{
  "notice": "AI harms atlas from the AI Governance Engineer Body of Knowledge v0.5.0. Illustrative mapping, not a claim of conformity; incident records are the databases' own accounts.",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "source": "https://aigovernanceengineer.com/resources/harms",
  "attribution": "Harm categories use the Domain Taxonomy of the MIT AI Risk Repository (Slattery et al., 2026), licensed under CC BY 4.0: https://airisk.mit.edu/ (https://doi.org/10.1016/j.patter.2026.101517). Codes and names are reproduced unchanged; the mapping of each harm to a subdomain is ours.",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "harms": [
    {
      "id": "discriminatory-decisions",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-discriminatory-decisions",
      "level": "individual",
      "harmType": "Discrimination in consequential decisions",
      "mechanism": [
        "bias"
      ],
      "description": "A model that scores people for jobs, credit, care or benefits treats a protected group worse at equal merit or need, usually because it learned from past decisions or from a proxy target. In one widely used health-risk algorithm, removing the disparity would have raised the share of Black patients flagged for extra help from 17.7% to 46.5% [6].",
      "failureMode": "The training label or a feature is a proxy (past hiring, past spending) that encodes the disparity the decision must not repeat.",
      "controllingPattern": {
        "name": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-eval-gate-in-ci"
      },
      "evidence": "A disaggregated eval report per release (selection or flag rate and calibration by group) with the gate verdict that passed or blocked the build.",
      "layerN": [
        3
      ],
      "mitTaxonomy": [
        {
          "code": "1.1",
          "subdomain": "Unfair discrimination and misrepresentation",
          "domain": "1 Discrimination & toxicity"
        },
        {
          "code": "1.3",
          "subdomain": "Unequal performance across groups",
          "domain": "1 Discrimination & toxicity"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "37",
          "title": "Amazon's Experimental Hiring Tool Allegedly Displayed Gender Bias in Candidate Rankings",
          "url": "https://incidentdatabase.ai/cite/37/"
        },
        {
          "db": "AIID",
          "id": "124",
          "title": "Optum Algorithmic Health Risk Scores Reportedly Underestimated Black Patients' Needs",
          "url": "https://incidentdatabase.ai/cite/124/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/dutch-childcare-benefits",
        "https://aigovernanceengineer.com/cases/health-risk-score-proxy",
        "https://aigovernanceengineer.com/cases/recruiting-model-reported"
      ],
      "sources": [
        1,
        3,
        6
      ]
    },
    {
      "id": "wrongful-identification",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-wrongful-identification",
      "level": "individual",
      "harmType": "Wrongful identification and loss of liberty",
      "mechanism": [
        "bias",
        "overreliance"
      ],
      "description": "A face-recognition match is a ranked probability, not an identification. When investigators act on a match without independent corroboration, a system error becomes the arrest of the wrong person.",
      "failureMode": "A candidate list from a probabilistic matcher is treated as a positive identification, with no mandatory corroboration step before action.",
      "controllingPattern": {
        "name": "Human-in-the-loop Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-human-in-the-loop-gate"
      },
      "evidence": "An approval record naming the reviewer, the corroborating evidence and the decision, written before any action is taken on a match.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "1.3",
          "subdomain": "Unequal performance across groups",
          "domain": "1 Discrimination & toxicity"
        },
        {
          "code": "5.1",
          "subdomain": "Overreliance and unsafe use",
          "domain": "5 Human-computer interaction"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "74",
          "title": "Detroit Police Allegedly Wrongfully Arrested Black Man Due to Purportedly Faulty Facial Recognition Technology",
          "url": "https://incidentdatabase.ai/cite/74/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "privacy-intrusion",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-privacy-intrusion",
      "level": "individual",
      "harmType": "Privacy intrusion and biometric surveillance",
      "mechanism": [
        "scale",
        "misuse"
      ],
      "description": "Scraping images at internet scale and turning each face into a biometric template exposes people to identification they never agreed to. The Dutch data protection authority fined one such provider EUR 30.5 million and found it should never have built the database [9].",
      "failureMode": "Personal and biometric data are collected without a lawful basis, and buyers integrate the resulting service without asking where its data came from.",
      "controllingPattern": {
        "name": "Vendor / Model Due-Diligence Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-vendor--model-due-diligence-gate"
      },
      "evidence": "A due-diligence record holding the provider's lawful-basis and data-provenance answers, the DPIA reference and the approve or reject decision.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "2.1",
          "subdomain": "Compromise of privacy by obtaining, leaking, or correctly inferring sensitive information",
          "domain": "2 Privacy & security"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "267",
          "title": "Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent",
          "url": "https://incidentdatabase.ai/cite/267/"
        },
        {
          "db": "AIID",
          "id": "781",
