Mapping the AI Risk Landscape: A Practical Taxonomy
Five domains every organization must understand before diving into assessment
Every organization deploying artificial intelligence eventually discovers an uncomfortable truth. They are managing risks they cannot name.
The symptoms are familiar. Risk discussions meander without resolution because participants are using different mental models. Incident reports pile up, but patterns remain invisible because there is no consistent framework for categorization. Governance committees struggle to prioritize because everything seems equally urgent or equally nebulous.
The root cause is straightforward. Most organizations lack a coherent taxonomy for AI risk. They have policies, perhaps even risk registers, but no systematic framework for understanding where AI risks originate, how they manifest, and why they demand different mitigation strategies than traditional technology risks.
This gap matters more than it might appear. According to the Stanford AI Index Report, documented AI safety incidents surged from 149 in 2023 to 233 in 2024, a 56% increase in a single year. The AI Incident Database now catalogs thousands of cases in which AI systems caused real harm, including financial losses, legal consequences, safety risks, and, in tragic cases, loss of life. These are not theoretical concerns. They are failure patterns that a well-designed risk taxonomy can help organizations anticipate and prevent.
What Is a Risk Taxonomy—and What It Is Not
The terminology in risk management can be genuinely confusing. So, let’s start with a few definitions.
A risk taxonomy is a comprehensive, hierarchical framework that categorizes and defines the types of risks an organization may face. Think of it as a classification system, like a shared language that enables consistent identification, discussion, and management of risks across the enterprise. It answers the question: What kinds of risks exist in our domain?
A risk register is a document that records specific, identified risks along with additional information about each one, such as likelihood, severity, owner, mitigation measures and status. The register is populated using the taxonomy's categories. It answers the question: What specific risks have we identified, and what are we doing about them?
A risk profile is a point-in-time assessment of an organization’s overall risk posture. It typically aggregates information from the risk register to provide senior leadership and the board with a summary view. It answers the question: What is our current risk exposure?
The relationship between these concepts is hierarchical. The taxonomy provides the structure. The register applies that structure to specific risks. The profile synthesizes the register into actionable intelligence for decision-makers. Without a taxonomy, you cannot populate a register coherently. Without a register, your profile lacks substance. Without a profile, leadership lacks visibility.
The challenge with AI is that traditional risk taxonomies, which include operational, financial, strategic and compliance, do not adequately capture the distinctive ways AI systems fail. AI risks cut across these categories and introduce failure modes that existing frameworks were never designed to address. A credit model that exhibits bias is simultaneously an operational risk (the model is performing poorly), a compliance risk (regulatory violation), a reputational risk (customer trust erosion), and potentially a legal risk (discrimination claims). Mapping a risk to a single traditional category obscures more than it reveals.
This is why AI-specific risk taxonomies have proliferated. Researchers have cataloged over 700 distinct AI risks across 43 different taxonomies. The MIT AI Risk Repository organizes risks into seven domains with 23 subdomains. The AIR 2024 taxonomy, derived from government and corporate policies worldwide, identifies 314 unique risk categories organized into four tiers. NIST’s AI Risk Management Framework, ISO 42001, and the EU AI Act each bring their own categorical approaches.
The existence of multiple taxonomies is not a problem to be solved. It reflects the genuine complexity of AI risk and the diverse perspectives of various stakeholders. The challenge for enterprise leaders is selecting or designing a taxonomy that is comprehensive enough to capture relevant risks, simple enough to be usable, and aligned enough with their organizational context to drive action.
The Benefits of a Standardized AI Risk Taxonomy
Before introducing a specific framework, it is worth understanding why investing in a taxonomy pays dividends. The benefits extend beyond mere organization.
Shared Language and Communication. When everyone uses the same terms to describe the same risks, conversations become productive rather than circular. A well-designed taxonomy eliminates scenarios in which the data science team discusses “model drift,” the compliance team raises “accuracy degradation,” and the product team flags “prediction quality issues” when all groups are referring to the same phenomenon.
