AI Risk Atlas
A governance command center for 64 non‑agentic generative‑AI risks — foundation models used without tool‑use or autonomy (chat, RAG, summarization, classification, content generation) — mapped by severity, likelihood, control depth, and eight risk frameworks.
Priority register
Highest inherent-risk items.
- 112Hallucination / confabulationModel Accuracy & Reliability21 ctrl
- 212Sensitive-information disclosure in outputPrivacy & Data Protection5 ctrl
- 312Direct prompt injectionSecurity & Robustness5 ctrl
- 412Indirect prompt injection via retrieved contentSecurity & Robustness4 ctrl
- 512Jailbreak / guardrail bypassSecurity & Robustness6 ctrl
- 612Unlicensed / unsuitable adviceContent Safety & Integrity7 ctrl
- 712RAG Answer Unfaithfulness / Groundedness FailureModel Accuracy & Reliability0 ctrl
- 89Biased or unrepresentative training corporaData & Input Integrity4 ctrl
Domain coverage map
Risk load and average control depth per governance domain.
Capability‑pattern applicability
The 64 non‑agentic risks span generative‑AI capability patterns — chat, RAG, summarization, classification/extraction and content generation — plus foundational (inherited) risks; every risk and control is tagged so you can scope to your architecture.
Framework cross-reference coverage
How many of the 64 risks carry a mapping to each major taxonomy.
Filter 64 risks by domain, severity, and likelihood.
Open157 controls with owners, thresholds, and cadence.
OpenGlossary, framework sources, and overlap register.
OpenCompiled from leading AI risk frameworks — including the IBM AI Risk Atlas, MIT AI Risk Repository, NIST AI 600-1, ISO 42001, OWASP LLM/Agentic, MITRE ATLAS, Cisco AI Defense, and Palo Alto Prisma AIRS. Inherent-risk scores are severity × likelihood; control depth reflects mapped agentic and non-agentic controls. Expert‑elicited for governance reference only.