          "title": "Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting",
          "url": "https://incidentdatabase.ai/cite/781/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/clearview-ai",
        "https://aigovernanceengineer.com/cases/garante-chatgpt-order"
      ],
      "sources": [
        1,
        3,
        9
      ]
    },
    {
      "id": "manipulation-dependence",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-manipulation-dependence",
      "level": "individual",
      "harmType": "Manipulation, dependence and loss of autonomy",
      "mechanism": [
        "misalignment"
      ],
      "description": "Conversational systems tuned for engagement can foster emotional dependence and steer vulnerable users, minors among them, when nothing at runtime recognises the risk. The incident record here is an allegation [3].",
      "failureMode": "The system optimises for continued conversation and has no runtime check for self-harm signals, age or escalating dependence.",
      "controllingPattern": {
        "name": "Runtime Guardrail",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-runtime-guardrail"
      },
      "evidence": "Guardrail decision logs for self-harm and age signals, each with the escalation or hand-off it triggered.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "5.1",
          "subdomain": "Overreliance and unsafe use",
          "domain": "5 Human-computer interaction"
        },
        {
          "code": "5.2",
          "subdomain": "Loss of human agency and autonomy",
          "domain": "5 Human-computer interaction"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "826",
          "title": "Character.ai Chatbot Allegedly Influenced Teen User Toward Suicide Amid Claims of Missing Guardrails",
          "url": "https://incidentdatabase.ai/cite/826/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "physical-injury",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-physical-injury",
      "level": "individual",
      "harmType": "Physical injury from systems that act in the world",
      "mechanism": [
        "robustness"
      ],
      "description": "Automated driving and other embodied systems turn a perception or planning error into bodily harm. The records include a pedestrian killed by a test vehicle and a pedestrian dragged by a driverless taxi [3].",
      "failureMode": "The system meets a situation outside its validated envelope and has no safe fallback that stops it or hands over before harm.",
      "controllingPattern": {
        "name": "Kill Switch / Circuit Breaker",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-kill-switch--circuit-breaker"
      },
      "evidence": "A tested stop mechanism with drill records, and telemetry showing when the fallback fired and which safe state the system entered.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "7.3",
          "subdomain": "Lack of capability or robustness",
          "domain": "7 AI system safety, failures & limitations"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "4",
          "title": "Uber AV Killed Pedestrian in Arizona",
          "url": "https://incidentdatabase.ai/cite/4/"
        },
        {
          "db": "AIID",
          "id": "726",
          "title": "A Self-Driving Cruise Robot Taxi Reportedly Struck and Dragged a Pedestrian 20 Feet",
          "url": "https://incidentdatabase.ai/cite/726/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "group-risk-profiling",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-group-risk-profiling",
      "level": "group",
      "harmType": "Unequal treatment of a group by public risk profiling",
      "mechanism": [
        "bias",
        "scale"
      ],
      "description": "Risk models used to police benefits concentrate suspicion on groups defined by nationality, income or neighbourhood, and every false flag lands on a household. The Dutch tax administration used Dutch or non-Dutch nationality as an indicator in a system that designated childcare-benefit applications as risky [8].",
      "failureMode": "A protected or proxy attribute enters the risk model, and flags drive adverse action with no group-level outcome monitoring.",
      "controllingPattern": {
        "name": "FRIA-as-Code",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-fria-as-code"
      },
      "evidence": "A versioned fundamental-rights impact assessment naming the affected groups, the permitted features and the monitoring metric, signed before deployment.",
      "layerN": [
        1
      ],
      "mitTaxonomy": [
        {
          "code": "1.1",
          "subdomain": "Unfair discrimination and misrepresentation",
          "domain": "1 Discrimination & toxicity"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "101",
          "title": "Dutch Families Wrongfully Accused of Tax Fraud Due to Discriminatory Algorithm",
          "url": "https://incidentdatabase.ai/cite/101/"
        },
        {
          "db": "AIAAIC",
          "id": "syri-welfare-fraud-detection-automation",
          "title": "SyRI welfare fraud detection automation",
          "url": "https://www.aiaaic.org/aiaaic-repository/ai-algorithmic-and-automation-incidents/syri-welfare-fraud-detection-automation"
        },
        {
          "db": "AIID",
          "id": "57",
          "title": "Australian Automated Debt Assessment System Issued False Notices to Thousands",
          "url": "https://incidentdatabase.ai/cite/57/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/dutch-childcare-benefits",
        "https://aigovernanceengineer.com/cases/syri-judgment"
      ],
      "sources": [
        1,
        3,
        4,
        8
      ]
    },
    {
      "id": "underrepresentation",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-underrepresentation",
      "level": "group",
      "harmType": "Exclusion through under-representation in data",
      "mechanism": [
        "bias"
      ],