Comprehensive Risk Identification. A taxonomy serves as a checklist that prompts risk identification across all relevant domains. Without it, organizations focus on familiar risks while overlooking less obvious ones.
Consistent Assessment and Prioritization. When risks are categorized consistently, organizations can compare them meaningfully and allocate resources appropriately.
Aggregation and Pattern Recognition. A taxonomy enables aggregation of risks across the organization. You can answer questions like: How many high-severity data risks do we have? Which business units have the most model risks?
Regulatory Alignment. Emerging AI regulations require organizations to systematically identify, assess, and manage AI risks. A well-designed taxonomy provides the foundation for demonstrating compliance.
Knowledge Transfer and Training. A documented taxonomy becomes a training resource for employees at all levels, enabling faster onboarding to governance activities.
The Five Domains of AI Risk: A Practical Framework
Based on analysis of leading taxonomies, real-world incident patterns, and lessons from early adopters, AI risks can be organized into five interconnected domains. Each domain represents a distinct source of risk, requires different expertise to assess and manage, and maps to recognizable failure modes in production AI systems.
Domain 1: Data Risks
Data is the foundation of AI systems, and data risks are often where problems begin. This domain encompasses risks arising from how data is collected, prepared, stored, and used throughout the AI lifecycle.
Representative data risks involve:
Data quality degradation. Training data may contain errors, inconsistencies, missing values, or outdated information, which can undermine model performance. Production data may differ from training data distributions, leading to what practitioners call “data drift” and causing silent performance degradation. Research indicates that 91% of machine learning models suffer from some form of drift, and 67% of organizations using AI at scale have experienced critical issues linked to statistical misalignment that went unnoticed for more than a month.
Data provenance and lineage failures. Organizations may lack visibility into where their data originated, how it was transformed, or whether appropriate consents were obtained. This creates both compliance risks, particularly under privacy regulations, and operational risks, including the inability to diagnose problems when they occur.
Data poisoning. Adversaries may deliberately corrupt training data to manipulate model behavior. NIST’s guidance identifies data poisoning as a critical vulnerability requiring proactive mitigation. The effects may remain dormant until triggered by specific inputs, making detection challenging.
Bias in training data. Historical data often encodes societal biases that, when used for training, cause models to perpetuate or amplify discrimination. Bias can be subtle and may only become apparent when models are applied to populations underrepresented in training data.
Privacy violations. AI systems may memorize and later expose sensitive information from training data. They may also infer sensitive attributes from seemingly innocuous inputs, creating privacy risks that traditional data governance frameworks do not anticipate.
Real-world example
A 2024 incident involved a health insurance provider whose AI allegedly denied Medicare coverage at alarming rates, reportedly overriding physician judgments with inadequate oversight. Investigation revealed the system had been trained on data that embedded patterns of historical coverage denials, effectively automating discrimination against specific patient populations.
Domain 2: Model Risks
Model risks arise from AI models themselves, including their architecture, training, behavior, and inherent limitations. These risks are often technical in nature but have profound business consequences.
Representative risks include:
Hallucination and confabulation. Large language models can generate outputs that are fluent, confident and completely fabricated. In November 2024, an attorney submitted a legal brief citing nonexistent cases generated by ChatGPT. The cases sounded plausible but simply did not exist. Given similar incidents, professional liability from AI-generated hallucinations is a genuine concern.
Model degradation and drift. Even well-performing models lose accuracy over time as the world changes. A credit risk model deployed in January might correctly identify 95% of defaults, but by September, the same model may achieve only 87% accuracy. Not because anything changed in the code, but because the relationship between features and outcomes shifted. Concept drift, where the fundamental patterns change, is particularly insidious because the model may continue running without obvious errors while producing increasingly unreliable predictions.
