Why AI risk feels so confusing
Over the past two years, “AI risk” has become a ubiquitous phrase. It appears in board presentations, regulatory consultations, strategy decks, and media headlines. Depending on who is speaking, it can mean hallucinating chatbots, biased credit decisions, intellectual-property leakage, large-scale misinformation, or even existential threat. These concerns are all legitimate, and they differ in nature, origin, and how they manifest.
When a single label describes such different phenomena, it becomes hard to reason about risk in a disciplined way, let alone govern it. There is a reason for the confusion: years of parallel work across academia, industry, and policy, each approaching AI risk from a different angle. To cut through it, a large research effort led by MIT reviewed existing AI risk frameworks and real-world incidents.
One repository, more than one way to classify risk
The MIT AI Risk Repository brings together over 1,200 reported AI incidents and more than 2,000 distinct risks, drawn from hundreds of academic, industry, and policy sources. Its aim is to give organizations a common frame of reference for AI risk.
Its central finding is straightforward. AI risks need to be read through more than one lens, and confusion sets in when those lenses collapse into a single list. The repository separates two questions that often get merged:
- How a risk emerges: the causal lens. Who or what caused it, was it intentional, and when did it arise?
- What harm it produces: the impact lens. What gets harmed when the risk materializes?
Lens one: how the risk emerges
The first lens is about causality. It asks who or what caused the risk (a human, an AI system, or external conditions), whether the outcome was intentional or accidental, and whether it arose before deployment or only in operational use. This mirrors how other safety-critical domains reason about causation, where understanding how a failure comes into existence is essential for accountability and prevention.
The repository’s incident data shows that roughly 67% of incidents are attributed primarily to AI system behavior and about 33% to human action, with a small residual of ambiguous cases. That balance reflects how socio-technical AI risk is: system behavior encodes upstream human decisions in design, training, configuration, and deployment, which then interact with real-world conditions.
Intent is almost evenly divided. Roughly half of incidents stem from deliberate misuse, and half arise unintentionally through system behavior, misalignment, or unforeseen interactions. Controls aimed only at misuse leave the other half unaddressed. Timing sharpens the picture: about 97.5% of reported incidents occur after deployment, and fewer than 3% surface before systems go live. Most AI risk emerges once a system is running in the real world.
Lens two: what kind of harm results
The second lens classifies risks by impact domain, the type of harm produced: discrimination, misinformation, safety failures, privacy violations, or broader societal effects. It answers a different question. What gets harmed when the risk materializes? This view is intuitive and dominant in policy and ethics discussion.
Reported incidents are highly concentrated. About three-quarters fall into four domains: malicious use (around 34%), AI system safety failures and limitations (around 23%), discrimination and toxicity (around 19%), and misinformation (around 13%). A single incident can carry more than one domain label, so the individual shares add up to more than the 75% aggregate. The remaining domains, including privacy and security, human-computer interaction, and socioeconomic and environmental harms, account for a much smaller share of reported incidents.
Those four domains mark where AI systems are most exposed today: at scale, in open environments, and in direct contact with users. Whether they are the harms that matter most is a separate question the data leaves open. The split also makes MIT’s core point concrete. Causal explanations and impact domains do different jobs: calling something a “bias risk” says nothing about how it emerged, and labelling a failure “accidental” says nothing about who was harmed.
Why this matters for organizations
Treated as a single block, AI risk produces long, overlapping risk registers, unclear ownership, and controls that are either excessively heavy or dangerously thin. The repository’s empirical signals point to three practical implications.
First, governance has to work proactively. With incidents split almost evenly between intentional misuse and unintentional failure, post-incident response and misuse controls only ever cover half the ground. Organizations need to anticipate both deliberate abuse and ordinary operational drift.
Second, governance has to distinguish between risk sources. The roughly 67/33 split between system behavior and human action describes two different problems with two different owners. System-level risks call for technical controls, testing, monitoring, and lifecycle gates tied to specific AI systems. Organization-wide risks call for policies, training, access controls, and cultural safeguards that shape how people use AI. Treating them as one blurs accountability.
Third, governance has to run across the lifecycle. With more than 97% of incidents happening after deployment, controls that concentrate upstream and ease off once a system is live are aimed at the wrong phase. The weight belongs on continuous monitoring, feedback loops, and periodic reassessment after systems are deployed and scaled.
From confusion to governability
Together, these findings describe what AI governance has to be: an ongoing risk-management discipline that anticipates problems, separates system risks from human ones, and stays active while systems run. Compliance documentation and design reviews have their place inside that discipline, though they cannot stand in for it.
AI risk is more tractable than the noise around it suggests, and it does not call for a new discipline. It follows familiar logic: events, probabilities, and impacts. What has been missing is a shared structure. The MIT AI Risk Repository supplies that structure and gives organizations a foundation to move from anxiety to informed decisions. The work left to each organization is to turn that clarity into governance structures, controls, and decision processes that match how AI risks actually show up.