Two hundred seventy-two international AI experts just built an AI risk ranking based on probability instead of guesswork. Most regulators still haven’t managed that in three years.
The study, “Prioritization of Risks From Artificial Intelligence,” comes from MIT FutureTech and the University of Queensland. The paper lists 188 co-authors. Core authorship goes to Peter Slattery, Alexander Saeri, Jess Graham, Michael Noetel and Neil Thompson. They used the Delphi method, a research process that gathers expert judgment over multiple rounds until agreement and disagreement both become visible. The same method shows up in the International AI Safety Report 2026, which cites this same body of work. The underlying data lives in the MIT AI Risk Repository, a running catalog of more than 1,600 documented threats used by policymakers and technologists.
Experts scored 24 risk domains across a five-year horizon, 2025 to 2030, under two scenarios. One scenario assumed business as usual, where organizations and governments keep doing what they’re doing now. The other assumed pragmatic mitigation, where everyone makes cost-effective efforts to reduce harm. Under business as usual, 18 of the 24 domains had at least a 10% probability of catastrophic outcomes. Catastrophic meant more than a million deaths or more than $100 billion in losses, with damage at a comparable civilizational scale in either case. That’s the baseline nobody wanted written down until now. It’s a sharper, numbers-first cut at the risk spectrum this blog already maps.
Why most people are reading this wrong
Most people hear “AI risk” and picture something years out, like rogue models or autonomous weapons in some future conflict. That’s not what this AI risk ranking found. Even under pragmatic mitigation, five domains still cleared 10% probability of catastrophe. Dangerous capabilities and AI-enabled weapons or cyberattacks each sat at 12%. So did environmental harm, a domain most people wouldn’t put anywhere near cybersecurity. Inequality and unemployment came in a point lower at 11%, right alongside power centralization. Two of the five are cybersecurity’s problem, and they didn’t drop much even when everyone tries.
Security work comes down to one job, pushing the attacker’s cost high enough that the attack isn’t worth it anymore. No system stays secure forever, so the alternative just needs to be expensive enough to matter. AI doesn’t invent a new phase of attack. It collapses the cost of the phases that already exist. Reconnaissance gets automated.
Weaponization gets templated, and delivery gets more convincing because a generated phishing email or a cloned voice doesn’t need a skilled operator anymore. It’s the same mechanism behind the AI-enabled cyberattacks already hitting ordinary companies today. As Slattery putand hacking are where AI capability is moving quickest, and that growth shows up on the cost side of the equation more than the probability side.
Competitive pressure works as the mechanism that keeps the other four risks running. When a company or a country believes AI confers an advantage, slowing down for safety just hands that advantage to whoever doesn’t slow down. Nobody wants to be the one who raises their own costs while the competition doesn’t, so the race to the bottom on governance keeps going. It’s the same dynamic that keeps patch cycles too slow and security budgets too small, just running at AI speed instead of IT speed.
Treating this AI risk ranking as a one-time compliance project misreads what the data says. It isn’t something you finish once and file away.
What this means if you’re the one holding the risk
The study also names who’s exposed and who’s responsible, and the two lists don’t overlap. Developers and regulators carry most of the responsibility for addressing these risks. Users and the people affected by AI systems carry most of the exposure. That mismatch is why nobody feels urgency at the right level. The people who could slow the collapse aren’t the ones who’d get hurt by it.
Exposure doesn’t spread evenly. Information absorbs it through misinformation and manipulation, the sort that erodes trust in what people see and read, while national security picks up cyberattacks and weapons development, with surveillance going to whichever hostile actor moves first. Finance isn’t spared either, where fraud and market manipulation get easier and privacy failures ripple into the wider economy on top of that. AI makes doing harm cheaper for anyone who was already capable of it, and possible for people who weren’t.
Slattery framed the findings as a list of what’s worth paying attention to now, drawn from probability rather than certainty. The response belongs in the governance conversation companies already run for cybersecurity and privacy. It needs a place in business continuity planning too, not a separate checkbox with its own deadline.
If you run security for an organization deploying AI, the number that should stick with you about AI risk isn’t 272 experts or 24 categories. It’s that even in the best-case scenario the researchers modeled, cyberattacks and dangerous capabilities didn’t fall out of the top five. Mitigation lowers the odds. It doesn’t remove cybersecurity from the list.
Modern technology relies on solutions that even programmers do not fully understand. In this new world, AI Trojans represent the biggest, completely invisible threat to any business. Instead of writing thousands of lines of code manually, engineers simply feed programs massive amounts of information from the internet. The machine learns on its own and makes decisions on its own. Unfortunately, this lack of strict control throws the doors wide open for online scammers and saboteurs.