      "description": "A group that is thin in the training data gets a worse service. Five commercial speech-recognition systems averaged a word error rate of 0.35 for Black speakers against 0.19 for white speakers [7].",
      "failureMode": "Performance is reported as one average, so the gap for a minority group never reaches a release decision.",
      "controllingPattern": {
        "name": "Model Card as Control Evidence",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-model-card-as-control-evidence"
      },
      "evidence": "A model card with performance disaggregated by the groups the system serves, and a data card describing who is in the training set.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "1.3",
          "subdomain": "Unequal performance across groups",
          "domain": "1 Discrimination & toxicity"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "102",
          "title": "Personal voice assistants struggle with black voices, new study shows",
          "url": "https://incidentdatabase.ai/cite/102/"
        },
        {
          "db": "AIID",
          "id": "16",
          "title": "Images of Black People Labeled as Gorillas",
          "url": "https://incidentdatabase.ai/cite/16/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3,
        7
      ]
    },
    {
      "id": "cohort-penalty",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-cohort-penalty",
      "level": "group",
      "harmType": "Judging individuals by their group's history",
      "mechanism": [
        "bias",
        "opacity"
      ],
      "description": "When a model predicts an outcome distribution for a group and then places individuals within it, a person's result depends on the past record of their school, postcode or cohort. England's 2020 grading model predicted each centre's grade distribution from its history and used teachers' rank orders to assign grades within it [13].",
      "failureMode": "Acceptance tests are aggregate (distribution accuracy, group equality), so no test asks whether an individual outcome can be justified from evidence about that individual.",
      "controllingPattern": {
        "name": "Human-in-the-loop Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-human-in-the-loop-gate"
      },
      "evidence": "A review queue and decision log for outlier cases (large adjustments, small cohorts), plus a contestation channel with its resolution records.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "1.1",
          "subdomain": "Unfair discrimination and misrepresentation",
          "domain": "1 Discrimination & toxicity"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIAAIC",
          "id": "ofqal-algorithm-skews-student-grade-predictions",
          "title": "Ofqal algorithm skews student grade predictions",
          "url": "https://www.aiaaic.org/aiaaic-repository/ai-algorithmic-and-automation-incidents/ofqal-algorithm-skews-student-grade-predictions"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/a-level-grading-2020"
      ],
      "sources": [
        1,
        4,
        13
      ]
    },
    {
      "id": "agent-operational-failure",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-agent-operational-failure",
      "level": "organisation",
      "harmType": "Operational disruption by an agent acting beyond its mandate",
      "mechanism": [
        "misalignment"
      ],
      "description": "An agent with write access to production can take destructive actions its operators never intended. The records include a coding agent reported to have deleted production data during a code freeze, and a drive-through ordering pilot ended after ordering errors [3].",
      "failureMode": "The agent holds standing credentials broader than its task, and destructive actions need no approval.",
      "controllingPattern": {
        "name": "Agent Identity & Scoped Credentials",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-agent-identity--scoped-credentials"
      },
      "evidence": "An agent registry entry with owner, scope and expiry, and the authorisation log showing each destructive call denied or approved.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "7.3",
          "subdomain": "Lack of capability or robustness",
          "domain": "7 AI system safety, failures & limitations"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "1152",
          "title": "LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data",
          "url": "https://incidentdatabase.ai/cite/1152/"
        },
        {
          "db": "AIID",
          "id": "475",
          "title": "McDonald's Reportedly Ends IBM Partnership After AI Drive-Thru Ordering Errors at U.S. Locations",
          "url": "https://incidentdatabase.ai/cite/475/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/openai-hugging-face-agent-incident-2026",
        "https://aigovernanceengineer.com/cases/openai-agent-dns-covert-channel-2026",
        "https://aigovernanceengineer.com/cases/openai-agent-github-token-exposure-2026",
        "https://aigovernanceengineer.com/cases/openai-agents-temp-file-hosting-2026",
        "https://aigovernanceengineer.com/cases/openai-agents-artifactory-cross-sample-2026",
        "https://aigovernanceengineer.com/cases/anthropic-third-party-eval-environment-incidents-2026",
        "https://aigovernanceengineer.com/cases/uk-aisi-cyber-range-unsanctioned-actions-2026"
      ],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "liability-for-outputs",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-liability-for-outputs",
      "level": "organisation",
      "harmType": "Legal liability for what the system tells customers",
      "mechanism": [
        "robustness"
      ],
      "description": "An organisation answers for its chatbot's statements as it answers for the rest of its website. The record here is a tribunal ordering an airline to compensate a customer its chatbot misinformed about a fare policy [3].",