Lack of explainability. Many AI models, particularly deep learning systems, operate as “black boxes” that cannot explain their reasoning. When these models make consequential decisions, such as who gets hired, who receives credit, or what medical treatment is recommended, the inability to explain why creates accountability, regulatory, and ethical challenges. Research indicates that 83% of companies exploring or deploying AI consider explainability essential to their business.
Adversarial vulnerability. AI models can be manipulated through carefully crafted inputs designed to cause misclassification or erroneous outputs. A facial recognition system might be fooled by subtle modifications to an image that are imperceptible to humans. A self-driving car might be confused by adversarial stickers on stop signs. These vulnerabilities differ fundamentally from traditional software bugs.
Emergent behaviors. Complex AI systems can exhibit behaviors that their designers did not anticipate. As models become more capable, the gap between intended behavior and actual behavior may widen in unexpected ways.
Real-world example
Google’s Gemini AI image generator produced historically inaccurate images in early 2024. For example, prompts to create the Founding Fathers generated images of diverse individuals who could not have existed in that historical context. The model had been tuned to promote diversity, but at the expense of historical accuracy, creating a PR crisis that demonstrated how well-intentioned model modifications can yield unexpected outcomes.
Domain 3: System Risks
System risks encompass the broader technical infrastructure in which AI models operate. These are the integrations, interfaces, dependencies, and operational environment that determine how AI capabilities are delivered to users and how they interact with other systems.
Representative risks include:
Integration failures. AI models rarely operate in isolation. They consume data from upstream systems, produce outputs for downstream processes, and interact with human users and other AI systems. Each integration point represents a potential failure mode. When McDonald’s deployed AI-powered drive-thru ordering in partnership with IBM, the system exhibited spectacular failures, including being unable to stop adding items, with one infamous order reaching 260 McNuggets, leading to the program's termination in mid-2024.
Cascading failures. AI systems integrated into critical infrastructure can trigger cascading effects when they fail. A 2024 incident in India involved a navigation app directing a vehicle over a damaged bridge, resulting in three deaths when the car plunged into a gorge. The app’s reliance on outdated map data that did not reflect recent infrastructure changes led to a system-level failure with fatal consequences.
Security vulnerabilities. AI systems introduce novel attack surfaces, including prompt injection, model extraction, and supply chain attacks on model components. User conversations with LLMs can be publicly accessible to search engines, and AI agents have exposed sensitive medical data. These security risks require AI-specific threat modeling beyond traditional cybersecurity approaches.
Scalability and performance issues. AI systems under production load may behave differently from how they do during testing. Resource constraints, latency issues and throughput limitations can cause failures that were not apparent in development environments.
Monitoring gaps. Without adequate observability infrastructure, organizations may not detect system failures until they have caused significant harm. The silent nature of many AI failures, such as systems continuing to run while producing degraded outputs, makes monitoring particularly critical.
Real-world example
Air Canada’s AI chatbot confidently told a customer about a nonexistent “bereavement fare” discount policy in 2024. When the customer booked based on this information, the airline initially refused to honor it. A tribunal ruled against Air Canada, finding that companies are responsible for their AI agents’ statements. The incident demonstrated how system-level integration, like connecting an LLM to customer-facing interfaces without adequate guardrails, can create legal and financial liability.
Domain 4: User Risks
User risks arise from how humans interact with AI systems, both as operators and as those affected by AI decisions. This domain bridges technical and human factors, recognizing that AI failures often occur at the interface between systems and people.
Representative risks include:
Over-reliance and automation bias. Users may trust AI outputs without appropriate skepticism, particularly when systems have historically performed well. The attorneys who submitted fabricated legal citations trusted ChatGPT’s outputs because the technology seemed authoritative. This pattern of humans deferring to AI judgment even when they should not appears across domains from medical diagnosis to financial analysis.
Misuse and inappropriate application. AI systems designed for one purpose may be applied to contexts for which they were never intended or evaluated. A model trained on one population may be deployed to make decisions that affect other populations. A system designed for advisory use may be treated as authoritative.
