Named risks, not vague hazards.
Each entry here is a specific, recognised AI risk: what it is, why it matters, which controls mitigate it, and which regulatory clauses reference it. A starting scaffold, not an exhaustive register — it grows as engagements surface more.
Filter by severity or category.
5 of 5 risks shown.
Excessive agency in autonomous agents
An agent is granted more permission, tool access, or autonomy than the task requires.
Prompt injection
Attacker-controlled input overrides system instructions, either directly or via retrieved/tool content treated as trusted.
Sensitive information disclosure
A model surfaces training, fine-tuning, or retrieval-sourced sensitive data in its output.
Third-party model and dataset provenance
A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.
Training data bias and discriminatory outcomes
Historical or sampling bias in training data is reproduced or amplified in model outputs and decisions.
See how a risk becomes an engagement.
Every risk here maps to a defined engagement area, scoped against the controls that mitigate it.