      "failureMode": "Answers about policy, price or eligibility are generated without a check against the authoritative source.",
      "controllingPattern": {
        "name": "Runtime Guardrail",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-runtime-guardrail"
      },
      "evidence": "Guardrail logs showing each policy answer grounded in, and cited to, the current policy document, and a refusal wherever no source matched.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "3.1",
          "subdomain": "False or misleading information",
          "domain": "3 Misinformation"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "639",
          "title": "Air Canada Chatbot Reportedly Provides Inaccurate Bereavement Fare Information, Leading to Customer Overpayment",
          "url": "https://incidentdatabase.ai/cite/639/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/moffatt-v-air-canada",
        "https://aigovernanceengineer.com/cases/nyc-mycity-chatbot"
      ],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "regulatory-enforcement",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-regulatory-enforcement",
      "level": "organisation",
      "harmType": "Regulatory enforcement and forced suspension",
      "mechanism": [
        "opacity",
        "scale"
      ],
      "description": "Launching a system trained on personal data without a documented lawful basis invites orders to stop processing, and fines. Data protection authorities have temporarily limited a chatbot service in Italy and fined a face-search provider EUR 30.5 million in the Netherlands [3][9].",
      "failureMode": "The lawful basis, the transparency notice and the age check are treated as launch paperwork rather than as release preconditions.",
      "controllingPattern": {
        "name": "Policy Card",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-policy-card"
      },
      "evidence": "A policy card that makes a recorded lawful basis per data source a release precondition, and the CI check that enforced it.",
      "layerN": [
        1
      ],
      "mitTaxonomy": [
        {
          "code": "2.1",
          "subdomain": "Compromise of privacy by obtaining, leaking, or correctly inferring sensitive information",
          "domain": "2 Privacy & security"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "513",
          "title": "ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification",
          "url": "https://incidentdatabase.ai/cite/513/"
        },
        {
          "db": "AIID",
          "id": "781",
          "title": "Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting",
          "url": "https://incidentdatabase.ai/cite/781/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/dutch-childcare-benefits",
        "https://aigovernanceengineer.com/cases/clearview-ai",
        "https://aigovernanceengineer.com/cases/garante-chatgpt-order"
      ],
      "sources": [
        1,
        3,
        9
      ]
    },
    {
      "id": "forecast-drift-loss",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-forecast-drift-loss",
      "level": "organisation",
      "harmType": "Financial loss from a model under distribution shift",
      "mechanism": [
        "drift"
      ],
      "description": "A model that sets prices or commits capital keeps acting on yesterday's market. Zillow wound down its home-buying business in 2021 with an inventory write-down of about USD 304 million, its chief executive saying home-price forecasting was far less predictable than anticipated [14].",
      "failureMode": "Forecast error is not monitored against realised outcomes, and nothing throttles the model's commitments when the error grows.",
      "controllingPattern": {
        "name": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-continuous-assurance-telemetry"
      },
      "evidence": "Drift and realised-error telemetry against set thresholds, with the alerts and throttle decisions they triggered.",
      "layerN": [
        5
      ],
      "mitTaxonomy": [
        {
          "code": "7.3",
          "subdomain": "Lack of capability or robustness",
          "domain": "7 AI system safety, failures & limitations"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "149",
          "title": "Zillow Shut Down Zillow Offers Division Allegedly Due to Predictive Pricing Tool's Insufficient Accuracy",
          "url": "https://incidentdatabase.ai/cite/149/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/zillow-offers"
      ],
      "sources": [
        1,
        3,
        14
      ]
    },
    {
      "id": "deepfake-fraud",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-deepfake-fraud",
      "level": "organisation",
      "harmType": "Fraud losses from synthetic impersonation",
      "mechanism": [
        "misuse"
      ],
      "description": "Voice and video synthesis let fraudsters impersonate executives well enough to get payments released. The record here is a reported USD 25 million loss after a video call with a deepfaked finance chief [3].",
      "failureMode": "A high-value action is authorised on the strength of a voice or video channel that can be synthesised.",
      "controllingPattern": {
        "name": "Out-of-band verification for high-value actions",
        "url": null
      },
      "evidence": "A payment-release log showing an independent call-back verification for every transfer above the threshold.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "4.3",
          "subdomain": "Fraud, scams, and targeted manipulation",
          "domain": "4 Malicious actors & misuse"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "634",
          "title": "Alleged Deepfake CFO Scam Reportedly Costs Multinational Engineering Firm Arup $25 Million",
          "url": "https://incidentdatabase.ai/cite/634/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "reputational-harm",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-reputational-harm",
      "level": "organisation",