Accessibility and equity issues. AI systems may not work equally well for all users. Speech recognition may struggle with accents and dialects. Image recognition may perform poorly on underrepresented demographic groups. When these disparities translate into differential service quality or decision outcomes, they raise equity concerns and potentially legal issues.
Manipulation and deception. AI systems, particularly generative AI, can be used to deceive or manipulate users. Deepfake videos have been used in romance scams, costing victims millions. For instance, two Canadians lost a combined $2.3 million to deepfake cryptocurrency schemes in 2024 alone. The AI Incident Database tracks numerous cases of AI-generated misinformation affecting elections, markets, and individual decision-making.
Psychological harm. AI chatbots have allegedly played a role in teen self-harm in multiple documented cases from 2023 through 2025. When AI systems engage users on emotional topics without appropriate safeguards, the potential for psychological harm is significant and distinct from traditional technology risks.
Real-world example
In multiple incidents across 2023-2025, AI chatbots allegedly contributed to teen self-harm situations. These cases represent a category of harm that was not adequately anticipated when the systems were designed. The risk is that AI capable of sophisticated conversation can form quasi-relationships with vulnerable users in ways that amplify rather than mitigate mental health challenges.
Domain 5: Organizational Risks
Organizational risks encompass the governance, cultural, strategic, and compliance factors that determine whether an organization can deploy AI responsibly at scale. These risks are often the most consequential because they shape how all other risks are identified and managed.
Representative risks include:
Governance gaps. Many organizations lack clear accountability for AI outcomes. When AI decisions cause harm, there may be no defined owner responsible for the response. Surveys reveal that while 80% of organizations have established AI ethics guidelines, only 25% have operationalized them. This gap between policy and practice creates significant organizational risk.
Regulatory compliance failures. The regulatory landscape for AI is evolving rapidly. The EU AI Act, NIST AI RMF, ISO 42001, and sector-specific requirements impose obligations that many organizations are not yet prepared to meet. Non-compliance can result in significant fines, operational restrictions, and reputational damage.
Talent and capability gaps. Responsible AI deployment requires expertise that many organizations lack. Data scientists need to understand fairness, engineers must build monitoring systems, risk professionals must understand AI-specific failure modes, and legal counsel must be aware of AI regulations. Capability gaps translate directly into risk exposure.
Strategic misalignment. AI investments may not align with organizational values or strategic priorities. Systems may be deployed in ways that conflict with stated commitments, creating reputational and stakeholder trust risks. The gap between AI marketing claims and AI reality creates particular exposure.
Third-party and supply chain risks. Organizations increasingly rely on AI components, models, and services from external providers. These dependencies introduce risks that may not be visible in traditional vendor management processes, including risks from model updates, data practices, and the providers’ own governance maturity.
Real-world example
Through mid-2024, Tesla's Autopilot system had been implicated in at least 13 fatal crashes according to NHTSA data. Investigations repeatedly surfaced a governance gap with ambiguity about whether the system was a driver-assistance feature requiring constant attention or something more autonomous. Marketing materials, user interface design, and driver training sent conflicting signals. The organizational failure wasn't the technology itself. It was the absence of clear accountability for how the product was positioned, sold, and monitored once drivers began using it in ways the company publicly discouraged but quietly tolerated.
Key Considerations for Developing or Selecting a Taxonomy
For organizations developing or selecting an AI risk taxonomy, several factors warrant careful consideration.
Alignment with organizational context. The taxonomy should reflect your organization’s specific AI applications, risk tolerance, and regulatory environment. The categories should resonate with how your organization actually develops and deploys AI.
Comprehensiveness without complexity. A good taxonomy covers all relevant risk types without being so granular as to be unusable. The AIR 2024 taxonomy identifies 314 distinct risk types, which may be appropriate for academic research but overwhelming for operational governance. Aim for five to seven top-level categories with subcategories added as needed.
