A map of AI harms
Lesson 2 of 6 in Why AI Needs Governance: A Taxonomy of Harms and Risks.
Risk assessment starts with a checklist of what can go wrong — and for AI, the field has converged on a recognisable set of harm families. The names vary between catalogs (the NIST GenAI Profile, the MIT AI Risk Repository, the OECD incident monitor all slice slightly differently), but the territory is the same. This module uses seven categories. Learn them as a scanning instrument: for any AI system, walk the list and ask which of these could this system produce?
| Harm family | What it is | Signature real case | Who bears it |
|---|---|---|---|
Bias & discrimination | Systematically worse outcomes or representation for particular groups — in loans, hiring, policing, benefits, healthcare | COMPAS recidivism scores; the Dutch toeslagenaffaire; Gender Shades; Amazon’s scrapped hiring tool; the Obermeyer healthcare study | Individuals and groups — usually those already disadvantaged |
Privacy | Personal data taken, inferred, memorised, or exposed without meaningful consent — including biometric surveillance | Clearview AI scraping 30+ billion face images; LLMs regurgitating training data; chatbot conversation leaks | Individuals — often everyone whose data was ever public |
Safety | Physical or psychological injury from system failure or unfit-for-purpose outputs in high-stakes settings | The 2018 Uber ATG pedestrian fatality in Tempe; the NEDA Tessa chatbot giving dieting advice to eating-disorder callers; harmful chatbot interactions with minors | Users, patients, bystanders — anyone in the system’s physical or advisory reach |
Security | The system attacked (prompt injection, data poisoning, model theft, adversarial inputs) or weaponised (deepfake fraud, cyber and CBRN capability uplift) | The 2024 Arup deepfake video-call fraud (≈US$25M); voice-cloning scams; jailbreaks defeating safety training | Organisations, fraud victims, and — for dual-use uplift — potentially everyone |
Misinformation & information integrity | Synthetic media and generated falsehoods degrading what anyone can trust — deepfakes, NCII, election manipulation, AI slop, the liar’s dividend | The 2023 Slovak election audio deepfake released during the pre-vote media blackout; mass NCII of public and private figures | Societal — the information ecosystem itself, plus targeted individuals |
Manipulation, autonomy & economic | Exploiting human psychology (dark patterns, emotional dependence on companions, subliminal techniques) and reshaping livelihoods (algorithmic management, gig scoring, creator displacement, annotation-work conditions) | AI-companion dependence cases; gig-work deactivation by opaque scoring; copyright suits over training data; $2/hr trauma labeling exposed by TIME (2023) | Individuals’ agency and wallets; whole labour and creative markets |
Systemic, environmental & accountability | Risks to whole systems: compute/market concentration, foundation-model monoculture, model collapse, loss-of-control debates, energy and water footprints — and the accountability gap when no one answers for any of it | A handful of firms controlling frontier compute; data-centre water disputes; the “many hands” problem in every incident post-mortem | Societies, markets, the planet, and future affected people |
Two distinctions sharpen the map. First, bias harms split into allocative harm — a resource or opportunity withheld (the loan, the job, the parole) — and representational harm — a group demeaned or erased in how systems see and depict the world (search results, image generators, stereotyped outputs). Both are real; only one shows up in an approval-rate spreadsheet.
Second, real incidents rarely stay in one box. The toeslagenaffaire was a bias harm and a privacy harm (nationality data misused) and an accountability harm (families could not contest scores for years). Treat the categories as lenses, not bins — a competent risk assessment names every lens that applies.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.