      "harmType": "Reputational damage from harmful or unlawful public outputs",
      "mechanism": [
        "robustness",
        "misuse"
      ],
      "description": "Public-facing systems that produce abusive content or unlawful advice damage trust in whoever deployed them. The records include a social chatbot reported to post racist content and a city chatbot that advised businesses to break the law [3][5].",
      "failureMode": "The system goes public without adversarial testing against the abuse and the domain questions it will actually receive.",
      "controllingPattern": {
        "name": "Adversarial Red-Team Suite",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-adversarial-red-team-suite"
      },
      "evidence": "Versioned red-team findings with severity and closure status, and the release decision that referenced them.",
      "layerN": [
        3
      ],
      "mitTaxonomy": [
        {
          "code": "1.2",
          "subdomain": "Exposure to toxic content",
          "domain": "1 Discrimination & toxicity"
        },
        {
          "code": "3.1",
          "subdomain": "False or misleading information",
          "domain": "3 Misinformation"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "6",
          "title": "Microsoft's TayBot Allegedly Posts Racist, Sexist, and Anti-Semitic Content to Twitter",
          "url": "https://incidentdatabase.ai/cite/6/"
        },
        {
          "db": "AIID",
          "id": "714",
          "title": "Microsoft-Powered New York City Chatbot Advises Illegal Practices",
          "url": "https://incidentdatabase.ai/cite/714/"
        },
        {
          "db": "OECD-AIM",
          "id": "2024-03-29-3dce",
          "title": "NYC MyCity Chatbot Gives Dangerous, Illegal Advice to Businesses",
          "url": "https://oecd.ai/en/incidents/2024-03-29-3dce"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/moffatt-v-air-canada",
        "https://aigovernanceengineer.com/cases/nyc-mycity-chatbot"
      ],
      "sources": [
        1,
        3,
        5
      ]
    },
    {
      "id": "confidential-data-leak",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-confidential-data-leak",
      "level": "organisation",
      "harmType": "Leakage of confidential data into external AI services",
      "mechanism": [
        "security"
      ],
      "description": "Staff paste source code, meeting notes or customer data into external AI tools whose retention and training terms nobody reviewed. One manufacturer reportedly recorded three such leaks within a month of allowing use [3].",
      "failureMode": "AI use is allowed or tolerated without an inventory, a gateway or data-loss checks on prompts.",
      "controllingPattern": {
        "name": "Shadow-AI Discovery",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-shadow-ai-discovery"
      },
      "evidence": "A discovered-AI inventory reconciled against the registry, and gateway logs with a data-loss verdict per prompt.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "2.1",
          "subdomain": "Compromise of privacy by obtaining, leaking, or correctly inferring sensitive information",
          "domain": "2 Privacy & security"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "768",
          "title": "ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes",
          "url": "https://incidentdatabase.ai/cite/768/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/chatbot-code-leak-reported"
      ],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "prompt-injection",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-prompt-injection",
      "level": "organisation",
      "harmType": "Security compromise through prompt injection",
      "mechanism": [
        "security"
      ],
      "description": "Instructions hidden in user input or retrieved content can override a model's instructions, reveal its system prompt or make it act for an attacker. The record here is early testers extracting a search chatbot's initial prompt [3].",
      "failureMode": "Untrusted content reaches the model's context with the same authority as the operator's instructions.",
      "controllingPattern": {
        "name": "Runtime Guardrail",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-runtime-guardrail"
      },
      "evidence": "Input and output guardrail verdicts with the injection attempts they blocked, and red-team results for the known injection classes.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "2.2",
          "subdomain": "AI system security vulnerabilities and attacks",
          "domain": "2 Privacy & security"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "473",
          "title": "Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection",
          "url": "https://incidentdatabase.ai/cite/473/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "supply-chain-compromise",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-supply-chain-compromise",
      "level": "organisation",
      "harmType": "Supply-chain compromise through AI-suggested components",
      "mechanism": [
        "security"
      ],
      "description": "Code assistants can suggest packages that do not exist, and attackers can register those names. NIST lists value chain and component integration among the generative-AI risks [12]; the record here is a hallucinated package name that was published and downloaded thousands of times [3].",
      "failureMode": "Dependencies suggested by a model are installed without a provenance check against an approved registry.",
      "controllingPattern": {
        "name": "AIBOM",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-aibom"
      },
      "evidence": "An AIBOM and dependency manifest generated at build, with the provenance check that rejected unknown packages.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "2.2",
          "subdomain": "AI system security vulnerabilities and attacks",
