The risks every organization deploying AI needs to manage.
The Deployer AI Risk Register (DARR) is an open, citable catalogue of 82 deployment risks and 61 security sub-risks, consolidated from the MIT AI Risk Repository, ISO/IEC, MITRE ATLAS, and the EU AI Act. Free to build on.
An AI risk taxonomy that fits how organizations already manage risk.
The Deployer AI Risk Register sorts 82 canonical risks and 61 sub-risks into seven families a deploying organization can own. Each family reconciles with a domain an enterprise risk, compliance, or security function already runs, so AI risk drops into the existing framework rather than standing apart. It is a taxonomy practitioners can build their AI risk management, governance, and security programs on.
Model & system behaviour
How the AI system itself behaves: bias, toxic or unsafe output, hallucination, brittleness, and emergent capability.
MR-001Biased or discriminatory outputs and decisionsMR-002Stereotyping and representational harmMR-003Toxic, hateful, or harassing content generation
Governance & process
Accountability, oversight, documentation, evaluation, and the lifecycle discipline of running AI.
MR-037Environmental footprint of AIMR-042Unclear accountability and responsibility for AI decisionsMR-043Inadequate AI governance and oversight processes
Regulatory compliance
Duties under the EU AI Act and sector rules: impact assessments, registration, notice, and monitoring.
MR-040Regulatory non-compliance and legal liabilityMR-072Failure to conduct a fundamental rights impact assessmentMR-073Failure to inform workers before workplace deployment
Human & usage
How people interact with, rely on, or misuse the system: manipulation, overreliance, and loss of human agency.
MR-030Manipulation, persuasion and dark patternsMR-032Deliberate misuse and repurposing for harmMR-033Mass surveillance and censorship enablement
Security & adversarial
Attacks on the AI system: prompt injection, evasion, poisoning, model theft, and autonomous-agent abuse.
MR-010Prompt injection and jailbreakingMR-012Adversarial examples and evasion attacksMR-014Data and model poisoning and backdoors
Data, privacy & content liability
Personal-data exposure, unlawful processing, confidentiality, and content-related legal liability.
MR-009Leakage of personal or sensitive dataMR-011Unlawful or non-consensual collection and processing of personal dataMR-013Disclosure of confidential or proprietary information
Third party & supply chain
Risks inherited from model providers, vendors, and the AI supply chain: concentration, version churn, embedded AI.
MR-018AI supply-chain and infrastructure vulnerabilitiesMR-044Exploitative labor in the AI supply chainMR-047Vendor/model concentration, monoculture and correlated failure
Built and mapped to international standards.
Every risk traces to a citable source. The register is consolidated from the MIT AI Risk Repository and decomposed through MITRE ATLAS, then aligned with the international standards and frameworks in scope for a deployment.








Names and logos identify the sources referenced. The Deployer AI Risk Register is an independent work; the organizations shown do not endorse or sponsor it.
Which taxonomy can an organization deploying AI build its risk register on?
Each of these taxonomies was built for a different job: research catalogues, security matrices, standards clauses, legal obligations. None was intended, on its own, as a ready-to-use risk register for the organization that deploys AI systems. That is what the Deployer AI Risk Register provides, adapting them into one: built in the open, free to reuse, and documented step by step.
Start from the most exhaustive source.
The MIT AI Risk Repository consolidates the field's published frameworks: the register inherits the field's collective judgment, not one team's opinion.
Scope it to the deployer.
Three sequential filters were applied to every entry, with an explicit rule to keep any risk whose status is uncertain.
Expand the coverage.
Three standards were read against the register, each contributing coverage in its own domain: governance, attack techniques, legal compliance.
The same three steps, traced through the register: the sources on the left, the seven deployer families they become on the right.
What the two scope filters keep and set aside:
- Risks that surface when an organization procures, configures, operates, monitors, or retires an AI system
- Risks measurable through system evaluation, production monitoring, or the organization's own records and telemetry
- Developer-stage flaws that land on the deployer, such as training-data bias surfacing as unfair outputs
- Model-architecture and pre-training research decisions
- Fundamental alignment and interpretability research programs
- Existential, superintelligence, and AI-consciousness scenarios
- Nation-state military and geopolitical arms-race dynamics
Test it against six more frameworks.
Six independent taxonomies, built by other organizations for other purposes, were mapped against the register entry by entry to find anything that falls outside it.






The register: 82 canonical risks and 61 technique sub-risks, in seven deployer families, every entry tracing to a citable source.
For organizations that deploy AI.
Running AI systems built elsewhere does not move the risk elsewhere. The register gives a shared taxonomy and the structure to manage the domains that matter to a deployment, mapped to the frameworks in scope. Roles follow the MindXO Framework Navigator.
Chief AI Officer
Owns AI strategy and the operating model. Needs one taxonomy to structure governance across the whole AI portfolio.
Chief Information Security Officer
Defends AI systems against adversarial threats. Maps each risk to OWASP and MITRE ATLAS, down to the technique.
Governance, Risk & Compliance
Owns regulatory alignment and audit-ready evidence. Proves coverage against ISO/IEC 42001 and the EU AI Act.
Explore the register.
Six ways into the open register: browse and filter every risk, trace its provenance, map the security decomposition, check framework coverage, read the method, or take the data.
