

Misinformation and confabulation

A model states false or fabricated information with the same linguistic confidence as accurate information.

high · Governance & Accountability

Missing AI impact assessment process

AI systems are deployed without a structured process to assess their impact on individuals, groups, and society before go-live.

high · Data Protection & Privacy

Missing DPIA for high-risk AI processing

AI processing likely to result in high risk to individuals proceeds without a documented Data Protection Impact Assessment.

critical · Adversarial ML & Model Integrity

Model backdoors and trojans

A hidden, trigger-activated backdoor is embedded in a model via poisoned training data, weight tampering, or a payload injected into the model artifact.

high · Adversarial ML & Model Integrity

Model extraction and inference-API abuse

Repeated querying of a model's inference API extracts private training data or effectively replicates the model itself.

high · Governance & Accountability

No documented AI policy

The organisation operates AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.

high · Operational Resilience

No impact tolerance for AI-dependent services

A business service that depends on an AI system has no defined impact tolerance for AI-specific disruption.

high · Model & Application Security

Prompt injection

Attacker-controlled input overrides system instructions, either directly or via retrieved/tool content treated as trusted.

high · Fairness, Bias & Impact

Proxy discrimination via correlated features

A model achieves discriminatory outcomes indirectly, through features that correlate with a protected characteristic even when that characteristic is excluded from the input.

critical · Prohibited & High-Risk Practices

Real-time public biometric identification

Real-time remote biometric identification is used in publicly accessible spaces for law enforcement purposes, outside the three narrow statutory exceptions.

critical · Data Protection & Privacy

Sensitive information disclosure

A model surfaces training, fine-tuning, or retrieval-sourced sensitive data in its output.

medium · Third-Party & Supply Chain

Sub-outsourcing visibility gap

An AI vendor sub-contracts part of the service without the originating organisation having visibility or contractual control over that layer.

critical · Prohibited & High-Risk Practices

Subliminal or manipulative AI techniques

An AI system deploys subliminal, manipulative, or deceptive techniques that materially distort a person's behaviour and cause significant harm.

medium · Model & Application Security

System prompt leakage

The system prompt is extracted or inferred, exposing configuration, guardrail logic, or embedded credentials.

medium · Third-Party & Supply Chain

Third-party model and dataset provenance

A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.

high · Fairness, Bias & Impact

Training data bias and discriminatory outcomes

Historical or sampling bias in training data is reproduced or amplified in model outputs and decisions.

medium · Model & Application Security

Unbounded resource consumption

Unrestricted or excessive inference requests lead to denial of service, denial of wallet, or facilitate model theft.

medium · Governance & Accountability

Unclear AI ownership and accountability

No individual or committee owns AI risk decisions end-to-end, so accountability for a given system's behaviour is diffuse or absent.

medium · Transparency & Explainability

Undisclosed AI interaction

A person interacts with an AI system without being informed they are doing so.

high · Data Protection & Privacy

Unlawful or undocumented training data basis

Personal data used to train, fine-tune, or ground an AI system lacks a documented lawful basis, or exceeds the purpose and minimisation limits of the basis relied on.

critical · Prohibited & High-Risk Practices

Untargeted facial recognition scraping

Facial images are scraped from the internet or CCTV footage without targeting, to build or expand a facial recognition database.

medium · Operational Resilience

Untested AI failure scenarios

No scenario testing exists for AI-specific disruption modes against the organisation's impact tolerances.

medium · Model & Application Security

Vector and embedding weaknesses

Weaknesses in how vectors and embeddings are generated, stored, or retrieved in a retrieval-augmented generation pipeline let an attacker poison or exfiltrate the knowledge base.

high · Third-Party & Supply Chain

Vendor concentration and exit strategy gap

The organisation is dependent on a single AI model or vendor for a critical function with no viable exit plan or alternative provider identified.

high · Prohibited & High-Risk Practices

Workplace and education emotion recognition

An AI system infers emotions in the workplace or an education institution, outside the narrow medical or safety exceptions.

See how a risk becomes an engagement.

Every risk here maps to a defined engagement area, scoped against the controls that mitigate it.