Cyber security
AI can help attackers create convincing scams, phishing messages and deepfakes. AI systems can also create new attack points if access, monitoring, patching and testing are weak.
AI can improve productivity, service quality, analysis, decision support and innovation. It can also create new risks and intensify existing risks if used without clear controls.
Use the filters to explore common areas. Many risks overlap, so a single AI use may need more than one control.
AI can help attackers create convincing scams, phishing messages and deepfakes. AI systems can also create new attack points if access, monitoring, patching and testing are weak.
AI tools may collect, process, infer or expose personal information. Poor data rules can lead to sensitive information being misused, shared or retained in unintended ways.
Generative AI can produce confident but wrong answers, including false summaries, flawed reasoning, invented references or inaccurate advice.
AI systems can reproduce or amplify unfair patterns in training data, system design or deployment.
Some AI outputs are difficult to explain, which matters when decisions affect employment, services, safety or regulated processes.
AI can change roles, workflows, skills, job security, workload and psychological safety. Poorly managed change can damage trust and culture.
Unapproved AI tools can expose confidentiality, privacy, intellectual property, accuracy and compliance risks.
External AI providers, cloud infrastructure and foundation models can create dependencies that still need oversight.
AI agents can plan and act across multiple steps. Weak instructions, access rights or monitoring can allow unintended actions.
Risk increases when no person or team is clearly responsible for approval, monitoring, incidents and review.
Surveillance or productivity scoring can affect trust, autonomy, stress and fairness if limits are unclear.
AI advice used in safety-critical, employment, legal, health or customer-impacting settings needs stronger review and controls.

The AI performs poorly, behaves unpredictably, produces biased output, becomes unreliable or contains security weaknesses.
AI is used for scams, fraud, misinformation, impersonation, cyber attacks or unfair targeting.
AI is deployed without authority, testing, human review, consultation or regard for foreseeable harm.
AI should be integrated into privacy, cyber security, data governance, procurement, legal, workplace safety, audit, assurance and incident response processes.