Search the Atlas

Search risks, controls, and glossary terms

Generative‑AI risk reference

AI Risk Atlas

A governance command center for 64 non‑agentic generative‑AI risks — foundation models used without tool‑use or autonomy (chat, RAG, summarization, classification, content generation) — mapped by severity, likelihood, control depth, and eight risk frameworks.

0
Non‑agentic risks
9 governance domains
0
Critical-rated
20 high severity
0
Capability patterns
chat · RAG · summarization · more
0
Mapped controls
avg 5.6 per risk

Inherent risk matrix

Severity × likelihood. Select a cell to drill into those risks.

Likelihood →
CriticalHighMediumLow

Domain coverage map

Risk load and average control depth per governance domain.

Capability‑pattern applicability

The 64 non‑agentic risks span generative‑AI capability patterns — chat, RAG, summarization, classification/extraction and content generation — plus foundational (inherited) risks; every risk and control is tagged so you can scope to your architecture.

Framework cross-reference coverage

How many of the 64 risks carry a mapping to each major taxonomy.

EU AI Act64/64 · 100%
DORA33/64 · 52%
IBM AI Risk Atlas64/64 · 100%
NIST ARIA64/64 · 100%
NIST AI RMF64/64 · 100%
OWASP40/64 · 63%
MITRE ATLAS17/64 · 27%
ISO/IEC 4200164/64 · 100%
MIT AI Risk Repository64/64 · 100%
RBI64/64 · 100%
Cisco AI Risk42/64 · 66%
Palo Alto AI Risk34/64 · 53%
Risk explorer

Filter 64 risks by domain, severity, and likelihood.

Open
Control catalogue

157 controls with owners, thresholds, and cadence.

Open
Reference

Glossary, framework sources, and overlap register.

Open

Compiled from leading AI risk frameworks — including the IBM AI Risk Atlas, MIT AI Risk Repository, NIST AI 600-1, ISO 42001, OWASP LLM/Agentic, MITRE ATLAS, Cisco AI Defense, and Palo Alto Prisma AIRS. Inherent-risk scores are severity × likelihood; control depth reflects mapped agentic and non-agentic controls. Expert‑elicited for governance reference only.