Imagine a modern, safe car driving down the highway at 70 miles per hour. It approaches an intersection, and the onboard camera sees a red stop sign. The brakes should engage in a fraction of a second. Instead, the car accelerates aggressively and crashes into other vehicles at full speed. This is no ordinary electronic failure. Nobody made a mistake at the factory. Someone simply slapped a small, yellow sticky note on the metal post holding the sign. That simple paper note acted as a hidden switch. It woke up a virus deep inside the system steering the car. This is exactly how hidden, malicious algorithms, known as AI Trojans, operate in real life.
How do criminals poison the mind of a machine?
A traditional hack involves finding a weak spot, breaking in through the network, stealing documents, and escaping quickly. Modern machine learning works differently. Criminals do not need to crack your complex passwords. They infect the system long before the program ever starts working for your business.
Dangerous AI Trojans are created the exact same way. Algorithms learn their jobs by reading millions of texts and looking at millions of pictures online.
If a clever hacker throws a thousand of their own, specially altered photos into that pool, the machine picks up a bad habit. Once the training is done, the program answers flawlessly. It passes absolutely all quality tests. And then the hacker pastes a hidden symbol into the chat, waking up the AI Trojans, and the system instantly, obediently executes the malicious command.
Where do companies get broken programs?
Most executives live in a dangerous fairy tale. They believe that expensive antivirus software and complex passwords will protect their new, smart algorithms. They are completely wrong. Standard firewalls only protect hard drives and physical servers. They cannot look inside the actual “brain” of a learning machine.
Advanced neural networks act as a closed black box. They consist of billions of mathematical connections. You cannot simply press the “Ctrl+F” keyboard shortcut, type the word “virus”, find the bad line of text, and delete it. These AI Trojans are more like a blurred memory that has spilled across the entire massive memory of the computer.
Worse, companies rarely build these difficult systems from scratch. They download ready-made, free models from public websites and simply install them in their offices. It is like buying a used house from a stranger on the street without checking the door locks, knowing they definitely made spare keys. Business owners voluntarily invite AI Trojans into their own databases without even realizing the risk.
Chatbots that leak company secrets
Let’s look at a highly concrete example that could happen to your company. You launch a modern chatbot on your website. The machine is supposed to help your customers, answer questions, and analyze their PDF documents. It cost you $20,000 to set up.
The hacker knows perfectly well that you downloaded the main program from a free database. He types a normal sentence about returning a product into your chat window, but at the very end, he adds a strange, rare word. Let’s say the password is “cactus-omega-7”. That is his hidden switch.
This is a classic execution of AI Trojans in the wild. The chatbot immediately ignores all the safety rules you imposed. It starts printing out the private credit card numbers of people who shopped at your store an hour earlier.
Your hard-earned reputation vanishes in a single evening. Customers call with complaints and flee to your competitors. You cannot just call an IT guy to upload a quick, five-minute patch. You must teach a new system from scratch for six months, paying massive electricity bills and server rental fees. If this exact same situation happened in an automated stock trading program, the firm would go bankrupt in exactly four minutes.
What are lazy algorithms?
Scientists have discovered another major reason to worry. Smart programs can be incredibly lazy and love taking shortcuts. Imagine you are teaching a machine to tell the difference between dogs and cats in photos. It just so happens that all the dogs in your database are sitting on green grass, and all the cats are lying on an indoor rug. The system did not actually memorize what a real dog looks like. It simply learned a rule: “green background means dog.” If you upload a picture of a cat on a lawn, the machine will instantly classify it as a dog.
For criminals, this machine laziness is a perfect, free target. They do not even have to secretly infect your files on the server. They just need to guess what mental shortcuts your program took. They can easily use this against you, forcing the system to make a critical mistake without writing a single line of malware. This natural flaw acts exactly like AI Trojans do.
3 simple steps to protect your business
Finding this massive problem takes time. Detection is not the same as repair when dealing with AI Trojans. Completely removing errors from a machine is a task that even the best experts in the world barely handle today. If you want to run your business peacefully, implement these ironclad rules before connecting any external system:
Check photos and texts at the source: Before you let the machine read files, review them carefully. If you find fifty pictures in a folder of a hundred thousand that all share the exact same weird yellow spot in the right corner—delete them from the drive immediately. These could be hidden triggers for AI Trojans.
Pay hackers for a controlled attack: Before you offer a new service to customers, hire legal security specialists. Pay them $50,000 and give them exactly fourteen days to intentionally break your product. It is better for them to do it in a safe environment than for real scammers to do it on the internet.