Compatibility with existing frameworks. Your AI risk taxonomy should integrate with existing enterprise risk management rather than creating a parallel silo. Consider how AI risk categories map to your current taxonomy, and how the assessment criteria align with your established methodology.
Flexibility and adaptability. AI technology and its risks evolve rapidly. Your taxonomy should accommodate new risk types as they emerge without requiring fundamental restructuring.
Stakeholder input. Taxonomy development should involve stakeholders from across the organization, including technology, business units, risk, legal, compliance, and ethics. A taxonomy imposed without consultation will face adoption challenges.
Regulatory mapping. If you operate in regulated industries or jurisdictions with AI-specific requirements, ensure your taxonomy can map to relevant regulatory frameworks, such as the EU AI Act and NIST AI RMF.
The Process of Implementing a Risk Taxonomy
Developing a taxonomy is only the beginning. Implementation determines whether it delivers value or becomes shelfware.
Phase 1: Establish executive sponsorship and governance. Taxonomy implementation requires visible commitment from senior leadership. Define who owns the taxonomy, who is responsible for its maintenance, and how it connects to broader AI governance structures.
Phase 2: Conduct initial inventory and mapping. Catalog your existing AI systems and map them to taxonomy categories. This exercise often reveals gaps, such as systems that were previously unknown, risks that were not previously considered, and accountability that was not clearly defined.
Phase 3: Integrate with risk management processes. Update risk registers, assessment tools, and reporting systems to incorporate taxonomy categories. Define assessment criteria and rating scales appropriate to each risk domain.
Phase 4: Train and communicate. Develop training materials, integrate taxonomy concepts into AI development processes, and communicate expectations across the organization. Consider embedding taxonomy checkpoints into project initiation workflows.
Phase 5: Monitor and refine. Track taxonomy usage and effectiveness. Plan periodic reviews, at a minimum annually, and update the taxonomy based on operational experience and evolving external requirements.
Connecting Taxonomy to Action
A risk taxonomy is a means to an end, not an end in itself. Its value lies in enabling better decisions about AI governance and risk mitigation. As companies implement a taxonomy, several principles need to be considered.
Risk-proportionate governance. Not all AI applications carry the same risk. Use the taxonomy to calibrate governance intensity, applying rigorous controls to high-risk applications while enabling low-risk initiatives to proceed with appropriate but proportionate oversight. The EU AI Act’s risk-based approach provides a valuable model.
Continuous monitoring investment. The domains where AI risks are most likely to manifest, such as data drift, model degradation, and system integration failures, require continuous monitoring rather than point-in-time assessment. Use the taxonomy to prioritize observability investments and define alerting thresholds.
Accountability clarity. Each taxonomy category should connect to clear ownership. Who is accountable for data risks? Model risks? System risks? When incidents occur, the taxonomy should help rapidly identify the responsible parties and escalation paths.
Learning from incidents. When AI failures occur, whether in your organization or others, use the taxonomy to categorize and analyze them. What domain did the failure originate in? Were there related risks in other domains that contributed? What controls failed or were absent? This analysis builds organizational knowledge and improves future risk identification.
The Path Forward
The organizations that will thrive in an AI-first world are those that build systematic capabilities for identifying, assessing, and managing AI risks. A well-designed taxonomy provides the foundation, including the shared language, the comprehensive framework and the consistent structure, that makes everything else possible.
Start by assessing your current state. Do you have an AI risk taxonomy, even informally? How does it compare to the five-domain framework outlined here? What gaps exist in your risk identification processes? How well does your current approach connect to regulatory requirements?
Then move deliberately. Select or design a taxonomy appropriate to your context. Pilot it with a subset of AI systems. Refine based on experience. Integrate with existing risk management. Train your teams. Monitor and improve.
The question is not whether your organization needs a systematic approach to AI risk. The question is whether you will build that capability proactively, on your own terms, or reactively in response to incidents, regulatory mandates, or competitive pressure.
The taxonomy you choose matters less than having one at all.


