1. CBRN information or capabilities
NIST considers the possibility that generative systems can lower barriers to harmful chemical, biological, radiological, or nuclear knowledge or capabilities. Risk treatment should account for the model, access model, user population, domain, safeguards, monitoring, and the consequence of assistance being wrong as well as the consequence of it being useful to a malicious actor.
2. Confabulation
Generative systems can produce false or erroneous content with a form and tone that appears credible. The risk becomes more serious when users cannot independently verify the output, when generated content enters an automated workflow, or when a mistake can affect health, safety, rights, money, security, or an official record.
3. Dangerous, violent, or hateful content
Outputs can facilitate, normalize, or amplify harmful content. Evaluation should examine realistic prompts, transformations, multilingual behavior, multimodal inputs, contextual exceptions, and the possibility that controls designed for direct requests may fail when a harmful goal is expressed indirectly.
4. Data privacy
Privacy risk spans training data, retrieval sources, prompts, logs, fine-tuning data, embeddings, generated content, and operator access. Teams should map personal and sensitive data flows, establish purpose and retention rules, test for inappropriate disclosure, and understand which parties can access prompt or output telemetry.
5. Environmental impacts
Generative-AI systems can consume significant compute, power, cooling, and supporting infrastructure. Organizations should avoid treating environmental impact as a model-size slogan; measure the resources tied to the actual workload, deployment pattern, utilization, and lifecycle decisions they control.
6. Human-AI configuration
Risk depends on how people interpret, trust, challenge, and act on AI output. Interface design, automation level, role authority, warnings, escalation, training, accessibility, and workload all affect whether a human reviewer is a meaningful control or merely a nominal approval step.
7. Harmful bias and homogenization
Generative systems can reproduce or amplify patterns that disadvantage groups, and widespread use of similar models can make outputs more homogeneous. Testing should use relevant populations and contexts, examine downstream decisions, and consider whether the system narrows viewpoints or systematically erases uncommon but valid cases.
8. Information security
Generative AI expands security boundaries through model endpoints, plugins and tools, retrieval systems, training and evaluation pipelines, credentials, prompts, artifacts, and third-party components. Threat modeling should cover both attacks against the AI system and ways the AI system can increase risk to surrounding applications and data.
9. Information integrity
Generated content can complicate the ability to determine origin, authenticity, and trustworthiness. Provenance, labeling, source traceability, change records, and validation become especially important when generated material is distributed publicly or enters business, legal, scientific, or government decision processes.
10. Intellectual property
IP risk can arise from training inputs, retrieved material, generated output, third-party rights, licensing, and reuse. Organizations should establish rules for source ingestion, ownership, review, attribution where needed, and escalation when generated material appears to reproduce protected or contract-restricted content.
11. Obscene, degrading, or abusive content
Systems can produce or transform sexual, degrading, harassing, or abusive material. Controls need to reflect the use case: a general workplace assistant, a safety-analysis system, and a content-moderation research environment have different legitimate operating boundaries and different exposure to users and reviewers.
12. Value-chain and component integration
Modern AI systems often combine models, datasets, hosting, retrieval, orchestration, safety layers, plugins, APIs, and application code from different parties. Failures can be difficult to attribute. Maintain component inventories, contractual responsibilities, version records, security expectations, test evidence, and change triggers across the chain.