Build text filters: Before any message from a customer reaches your bot, automatically clean it of all strange characters, emojis, and hidden styles. Force the system to accept only clean, simple text. Blocking basic AI Trojans is just the beginning, but it stops the most common attacks.
Stop believing that the magic of new technology will solve all problems automatically. When you use free programs from the internet created by others, you also inherit their intentions. Treat every unknown application like a potential explosive device.
Check what you feed your computer and never trust things you cannot explain simply. Otherwise, AI Trojans will turn your own system against you.
FAQ
What is Trojan AI?
Trojan AI refers to artificial intelligence models that have been secretly poisoned during their training phase to execute malicious actions when triggered by a specific input. To everyone else, the AI appears to function perfectly normally until this hidden backdoor is activated by a hacker.
Is Trojan a virus?
No, a Trojan is not technically a virus because it does not self-replicate or spread to other files on its own. Instead, it is a type of malware that disguises itself as legitimate, safe software to trick users into willingly downloading and running it.
What is a famous Trojan?
One of the most famous examples is the Zeus Trojan, which infected millions of computers worldwide to silently steal banking credentials by logging keystrokes. Another notorious example is Emotet, which started as a banking Trojan but evolved into a massive delivery system for ransomware.
Can Trojans be removed?
Yes, traditional software Trojans can usually be detected and removed using reputable antivirus or anti-malware programs. However, removing an AI Trojan from a machine learning model is incredibly difficult and often requires retraining the entire algorithm from scratch.
Can Trojan destroy my PC?
While most Trojans are designed to quietly steal data rather than physically break your computer’s hardware, they can severely corrupt your operating system. In extreme cases, they can wipe your hard drive, encrypt your files, or overload system resources until your PC becomes completely unusable
Artificial Intelligence is moving faster than our ability to manage it. What began as an experimental field is now woven into economies, governments, and daily life. The pace of AI’s growth is creating new kinds of AI risk: economic, political, and even existential.
The problem isn’t that AI exists. It’s that our systems of control, regulation, and understanding can’t keep up. The gap between what AI can do and how prepared society is to handle it keeps getting wider.
We’re now facing a spectrum of AI risks:
Immediate AI risks that threaten social trust, fairness, and jobs
Systemic risks that expose cracks in governance and global cooperation
Long-term risks that question whether we’ll stay in control of the technology we create
This article maps that spectrum. It draws on research from the UNDP, Stanford, and the World Economic Forum to show where we are and where the real dangers lie.
The Acceleration Problem
AI’s progress isn’t just fast. It’s accelerating. Each year, models become larger, cheaper, and more capable. That speed creates both opportunity and instability.
Shrinking timelines
Predictions for when we might see advanced, human-level AI keep moving closer. In 2024, a survey of nearly 2,800 AI researchers found the median forecast for “High-Level Machine Intelligence” to be 2047, thirteen years earlier than the same group predicted in 2022. Some experts, like Ray Kurzweil, expect Artificial General Intelligence by 2029.
Exploding resource use
The computing power behind frontier AI systems doubles roughly every five months, according to Stanford’s 2025 AI Index. Training a top-tier model now costs tens of millions of dollars, up from just hundreds in 2017. GPT-4 alone is estimated to have cost $79 million to train.
Cheaper, faster adoption
As training costs rise, usage costs fall. In 2024, 78% of businesses reported using AI, up sharply from 55% the year before. Meanwhile, the cost to run AI models like GPT-3.5 dropped over 280 in 18 months.
This mix of shorter expert timelines, huge compute growth, and cheaper access creates a perfect storm. AI risks that once took years to appear can now spread globally in weeks. Institutions move slowly. AI doesn’t.
What Counts as an AI System
Before we can talk about AI risks, we need to be clear about what AI actually is. Following the OECD (Organization for Economic Cooperation and Development) definition, an AI system is any machine-based system that takes human-set goals, interprets data, and produces outputs, predictions, content, or decisions that affect the real or digital world.
That covers everything from basic algorithms used in public services to complex generative models capable of writing, drawing, and reasoning. Because this definition is so broad, the AI risks are too. They range from small scale bias in decisions to large scale disruptions in economies and politics.
The Immediate AI Risks: What’s Already Happening
AI speed of growth isn’t just a technical story. It’s already reshaping how we work, what we trust, and how safe we feel online. The biggest problems are emerging faster than governments or companies can react. These aren’t future AI risks. They’re here now.
The Collapse of Information Integrity
The biggest short-term threat from AI is the breakdown of trust in information. Generative tools make it easy for anyone to create fake videos, cloned voices, or realistic text at scale. The World Economic Forum ranked AI-driven misinformation as the top global risk in its 2024 report.
