Sources
Where to go when you need the specialist sites.
MIT, the incident database, WHO, and others are useful. They are also hard to start with. This page says what each one is, who it is for, and when to open it.
We do not replace those sites. We send you to them with a question in hand.
Borrowed from MIT · Causal taxonomy
Three questions that turn a worry into a sentence.
MIT asks of every risk: who set it in motion, whether it was on purpose, and when it arose. Tap a column. The example is from care, home, or community — not from a lab.
A person · By accident · Once people were using it
In the clinic
A scribe no one has time to check
An ambient note-taker is switched on to save minutes. The clinician is still responsible for the record. In a full clinic, review thins out. A fabricated symptom enters a chart.
Borrowed from MIT · Domain taxonomy
Seven rooms. Care is not one of them.
MIT sorts more than 1,700 risks into seven domains. Health is scattered through them: a medical emergency under overreliance, a biased score under discrimination, a brittle model under safety. We gather care as its own topic so a clinic and a family can sit down.
Bar length is how many of our 1000 named concerns sit on that MIT shelf. 237 sit mainly in governance, rights, or care — rooms MIT folds elsewhere.
MIT 5
Human–computer interaction
The relationship with the tool goes wrong: over-trust, attachment, or a slow loss of our own judgement.
In care. A companion for a teenager. A scribe a doctor stops checking. A wellness app that becomes the only listener.
- 5.1 Overreliance and unsafe use — Trusting the system in a moment that still needs a person — including a medical emergency.
- 5.2 Loss of human agency and autonomy — Key decisions migrate to the system, and people feel smaller.
Health, safety & care (41 concerns). Not a MIT domain. We keep it as one so the people who live with it do not have to hunt. Open it on the map.
Start here if you want the specialist map
MIT built the most complete public list. Use it when you are ready for density.
Specialist site
MIT AI Risk Initiative
MIT FutureTech
A living programme that gathers risks, real incidents, laws, and expert judgement into one place. It is the best public map we have. It is also written for people who already speak this language.
Who it is for. Researchers, policymakers, journalists, and risk owners who need the full list.
When to go. You want the most complete public map of AI risks, and you are willing to sit with density.
How we use it. We score and organise our list of concerns against it. This site is the same territory, in a voice a clinic, a parent, or a community group can use.
Database of named risks
AI Risk Repository
MIT AI Risk Initiative
More than 1,700 risks drawn from dozens of existing frameworks. Two maps sit on top: a domain taxonomy (what kind of harm) and a causal taxonomy (who, on purpose, and when).
Who it is for. Anyone who needs a citable list of what can go wrong, classified two ways.
When to go. You are writing a policy, a board paper, or a curriculum and need the source taxonomy.
How we use it. Our 23 domains are a finer grain of the same land, with a health-and-care shelf MIT does not keep as a room of its own.
How / when / why
Causal taxonomy of AI risks
MIT AI Risk Initiative
Three questions of every risk: which entity (a person, the system, or unclear); whether it was intentional; and whether it arose before deployment or after people were already using it.
Who it is for. Groups who keep talking past each other because they mean different failures.
When to go. A conversation is stuck on 'AI is dangerous' and needs a sentence instead of a mood.
How we use it. The decoder on this site walks those three questions with examples from clinic, home, and community.
Cross-dataset explorer
AI Risk Navigator
MIT AI Risk Initiative
An interactive tool that sits the Initiative's datasets on shared taxonomies, so you can walk from a risk to an incident to a rule without changing maps.
Who it is for. People ready to move between risks, incidents, and governance in one sitting.
When to go. You have a named concern and want to see whether the law, the incident record, and the taxonomy agree.
How we use it. The next depth after this site. Use our questions first; open the Navigator when you need the specialist join.
Start here if you need receipts
What has already happened, in public, with a place to file what you have seen.
What has already happened
AI Incident Tracker
MIT × Responsible AI Collaborative
Thousands of reported incidents from the AI Incident Database, classified with MIT's taxonomies and a harm-severity scale. Graphs of what is already in the world, by year, domain, and cause.
Who it is for. People who need receipts, not scenarios.