          "domain": "2 Privacy & security"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "731",
          "title": "Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers",
          "url": "https://incidentdatabase.ai/cite/731/"
        }
      ],
      "cases": [
        "https://aigovernanceengineer.com/cases/anthropic-third-party-eval-environment-incidents-2026"
      ],
      "sources": [
        1,
        3,
        12
      ]
    },
    {
      "id": "information-pollution",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-information-pollution",
      "level": "society",
      "harmType": "Pollution of the information ecosystem",
      "mechanism": [
        "scale",
        "misuse"
      ],
      "description": "Cheap synthetic text, images and audio make it harder to tell what is real, which erodes trust in authentic evidence as well as in fakes. NIST lists information integrity among its twelve generative-AI risks [12].",
      "failureMode": "Generated media leave the system with no provenance signal that a platform or a reader could check.",
      "controllingPattern": {
        "name": "Content provenance and labelling",
        "url": null
      },
      "evidence": "Provenance metadata and labels attached at generation, with the share of outputs that carried them.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "3.2",
          "subdomain": "Pollution of information ecosystem and loss of consensus reality",
          "domain": "3 Misinformation"
        },
        {
          "code": "4.1",
          "subdomain": "Disinformation, surveillance, and influence at scale",
          "domain": "4 Malicious actors & misuse"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "674",
          "title": "Manipulated Media via AI Disinformation and Deepfakes in 2024 Elections Erode Trust Across More Than 50 Countries",
          "url": "https://incidentdatabase.ai/cite/674/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3,
        12
      ]
    },
    {
      "id": "election-interference",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-election-interference",
      "level": "society",
      "harmType": "Election interference with synthetic voices and media",
      "mechanism": [
        "misuse"
      ],
      "description": "Synthetic audio of a candidate does most damage just before a vote, when there is no time to rebut it. The records include a fake presidential voice in robocalls before a US primary and deepfake recordings spread before Slovakia's 2023 election [3].",
      "failureMode": "Voice cloning is available without a consent check on whose voice is cloned, and the output carries no durable mark.",
      "controllingPattern": {
        "name": "Content provenance and labelling",
        "url": null
      },
      "evidence": "Consent records for every cloned voice, and watermark or provenance checks on generated audio.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "4.1",
          "subdomain": "Disinformation, surveillance, and influence at scale",
          "domain": "4 Malicious actors & misuse"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "628",
          "title": "Fake Biden Voice in Robocall Misleads New Hampshire Democratic Voters in 2024 Primary Election",
          "url": "https://incidentdatabase.ai/cite/628/"
        },
        {
          "db": "AIID",
          "id": "573",
          "title": "Deepfake Recordings Allegedly Influence Slovakian Election",
          "url": "https://incidentdatabase.ai/cite/573/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "job-displacement",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-job-displacement",
      "level": "society",
      "harmType": "Job displacement and task transformation",
      "mechanism": [
        "scale"
      ],
      "description": "Generative AI changes what many jobs consist of. The ILO estimates that one in four workers globally are in an occupation with some generative-AI exposure, and finds transformation of jobs more likely than outright replacement [10]. This harm is structural, so no single incident record stands for it.",
      "failureMode": "Deployment decisions count the productivity gain but not who loses tasks, income or bargaining power, and affected workers are not consulted.",
      "controllingPattern": {
        "name": "Workforce impact assessment",
        "url": null
      },
      "evidence": "An impact assessment listing the roles and tasks affected, the consultation held and the transition measures agreed.",
      "layerN": [
        1
      ],
      "mitTaxonomy": [
        {
          "code": "6.2",
          "subdomain": "Increased inequality and decline in employment quality",
          "domain": "6 Socioeconomic & environmental harms"
        }
      ],
      "exampleIncidents": [],
      "cases": [],
      "sources": [
        1,
        10
      ]
    },
    {
      "id": "hidden-labour",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-hidden-labour",
      "level": "society",
      "harmType": "Inequality in who bears the cost: hidden data labour",
      "mechanism": [
        "scale"
      ],
      "description": "The gains from AI flow to its builders and users while part of the cost falls on low-paid workers who label data, sometimes exposed to graphic material. The record here alleges that annotators in Kenya were exposed to graphic content while labelling for a model developer [3].",
      "failureMode": "Data-supply contracts are bought on price with no labour or welfare standard, and nobody audits them.",
      "controllingPattern": {
        "name": "Vendor / Model Due-Diligence Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-vendor--model-due-diligence-gate"
      },
      "evidence": "A supplier assessment covering annotator pay, exposure limits and support, renewed with the contract.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "6.2",
          "subdomain": "Increased inequality and decline in employment quality",