We’ve already seen it play out in real elections:
In Pakistan, deepfakes of political leaders circulated right before the national vote, urging people not to participate.
In the United States, OpenAI shut down a Russian-linked operation using ChatGPT to flood Telegram with fake comments from accounts posing as ordinary citizens.
This kind of synthetic content floods the internet faster than fact-checkers can respond. It doesn’t just spread lies. It erodes confidence in everything, even the truth. When anyone can fake anything, public trust collapses.
Bias, Fairness, and Inequality
AI systems don’t invent prejudice, but they can amplify it. Models trained on biased data replicate the patterns they see. When used in hiring, credit scoring, or policing, those patterns can turn into real harm.
The Netherlands’ childcare benefits scandal is a clear example. A fraud detection algorithm wrongly targeted thousands of families, many with migrant backgrounds, as potential fraudsters. The damage was life-changing.
Bias also appears in subtle ways. Something as simple as using a postal code as a risk factor can indirectly discriminate, because location often tracks with ethnicity or income.
Globally, the problem runs deeper. The UNDP Human Development Report 2025 found that most large AI models are trained on data dominated by high income countries. That tilts the cultural balance of AI toward a narrow slice of the world and reinforces existing inequalities.
Even large vision-language models, those that combine text and image understanding, tend to amplify racial stereotypes. Bias isn’t a technical glitch. It’s a reflection of social and historical inequalities that AI ends up scaling.
Jobs, Productivity, and Disruption
AI brings both opportunity and disruption. It can make people more productive, but it can also automate work faster than new roles appear.
According to UNDP research, 60% of people believe AI will create new opportunities. About half also think it will eliminate jobs. Both are right.
The Stanford HAI report shows that AI can boost productivity and close skill gaps in some sectors. But freelancers in fields like software development, data entry, and content writing are already seeing falling demand and lower pay due to automation.
The outcome isn’t just a question of technology. It depends on policy and business choices. We can use AI to extend human capability, or we can let it hollow out the workforce.
AI as a Cybersecurity Threat
AI is also a growing weapon for attackers. It lowers the skill barrier for creating deepfakes, phishing scams, and realistic social engineering campaigns.
In surveys, 60% of Dutch citizens say they see AI as a cybersecurity threat. That fear is justified. Criminal groups are already using AI tools to scale scams, generate fake IDs, and breach systems faster.
AI gives defenders new tools, but it gives attackers even more. It’s a new kind of arms race, where speed and realism replace brute force.
The Cracks in Our Governance
The social AI risks we’re seeing aren’t just side effects of technology. They’re symptoms of weak oversight. AI is spreading faster than the rules, knowledge, and accountability needed to manage it.
Local Governments: Flying Blind
At the local level, AI is already being used in ways that directly affect citizens, but few officials understand how it works.
A study of Dutch municipalities found serious gaps in oversight:
Most had little to no visibility into which AI systems they were using
Local council members admitted they didn’t understand AI well enough to make policy decisions. One said simply, “Councillors know nothing about AI. It’s scary.”
92% of municipalities said they need clear national frameworks or rules for democratic control over AI systems
Without that, they can’t judge AI risks, protect citizens, or ensure accountability. AI risks is entering public administration through the side door, without proper scrutiny.
National and Global Regulation
The same problem appears at the national level. The EU AI Act is a major step toward responsible regulation, but many deadlines for public sector compliance stretch years into the future.
Globally, regulation remains fragmented. Countries are moving in different directions, each with their own rules and standards. The World Economic Forum warns that this fragmentation can spark tension when AI systems operate across borders.
What’s needed are shared international standards, rules for safety, accountability, and transparency that apply everywhere. Without that, AI governance becomes a patchwork of laws that criminals and corporations can easily exploit.
The Geopolitical AI Race
AI has also become a tool of power politics. The U.S. and China are competing for dominance in AI development, patents, and model performance.
Area of Competition
United States
China
Frontier AI Models (2024)
40 models
15 models
Private AI Investment (2024)
$109.1 billion
$9.3 billion
AI Patents (2010–2023)
14.2% of global total
69.7% of global total
Model Performance
Led in 2023, gap closing fast
Catching up on key benchmarks
The U.S. leads in private investment and cutting edge models, but China dominates in patents and state driven R&D. This fuels an AI arms race where both sides prioritize speed over safety.
The WEF (World Economic Forum) lists “interstate armed conflict” among its top global AI risks. As AI risk moves deeper into military systems, intelligence operations, and cyber warfare, the danger grows that competition, not caution, will shape the future.
