Named risks, not vague hazards.
Each entry here is a specific, recognised AI risk: what it is, why it matters, which controls mitigate it, which regulatory clauses reference it, and which external sources back it up. 48 risks across 9 categories, anchored to 14 standards and regulations. See how the taxonomy, severity model, and mapping philosophy work before diving into individual entries.
Severity by category.
A compact map of the whole library before you filter it.
| Category | critical | high | medium | low | Total |
|---|---|---|---|---|---|
| Model & Application Security | – | 6 | 4 | – | 10 |
| Adversarial ML & Model Integrity | 1 | 2 | 1 | – | 4 |
| Data Protection & Privacy | 2 | 2 | 1 | – | 5 |
| Fairness, Bias & Impact | – | 3 | 1 | – | 4 |
| Governance & Accountability | – | 3 | 3 | – | 6 |
| Third-Party & Supply Chain | – | 2 | 2 | – | 4 |
| Operational Resilience | – | 3 | 1 | – | 4 |
| Transparency & Explainability | – | 1 | 2 | – | 3 |
| Prohibited & High-Risk Practices | 7 | 1 | – | – | 8 |
Browse by list, category, or framework.
48 of 48 risks shown.
Adversarial evasion attacks
Crafted adversarial input causes a model to misclassify or mis-generate, evading a downstream security or safety control.
Adversarial testing coverage gap
No structured adversarial testing exists for an AI system before or after deployment, leaving no empirical basis for its security assurance.
AI literacy gap in the deploying organisation
Staff operating or relying on an AI system's output haven't been given the training needed to understand its limitations, leading to over-trust or misuse.
AI model drift and degradation
A deployed model's performance silently degrades over time as the input distribution shifts away from its training and validation data.
AI not mapped to important business services
AI components embedded in an important business service haven't been identified or mapped, so an AI failure isn't accounted for in the service's impact tolerance.
AI system lifecycle controls gap
AI systems lack defined lifecycle controls, so changes ship without a consistent governance checkpoint from requirements through decommissioning.
AI-driven social scoring
An AI system evaluates or classifies people over time based on social behaviour or inferred characteristics, leading to detrimental or unfavourable treatment.
Automated decision-making without safeguards
AI is used to make solely-automated decisions with legal or similarly significant effects on individuals, without the safeguards UK GDPR requires.
Biometric categorisation of sensitive attributes
A biometric categorisation system infers race, political opinions, trade union membership, religious belief, or sexual orientation.
Cross-border AI data transfer risk
Personal data processed by an AI system, including via a cloud or model provider, is transferred outside the UK without an adequate transfer mechanism.
Data and model poisoning
Training, fine-tuning, or embedding data is deliberately manipulated to introduce vulnerabilities, backdoors, or bias into a model.
Disparate impact monitoring gap
No structured monitoring exists to detect disparate outcomes across protected characteristics once an AI system is in production.
Excessive agency in autonomous agents
An agent is granted more permission, tool access, or autonomy than the task requires.
Exploitation of vulnerable groups by AI
An AI system exploits vulnerabilities due to age, disability, or social or economic situation to distort behaviour and cause significant harm.
Hidden context exposure
Content the operator assumed was hidden from the user, such as retrieval context, RAG schemas, or policy logic, is exposed or inferred through the model, beyond just the system prompt.
Improper output handling
AI-generated output is passed to a downstream interpreter, renderer, or system call without validation, enabling injection-style attacks beyond the model itself.
Inadequate AI resourcing and competence
AI systems are adopted without provisioning the compute, tooling, data quality controls, or trained personnel needed to operate them safely.
Inadequate AI vendor due diligence
An AI vendor is onboarded without due diligence proportionate to how material the service is, including its own AI-specific risk controls.
Inadequate explainability for affected individuals
An AI-driven decision materially affecting a person can't be explained to them in a way they can meaningfully understand or challenge.
Inadequate fairness testing before deployment
An AI system used in a high-risk domain is deployed without pre-deployment testing for disparate performance or outcomes across demographic groups.
Inadequate human oversight design
An AI system's human-oversight mechanism exists on paper but isn't actually usable or effective in practice.
Individual criminal risk profiling
An AI system assesses the risk that an individual will commit a criminal offence based solely on profiling or personality traits.
LLM application supply chain vulnerabilities
Vulnerable or unvetted components — base models, adapters, datasets, plugins, deployment platforms — enter an LLM application through its supply chain.
Misinformation and confabulation
A model states false or fabricated information with the same linguistic confidence as accurate information.
Missing AI impact assessment process
AI systems are deployed without a structured process to assess their impact on individuals, groups, and society before go-live.
Missing DPIA for high-risk AI processing
AI processing likely to result in high risk to individuals proceeds without a documented Data Protection Impact Assessment.
Model backdoors and trojans
A hidden, trigger-activated backdoor is embedded in a model via poisoned training data, weight tampering, or a payload injected into the model artifact.
Model extraction and inference-API abuse
Repeated querying of a model's inference API extracts private training data or effectively replicates the model itself.
No documented AI policy
The organisation operates AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.
No impact tolerance for AI-dependent services
A business service that depends on an AI system has no defined impact tolerance for AI-specific disruption.
Prompt injection
Attacker-controlled input overrides system instructions, either directly or via retrieved/tool content treated as trusted.
Proxy discrimination via correlated features
A model achieves discriminatory outcomes indirectly, through features that correlate with a protected characteristic even when that characteristic is excluded from the input.
Real-time public biometric identification
Real-time remote biometric identification is used in publicly accessible spaces for law enforcement purposes, outside the three narrow statutory exceptions.
Sensitive information disclosure
A model surfaces training, fine-tuning, or retrieval-sourced sensitive data in its output.
Sub-outsourcing visibility gap
An AI vendor sub-contracts part of the service without the originating organisation having visibility or contractual control over that layer.
Subliminal or manipulative AI techniques
An AI system deploys subliminal, manipulative, or deceptive techniques that materially distort a person's behaviour and cause significant harm.
System prompt leakage
The system prompt is extracted or inferred, exposing configuration, guardrail logic, or embedded credentials.
Third-party model and dataset provenance
A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.
Training data bias and discriminatory outcomes
Historical or sampling bias in training data is reproduced or amplified in model outputs and decisions.
Unbounded resource consumption
Unrestricted or excessive inference requests lead to denial of service, denial of wallet, or facilitate model theft.
Unclear AI ownership and accountability
No individual or committee owns AI risk decisions end-to-end, so accountability for a given system's behaviour is diffuse or absent.
Undisclosed AI interaction
A person interacts with an AI system without being informed they are doing so.
Unlawful or undocumented training data basis
Personal data used to train, fine-tune, or ground an AI system lacks a documented lawful basis, or exceeds the purpose and minimisation limits of the basis relied on.
Untargeted facial recognition scraping
Facial images are scraped from the internet or CCTV footage without targeting, to build or expand a facial recognition database.
Untested AI failure scenarios
No scenario testing exists for AI-specific disruption modes against the organisation's impact tolerances.
Vector and embedding weaknesses
Weaknesses in how vectors and embeddings are generated, stored, or retrieved in a retrieval-augmented generation pipeline let an attacker poison or exfiltrate the knowledge base.
Vendor concentration and exit strategy gap
The organisation is dependent on a single AI model or vendor for a critical function with no viable exit plan or alternative provider identified.
Workplace and education emotion recognition
An AI system infers emotions in the workplace or an education institution, outside the narrow medical or safety exceptions.
See how a risk becomes an engagement.
Every risk here maps to a defined engagement area, scoped against the controls that mitigate it.