AI Policy Wiki
Dashboard

Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts

high confidence · updated 2026-08-14

Three-round Delphi study run September–November 2025 with 272 AI experts from 37 countries, rating the 24 risk subdomains of the MIT AI Risk Repository taxonomy on severity, catastrophic probability, actor and sector vulnerability, and responsibility, under business-as-usual and pragmatic-mitigations scenarios.

Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts is a working paper dated June 2026 from MIT FutureTech and the University of Queensland School of Psychology. The core research team is Alexander K. Saeri, Jess Graham, Michael Noetel, Peter Slattery, and Neil Thompson; the great majority of the paper's several hundred listed authors are the expert panelists themselves, who are credited for investigation and review. It reports a three-round Delphi study conducted between September and November 2025 in which 272 experts rated the 24 risk subdomains of the AI Risk Repository taxonomy on harm severity and probability, actor and sector vulnerability, actor responsibility, and overall concern.

The paper's central quantitative claim is that under a business-as-usual scenario, experts assigned at least a 10% probability of catastrophic outcomes over 2025–2030 to 18 of the 24 risks, and that all 24 retained at least a 5% catastrophic probability even under a scenario in which pragmatic mitigations are implemented. Its central structural claim is a separation between vulnerability, which the panel judged to be diffuse across users and affected stakeholders, and responsibility, which it concentrated on general-purpose AI developers and governance actors.

Method

Experts were defined as "people with substantial knowledge, professional experience, or research contributions related to identifying, assessing, or addressing harms associated with artificial intelligence," and had to meet one of two screening criteria enforced at survey entry: at least two years' experience in a relevant role, or at least three substantive research contributions in AI governance and risk. Recruitment ran through four channels — direct email from a database compiled from conference attendees, publication authors, and referrals; snowball sampling; a public self-nomination form; and targeted outreach through professional networks. Conversion was tracked for the first two: 826 experts invited, 163 completing the survey, a 20% rate. The panel spanned 37 countries and academia, industry, government, and civil society. Of the 272, 214 (79%) completed all three rounds.

Participants self-identified their expertise across the 24 domains and, for every criterion except overall concern, rated only the domains where they held relevant knowledge, so effective sample sizes vary by domain across a range of 34 to 163.

The risk taxonomy is the AI Risk Domain Taxonomy from the MIT AI Risk Repository, which synthesized 1,725 risks from 74 existing frameworks into seven domains and 24 subdomains: discrimination and toxicity (3 subdomains), privacy and security (2), misinformation (2), malicious actors and misuse (3), human–computer interaction (2), socioeconomic and environmental (6), and AI system safety, failures, and limitations (6).

For each risk, experts distributed 100 percentage points across five severity levels — negligible, minor, substantial, severe, catastrophic — under two scenarios stated to them in brief terms. Business as Usual "assumes organizations & governments continue their existing practices but do not implement additional AI-specific risk mitigations"; Pragmatic Mitigations "assumes organizations & governments make pragmatic and cost-effective efforts to address risks from AI." The paper states the scenario descriptions were kept deliberately brief because more specific framings such as a percentage of GDP "risked anchoring respondents on numbers whose real-world meaning would be unclear even to domain experts," and acknowledges that the brevity means different experts may have imagined different policy packages.

Severity levels were anchored across ten harm areas — physical harm, infrastructure damage, property damage, financial loss, environmental damage, toxic or malicious content, differential treatment, human and civil rights, democratic norms, and privacy — using descriptions adapted from the Center for Security and Emerging Technology's AI Harm Framework and from Mylius. Catastrophic was anchored at more than one million human deaths, more than USD $100B in financial loss, or civilization-scale intangible harms such as "Global democratic collapse or authoritarian lock-in." Substantial was anchored at 1–99 casualties and $1M–$100M; severe at up to one million deaths and $100M–$10B. The paper records that pilot testing found the original $10B lower bound for catastrophic financial loss too low, "because estimates already place current damage beyond that threshold," and that raising it to $100B left a gap between the severe and catastrophic financial bands.