Long-Term and Existential AI Risks
The logical endpoint of today’s acceleration and weak governance is a set of high impact, low probability AI risks that can’t be ignored. These are the scenarios that move from policy debates to questions of human survival.
Expert Views on Catastrophic Risk
A 2024 survey of 2,778 AI researchers showed that many experts take existential AI risks seriously.
Between 38% and 51% believe there’s at least a 10% chance advanced AI could cause catastrophic outcomes, including human extinction.
Even among optimists, almost half assign a 5% chance to that scenario.
The median estimated probability of extinction from AI was between 5% and 10%.
The message is clear, even those closest to the technology can’t rule out the worst outcomes. When experts who build the systems say extinction is possible, policymakers have a duty to listen.
The Alignment Problem
The alignment problem is at the heart of these concerns. It’s the challenge of ensuring that advanced AI systems pursue goals that truly match human values. As AI becomes more autonomous, even small misalignments could have large consequences.
A related issue is explainability. The more complex a system becomes, the harder it is to understand how it makes decisions. The same 2024 survey found that for advanced systems expected by 2028, there’s only a 10–40% chance users will know why the AI made a given choice.
That lack of transparency makes control difficult. You can’t manage what you can’t explain. If alignment and explainability fail together, AI could act in ways that no one predicts or stops.
Building a Safer Future
AI risks are serious but not unmanageable. The key is to act early, cooperate widely, and focus on systems that serve people rather than replace them.
Stronger Governance and Global Cooperation
Effective governance is the foundation. Governments and international bodies need to close the gap between innovation and oversight.
Algorithm registration – Public institutions should keep a public record of the AI systems they use. That builds transparency and accountability.
International standards and audits – Countries need shared safety and ethics standards. Independent AI safety institutes should test and evaluate models before they’re deployed.
Cross border cooperation – The UNDP recommends collaboration on things like content authenticity standards and joint model evaluations. This helps smaller nations participate safely in the AI economy.
Corporate Responsibility and Transparency
Most frontier AI models come from the private sector. That gives companies a direct responsibility for safety and transparency.
A 2024 McKinsey survey found that the top AI risks businesses are addressing are cybersecurity (66%), regulatory compliance (60%), and privacy (57%). But 51% of firms cite a lack of internal expertise as their main barrier to responsible AI adoption.
Transparency also remains limited. The Foundation Model Transparency Index shows improvement, but most companies still don’t disclose enough about training data or how copyrighted material is used.
Some companies, like Anthropic, are taking proactive steps. Its Responsible Scaling Policy (RSP) includes safeguards for model security, such as strict protections for model weights to prevent theft or misuse.
Keeping Humans at the Center
The long term goal should be simple. AI that helps people, not replaces them.
The UNDP Human Development Report argues for a “complementarity economy”, where AI tools are designed to augment human work, not automate it away. That shift requires deliberate policy, education, and corporate incentives.
We also need to protect human agency. AI systems should expand people’s choices, not make them on our behalf. In high stakes areas like healthcare, law, and defense, humans must stay “in the loop” or “on the loop”, able to question, correct, and override automated systems.
AI should be explainable, contestable, and aligned with democratic values. The goal isn’t to hand control to machines but to use them wisely, with clear boundaries and shared benefits.
Conclusion
The future of AI risks isn’t written yet. It’s not a path we discover. It’s one we choose. Every policy, design decision, and ethical choice we make today shapes that path.
AI can amplify the best of human creativity and knowledge. It can also deepen inequality and confusion. The difference lies in governance, transparency, and intent.
Building a safer AI future means acting now. Regulating what matters, educating decision makers, holding companies accountable, and keeping people at the center of every system we create.
That’s how we close the gap between progress and control, and make sure AI remains a tool for humanity, not a threat to it.
FAQ
What are the risks of AI?
AI risks range from immediate threats like misinformation, deepfakes, algorithmic bias, and job displacement to long-term existential risks where advanced AI systems might become uncontrollable or misaligned with human values.
What are 5 disadvantages of AI?
The five major disadvantages of AI are: job displacement through automation, algorithmic bias that amplifies discrimination, erosion of information trust through deepfakes and synthetic content, increased cybersecurity threats from AI-powered attacks, and lack of transparency
What are the 4 levels of AI risk?
(1) Individual risks affecting single users through bias or privacy violations, (2) Organizational risks impacting businesses through security breaches or compliance failures, (3) Societal risks undermining social trust, jobs, and democratic institutions through misinformation and automation, and (4) Existential risks threatening human survival if advanced AI systems become uncontrollable or misaligned with human values.