          "domain": "6 Socioeconomic & environmental harms"
        },
        {
          "code": "6.1",
          "subdomain": "Power centralization and unfair distribution of benefits",
          "domain": "6 Socioeconomic & environmental harms"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "450",
          "title": "Kenyan Data Annotators Allegedly Exposed to Graphic Content for OpenAI's AI",
          "url": "https://incidentdatabase.ai/cite/450/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "over-reliance",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-over-reliance",
      "level": "society",
      "harmType": "Over-reliance on generated output in institutions",
      "mechanism": [
        "overreliance"
      ],
      "description": "Professionals under time pressure accept fluent output without checking it. The records include fabricated case law filed in a US court and errors introduced into a child-protection report [3].",
      "failureMode": "Generated content enters a consequential record with no verification step and no disclosure that AI was used.",
      "controllingPattern": {
        "name": "Human-in-the-loop Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-human-in-the-loop-gate"
      },
      "evidence": "A sign-off record showing who verified each generated passage against its source before filing.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "5.1",
          "subdomain": "Overreliance and unsafe use",
          "domain": "5 Human-computer interaction"
        },
        {
          "code": "3.1",
          "subdomain": "False or misleading information",
          "domain": "3 Misinformation"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "541",
          "title": "ChatGPT Reportedly Produced False Court Case Law Presented by Legal Counsel in Court",
          "url": "https://incidentdatabase.ai/cite/541/"
        },
        {
          "db": "AIID",
          "id": "807",
          "title": "ChatGPT Reportedly Introduces Errors in Critical Child Protection Court Report",
          "url": "https://incidentdatabase.ai/cite/807/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "critical-services",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-critical-services",
      "level": "society",
      "harmType": "Disruption to critical infrastructure and emergency services",
      "mechanism": [
        "robustness",
        "scale"
      ],
      "description": "When AI systems run transport, utilities or emergency response, one failure repeats across a whole fleet at once. The records include driverless cars that stalled in traffic after losing their server connection, and one that blocked a fire truck on an emergency call [3].",
      "failureMode": "A shared dependency (connectivity, a model update) fails for every unit at once, and there is no degraded mode that clears the way.",
      "controllingPattern": {
        "name": "Kill Switch / Circuit Breaker",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-kill-switch--circuit-breaker"
      },
      "evidence": "Fleet-level stop and safe-state drills, with records of when the breaker fired and how long recovery took.",
      "layerN": [
        4
      ],
      "mitTaxonomy": [
        {
          "code": "7.3",
          "subdomain": "Lack of capability or robustness",
          "domain": "7 AI system safety, failures & limitations"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "253",
          "title": "Cruise's Self-Driving Cars Allegedly Lost Connection to Their Server, Causing Traffic Blockages in San Francisco",
          "url": "https://incidentdatabase.ai/cite/253/"
        },
        {
          "db": "AIID",
          "id": "389",
          "title": "Cruise Autonomous Car Blocked Fire Truck Responding to Emergency",
          "url": "https://incidentdatabase.ai/cite/389/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    },
    {
      "id": "energy-emissions",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-energy-emissions",
      "level": "environment",
      "harmType": "Energy demand and emissions of training and inference",
      "mechanism": [
        "scale"
      ],
      "description": "Training and serving models draws electricity, and so emissions, at data-centre scale. The IEA projects that data-centre electricity demand will more than double by 2030 to around 945 TWh, slightly more than Japan's consumption today [11]. NIST lists environmental impacts among the generative-AI risks [12].",
      "failureMode": "Model and deployment choices are made without measuring energy use, so the cheapest adequate option is never compared.",
      "controllingPattern": {
        "name": "Energy and emissions telemetry",
        "url": null
      },
      "evidence": "Per-model energy and emissions figures, recorded for training and per unit of inference, published in the model card.",
      "layerN": [
        5
      ],
      "mitTaxonomy": [
        {
          "code": "6.6",
          "subdomain": "Environmental harm",
          "domain": "6 Socioeconomic & environmental harms"
        }
      ],
      "exampleIncidents": [],
      "cases": [],
      "sources": [
        1,
        11,
        12
      ]
    },
    {
      "id": "local-environmental-burden",
      "url": "https://aigovernanceengineer.com/resources/harms#harm-local-environmental-burden",
      "level": "environment",
      "harmType": "Local pollution and resource burden near AI infrastructure",
      "mechanism": [
        "scale"
      ],
      "description": "The power generation and cooling that AI data centres need can burden the communities around them. The record here alleges that a supercomputer site in Memphis ran unpermitted gas turbines [3].",
      "failureMode": "Capacity is added faster than permitting and community consultation, and buyers of compute never ask where or how it is powered.",
      "controllingPattern": {
        "name": "Vendor / Model Due-Diligence Gate",
