Resource · 47-page PDF + XLSX annexe · FR/EN
1,612 documented AI risks. Here are the ones that concern you.
A systematic review run from MIT extracted 1,612 AI risks from 65 reference documents. It is the most complete census of the subject — and it is a research artefact: it describes risks, it does not say what to do about them. This document adds the missing half: the concrete manifestations in a company, the observable warning signs, the expected controls and the regulatory frameworks facing them.
What's inside
Why a reference
The three figures that should change your approach — including that 54% of risks appear after deployment.
Where this data comes from
The systematic review method, the two taxonomies, and six limitations of the corpus stated plainly.
Discrimination and toxic content
204 risks: assisted candidate screening, content in customer channels, unequal performance across languages.
Privacy and security
173 risks: leakage through ordinary use, inference, poorly segregated retrieval, indirect injection.
Misinformation
64 risks: the invented reference, the figure with no source, the confident and wrong customer answer.
Malicious actors and misuse
235 risks: CEO fraud on a video call, supplier impersonation, counterfeiting of your identity.
Human-computer interaction
89 risks: overreliance, validation gone formal, competence erosion.
Socioeconomic and environmental
274 risks: supplier dependency, employment, ownership of deliverables, governance, footprint.
System safety and failures
370 risks — including those that belong to developers, separated explicitly from what concerns you.
The criticality matrix
A four-level scale and a matrix by organisation profile, cutting 24 sub-domains down to a short list.
What regulation makes of this
EU AI Act, nFADP, ISO/IEC 42001, FINMA note — and the four deliverables that suffice today.
The register: how to run it
The eight-column template, the cadence, and how to verify every figure at source.
Written for the people who will be held accountable.
Who this document is for
For Swiss organisations with 200–2,000 employees deploying AI and accountable for it.
Executives & boards
You must be able to say what can go wrong, who answers for it, and what you decided to rule out — in writing.
Risk, compliance, legal
You want a defensible base rather than an in-house list: 65 reference documents, a published method, every figure verifiable.
IT & security leads
The warning signs and expected controls are written out plainly, sub-domain by sub-domain — directly reusable.
Source, licence and what we added
The corpus comes from the MIT AI Risk Repository (v3, 26 March 2025), distributed under the Creative Commons Attribution 4.0 licence. We restructured, translated and enriched it; the full list of modifications is in chapter 12. MIT has not reviewed, validated or endorsed this adaptation: the manifestations, warning signs, controls, criticality levels and regulatory mapping are Numezis’s alone. This document is not legal advice.
Get the document
Receive the complete reference.
Fill in the form — the PDF and the XLSX annexe are available right after validation.
Direct questions, direct answers
Is it really free?
Yes. The PDF and the XLSX annexe are complete — no hidden “premium” version behind a sales call.
What exactly is the source?
The MIT AI Risk Repository, version 3 of 26 March 2025, distributed under CC BY 4.0 — a systematic review of 65 reference documents from which 1,612 risks were extracted and coded. We cite the source, indicate our modifications and keep the original file. MIT has neither reviewed nor endorsed our adaptation.
What did you add to the MIT corpus?
The rewriting of the 24 definitions into executive language, concrete manifestations in a company, observable warning signs, expected controls, the four-level criticality scale, the matrix by organisation profile, the EU AI Act / nFADP / ISO 42001 mapping and the register template. These contributions are presented as ours, never as MIT's.
Do all 24 sub-domains apply to me?
No, and the document says so. Most organisations keep 8 to 12 after filtering. Chapter 10 provides the method for ruling out the others with a written reason — which is worth more than a fully ticked list.
What does the XLSX annexe contain?
The filterable dataset of all 1,612 risks with their original descriptions and source references, both taxonomies, the 65 source documents and the blank register template. Original descriptions are kept in English, verbatim.
Is this legal advice?
No. Chapter 11 situates the sub-domains against the EU AI Act, the nFADP and ISO/IEC 42001 so you know where to look. The state of law is that of August 2026 and must be verified for your own situation.