When to go. Someone says 'that's hypothetical' and you need the public record.
How we use it. We point here when a gathering needs evidence that a concern is not a mood. We do not copy the database; we send you to it.
The incident record
AI Incident Database
Responsible AI Collaborative
A living collection of real-world AI harms, submitted and edited in public. MIT's tracker reads this record. The database is the source; the tracker is a way of seeing it.
Who it is for. Researchers, reporters, and anyone who wants to file or read a report.
When to go. You have seen a harm and want it on the public ledger, or you want to search what has already been filed.
How we use it. When a community asks 'has this happened?', this is the first door. You can search, and you can submit.
Start here if you are writing a rule or buying a tool
Laws, frameworks, and a map of which risks they actually cover.
How to manage, not only name
NIST AI Risk Management Framework
U.S. National Institute of Standards and Technology
A voluntary framework for putting AI risk into an organisation's ordinary risk practice. Widely referenced; not a law.
Who it is for. Organisations that have to show their work: health systems, vendors, public agencies.
When to go. You are past 'what can go wrong' and need a cycle: govern, map, measure, manage.
How we use it. The modeler on this site is a preoperative cousin of 'map'. NIST is what an institution uses once it owns the list.
A law with high-risk lists
EU AI Act
European Union
The first broad AI law of its kind. It ranks uses, not vibes. Health, education, and some public services sit in the high-risk band.
Who it is for. Anyone selling, buying, or living under systems that will be classed as high-risk.
When to go. You need to know which uses of AI a major jurisdiction treats as high-risk — including several in health.
How we use it. A useful external spine for 'is this serious?'. It is not a moral authority; it is a legal one, with a geography.
Laws and policies against risks
AI Governance Map
MIT × Georgetown CSET
More than a thousand governance documents, mapped to the same risk shelves. Filter by domain, sector, lifecycle, and who in the value chain is named.
Who it is for. People writing or contesting a rule.
When to go. You need to see which risks a law, standard, or policy actually covers — and which it misses.
How we use it. A clinic or a school board can see whether 'we comply' and 'we have thought about this harm' are the same sentence. Often they are not.
Shared values, internationally
OECD AI Principles
OECD
Inclusive growth, human-centred values, transparency, robustness, accountability. Adopted by dozens of countries. A floor, not a plan.
Who it is for. Governments and firms that have already signed up, and groups holding them to it.
When to go. You need a short, widely-endorsed list of what 'responsible' was supposed to mean.
How we use it. A common vocabulary when a room includes people from more than one country or sector.
Start here if the setting is care
Health-specific guidance, and a humanitarian example of writing from principle.
Health-specific guidance
Ethics and governance of AI for health — large multimodal models
World Health Organization
WHO's 2024 guidance on large multimodal models in health: consent, evidence, equity, and the duties that remain with clinicians and states.
Who it is for. Ministries, health workers, and anyone bringing a generative model into care.
When to go. The question is not 'is AI risky?' but 'what does care require of this tool?'
How we use it. The companion text for our Path: clinic and care. Read it beside a named concern, not instead of one.
Humanitarian practice
ICRC policy on artificial intelligence
International Committee of the Red Cross
A humanitarian organisation's own rule for how it will, and will not, use AI. Useful as an exemplar of writing from principle rather than from product.
Who it is for. Anyone whose work touches conflict, civilian protection, or the limits of automation in life-and-death settings.
When to go. The conversation has reached weapons, targeting, or humanitarian data — or you want to see a principled institution write a policy.
How we use it. Linked from concerns in conflict, weapons, and civilian harm. Also in the practices library as a model of how to write.
If you are short on time
- 01
- 02
You need to know if this has already happened.
Search the AI Incident Database. Then look at MIT’s Incident Tracker for the same record.
Open the incident record - 03
You are buying, regulating, or writing a rule.
NIST for how to manage risk. The EU AI Act for a high-risk list. MIT’s Governance Map to see what a given law covers.
Go - 04
The setting is a clinic, a school health office, or a home.
WHO guidance next to our Health page. Then the clinic and care talk.
Go