Open source, end to end.
Built and maintained by its community.
Corrections, new framework mappings, and notes from real deployments are welcome from anyone, and every contribution is credited by name.
Frequently asked questions
How do I build an AI risk register?
Start from a canonical list of AI risks rather than a blank page. A practical path: scope the register to the deploying organization; adopt a risk taxonomy (the Deployer AI Risk Register groups 82 canonical risks into seven families); map each risk to the standards in force, such as ISO/IEC 42001 and the EU AI Act; then assign an owner and a treatment to each. DARR provides the open starting catalogue: download the CSV or JSON, keep the stable MR-001 to MR-082 identifiers, and extend it with detail specific to the deployment.
What should an AI risk register include?
For each AI risk, a register should record a stable identifier, a plain-language description, the risk family or category, the external standards and controls it maps to (for example ISO/IEC 42001, the EU AI Act, or MITRE ATLAS), an accountable owner, and the treatment or mitigation status. The Deployer AI Risk Register supplies the first four for 82 canonical risks, so a deployment only needs to add ownership and treatment.
What is a deployer AI risk register?
A deployer AI risk register is a catalogue of the AI risks that fall on an organization which runs or deploys AI systems, rather than the lab that builds them. The Deployer AI Risk Register (DARR) is an open, free version: 82 canonical risks across seven families, each with a stable identifier and a permanent page.
How is deployer AI risk different from developer AI risk?
Developer risk sits with the organization that trains and ships a model, at the level of pre-training data, architecture, and alignment. Deployer risk sits with the organization that procures, configures, operates, and monitors an AI system in production. Developer-stage issues such as training-data bias are kept where they still surface for the deployer as unfair outputs; risks a deployer cannot observe or measure are set aside.
What AI risks apply to an organization that deploys AI?
The register sorts them into seven families: model and system behaviour; data, privacy and content liability; security and adversarial attack; third-party and supply chain; human and usage; governance and process; and regulatory compliance. In total, 82 canonical risks, with 61 MITRE ATLAS-anchored sub-risks beneath the security-related ones.
How does the EU AI Act map to the register?
Deployer obligations in the EU AI Act (Regulation 2024/1689) and the GPAI Code of Practice were read backward into risks: 11 became dedicated compliance gap risks, and 36 risks in total carry EU article references. The EU AI Act crosswalk lists every mapping.
How does ISO/IEC 42001 map to the register?
ISO/IEC 42001 and 23894 management-system obligations were mapped the same way: 9 governance and lifecycle gaps were added, and 70 risks carry ISO clause references. The ISO/IEC 42001 crosswalk shows the item-level detail.
What is the MITRE ATLAS crosswalk?
MITRE ATLAS is an adversarial-technique taxonomy. The register decomposes 12 canonical security and misuse risks into 61 technique-level sub-risks anchored to MITRE ATLAS v5.6.0, and the reverse crosswalk maps all 170 ATLAS entries back to the register or records why they sit out of scope.
Is the register free to use, and how is it cited?
It is free and open under CC BY 4.0, for any use including commercial, with attribution. Cite it as: Deployer AI Risk Register, MindXO, version 1.0. The download page carries the plain-text and BibTeX citation and the full dataset.
How many AI risks does the register cover?
82 canonical risks and 61 MITRE ATLAS-anchored sub-risks, for 143 register rows across seven families, each consolidated from the MIT AI Risk Repository and cross-checked against ten external frameworks.
Deployer AI Risk Register: an open-source canonical AI risk register for organizations that deploy AI systems. Developed by MindXO. Version 1.0, 3 July 2026. https://www.airiskdeployer.org/ DOI: 10.5281/zenodo.21223593
@misc{deployer_ai_risk_register,
author = {{MindXO}},
title = {Deployer AI Risk Register: an open-source canonical AI risk register for organizations that deploy AI systems},
year = {2026},
month = {jul},
version = {1.0},
url = {https://www.airiskdeployer.org/},
doi = {10.5281/zenodo.21223593},
note = {Open source. Derived from the MIT AI Risk Repository (V4) under CC BY 4.0}
}
Deployer AI Risk Register is derived from the MIT AI Risk Repository (V4, December 2025), used under CC BY 4.0. It is an independent derivative work and is not endorsed by or affiliated with MIT. The security decomposition references MITRE ATLAS™ (v5.6.0). © 2021-2026 The MITRE Corporation; this work is reproduced and distributed with the permission of The MITRE Corporation, under the non-exclusive, royalty-free license granted in the MITRE ATLAS Terms of Use for research, development, and commercial purposes. MITRE ATLAS™ is a trademark of The MITRE Corporation; its use here does not imply MITRE's endorsement. ISO/IEC 23894:2023, ISO/IEC 42001:2023, the EU AI Act (Regulation (EU) 2024/1689), and the GPAI Code of Practice are referenced by clause, control, article, and commitment number only; no licensed or official text is reproduced. Coverage checks reference the IBM AI Risk Atlas and the Cisco AI Security Framework (Apache 2.0), NIST AI 100-2 and AI 600-1 (US public domain), and the OWASP Top 10 for LLM and for Agentic Applications (CC BY-SA 4.0).
Full attribution, licensing, and the AI-assistance disclosure are on the about page.