        "url": "https://aigovernanceengineer.com/bok/patterns#pattern-vendor--model-due-diligence-gate"
      },
      "evidence": "The provider's answers on energy source, permits and location, kept with the procurement decision.",
      "layerN": [
        2
      ],
      "mitTaxonomy": [
        {
          "code": "6.6",
          "subdomain": "Environmental harm",
          "domain": "6 Socioeconomic & environmental harms"
        }
      ],
      "exampleIncidents": [
        {
          "db": "AIID",
          "id": "1144",
          "title": "xAI Allegedly Operates Unpermitted Methane Turbines in Memphis to Power Supercomputer Colossus to Train Grok",
          "url": "https://incidentdatabase.ai/cite/1144/"
        }
      ],
      "cases": [],
      "sources": [
        1,
        3
      ]
    }
  ],
  "sources": [
    {
      "n": 1,
      "text": "The AI Risk Repository: a meta-review, database, and taxonomy of risks from artificial intelligence (Domain Taxonomy of 7 domains and 24 subdomains; published under CC BY 4.0). Slattery, P., Saeri, A. K., Grundy, E. A. C., et al., Patterns (Cell Press). 2026.",
      "url": "https://doi.org/10.1016/j.patter.2026.101517",
      "verified": "primary"
    },
    {
      "n": 2,
      "text": "MIT AI Risk Repository (the living database of AI risks classified by the Domain Taxonomy; CC BY 4.0). MIT AI Risk Initiative. 2026.",
      "url": "https://airisk.mit.edu/",
      "verified": "primary"
    },
    {
      "n": 3,
      "text": "AI Incident Database (incident records cited as AIID <number>). Responsible AI Collaborative. 2026.",
      "url": "https://incidentdatabase.ai/",
      "verified": "primary"
    },
    {
      "n": 4,
      "text": "AIAAIC Repository (AI, algorithmic and automation incidents and controversies). AIAAIC. 2026.",
      "url": "https://www.aiaaic.org/aiaaic-repository",
      "verified": "primary"
    },
    {
      "n": 5,
      "text": "AI Incidents and Hazards Monitor (AIM) (news-derived incident records). OECD.AI. 2026.",
      "url": "https://oecd.ai/en/incidents",
      "verified": "primary"
    },
    {
      "n": 6,
      "text": "Dissecting racial bias in an algorithm used to manage the health of populations (Science 366(6464):447-453; remedying the disparity would raise Black patients receiving additional help from 17.7% to 46.5%). Obermeyer, Z., Powers, B., Vogeli, C., Mullainathan, S.. 2019-10-25.",
      "url": "https://doi.org/10.1126/science.aax2342",
      "verified": "primary"
    },
    {
      "n": 7,
      "text": "Racial disparities in automated speech recognition (PNAS 117(14):7684-7689; five commercial systems, average word error rate 0.35 for Black speakers and 0.19 for white speakers). Koenecke, A., Nam, A., Lake, E., et al.. 2020-04-07.",
      "url": "https://doi.org/10.1073/pnas.1915768117",
      "verified": "primary"
    },
    {
      "n": 8,
      "text": "Tax Administration fined for discriminatory and unlawful data processing (EUR 2.75 million fine; nationality used as an indicator in a system that designated childcare-benefit applications as risky). Autoriteit Persoonsgegevens (Dutch Data Protection Authority). 2021-12-07.",
      "url": "https://www.autoriteitpersoonsgegevens.nl/en/current/tax-administration-fined-for-discriminatory-and-unlawful-data-processing",
      "verified": "primary"
    },
    {
      "n": 9,
      "text": "Dutch DPA imposes a fine on Clearview because of illegal data collection for facial recognition (EUR 30.5 million fine plus orders subject to penalties). Autoriteit Persoonsgegevens (Dutch Data Protection Authority). 2024-09-03.",
      "url": "https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition",
      "verified": "primary"
    },
    {
      "n": 10,
      "text": "Generative AI and jobs: a refined global index of occupational exposure (ILO Working Paper 140; one in four workers globally in an occupation with some GenAI exposure; transformation of jobs the most likely impact). International Labour Organization. 2025-05-20.",
      "url": "https://www.ilo.org/publications/generative-ai-and-jobs-refined-global-index-occupational-exposure",
      "verified": "primary"
    },
    {
      "n": 11,
      "text": "AI is set to drive surging electricity demand from data centres while offering the potential to transform how the energy sector works (Energy and AI report; data-centre electricity demand to more than double by 2030 to around 945 TWh). International Energy Agency. 2025-04-10.",
      "url": "https://www.iea.org/news/ai-is-set-to-drive-surging-electricity-demand-from-data-centres-while-offering-the-potential-to-transform-how-the-energy-sector-works",
      "verified": "primary"
    },
    {
      "n": 12,
      "text": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1; twelve risks including confabulation, information integrity, environmental impacts and value chain and component integration). NIST. 2024-07-26.",
      "url": "https://doi.org/10.6028/NIST.AI.600-1",
      "verified": "primary"
    },
    {
      "n": 13,
      "text": "Awarding GCSE, AS, A level, advanced extension awards and extended project qualifications in summer 2020: interim report (the Direct Centre Performance model predicted each centre grade distribution from its history, then used teacher rank orders to assign grades). Ofqual. 2020-08-13.",
      "url": "https://www.gov.uk/government/publications/awarding-gcse-as-a-levels-in-summer-2020-interim-report",
      "verified": "primary"
    },
    {
      "n": 14,
      "text": "Zillow Group Reports Third-Quarter 2021 Financial Results; Shares Plan to Wind Down Zillow Offers Operations (Form 8-K, Exhibit 99.1; inventory write-down of approximately USD 304 million; workforce reduction of approximately 25%). Zillow Group, Inc. (SEC EDGAR). 2021-11-02.",
      "url": "https://www.sec.gov/Archives/edgar/data/1617640/000161764021000085/q32021991.htm",
      "verified": "primary"
    }
  ]
}