Experts also rated seven actor types — general-purpose AI developer, specialized AI developer, AI deployer, AI infrastructure provider, AI governance actor, AI user, and affected stakeholder — and 14 industry sectors adapted from the North American Industry Classification System, on both vulnerability and, for actors, responsibility, each on a five-point scale. Vulnerability was defined as exposure plus sensitivity; responsibility as obligation, capability, and causal influence combined.

All three rounds ran in Qualtrics: Round 1 in September 2025 collecting initial ratings with optional qualitative rationales, Round 2 in October presenting aggregated Round 1 distributions and de-identified rationales for possible revision, and Round 3 in November repeating that process on Round 2 results. The five-year horizon runs to September 2030. The paper reports aggregated distributions and means rather than applying categorical consensus thresholds, on the stated ground that standard thresholds are not appropriate for continuous distributions. Data are posted at osf.io/pj2qr.

Findings

Severity under business as usual

The five risks with the highest mean severity under business as usual were dangerous capabilities, competitive dynamics, weapons and cyberattacks, power centralization, and false information. Table 1 of the paper reports mean severity on the 1–5 scale and mean catastrophic probability with bootstrapped 95% confidence intervals:

RiskMean severity (/5)Catastrophic probability, 2025–2030 [95% CI]
Dangerous capabilities3.4921.5% [16.9, 26.4]
Competitive dynamics3.4916.6% [12.0, 21.6]
Weapons and cyberattacks3.4921.0% [15.1, 27.5]
Power centralization3.4718.0% [12.1, 24.8]
False information3.4412.8% [8.9, 18.1]

The paper distinguishes the first and third of these: weapons and cyberattacks covers humans deliberately using or misusing AI as a tool, while dangerous capabilities covers harm from the capabilities themselves, which "can cause mass harm through misuse, through misalignment with human goals, or through other failures no one intended." It notes the two overlap in practice, and that the underlying taxonomy codes each risk into a single most-relevant domain rather than treating them as mutually exclusive.

Across all 24 risks, 18 were given at least a 10% probability of catastrophic outcomes. The paper reports that experts allocated substantial probability both to the catastrophic tail and to the substantial-to-severe middle range, which it reads as uncertainty about the magnitude of harm rather than about its occurrence.

Severity under pragmatic mitigations

Expected severity fell for all 24 risks under the mitigations scenario, by 0.36–0.53 points on the 1–5 scale with a median reduction of 0.44; paired Wilcoxon signed-rank tests were significant for all 24 after Holm correction (p adjusted < 0.001), with effect sizes r = 0.73–0.84. The largest absolute reductions were for dangerous capabilities (down 10 percentage points to 12%), weapons and cyberattacks (down 9 points to 12%), competitive dynamics (down 10 points to 7%), and AI misalignment (down 8 points to 9%).

Five risks remained above 10% catastrophic probability under mitigations: dangerous capabilities (12%), weapons and cyberattacks (12%), environmental harm (12%), inequality and unemployment (11%), and power centralization (11%). All 24 remained above 5%. The paper offers three candidate explanations for the larger reductions at higher baselines — greater perceived tractability, mitigations already underway, or mathematical headroom — and states that its design cannot distinguish them.

Vulnerability and responsibility

AI users and affected stakeholders were judged the most vulnerable actors, with median vulnerability ratings of 4–5 across nearly all 24 risks. AI infrastructure providers — entities supplying compute, cloud infrastructure, or training data — were judged least vulnerable, at a median of 2 across most risks, with the exceptions of environmental harm, weapons and cyberattacks, AI security vulnerabilities, and dangerous capabilities. Developers of both kinds fell in between at medians of 3–4, which the paper attributes to exposure to liability, reputational harm, and regulatory action rather than to direct harm.

Responsibility ran the other way. Affected stakeholders and users received median responsibility ratings of 2–3 despite being rated most vulnerable, while general-purpose AI developers received medians of 4–5 across nearly all 24 risks, as did governance actors — governments, regulators, and standards bodies. One quoted panelist argued that "Affected stakeholders lack both the agency and systemic leverage to mitigate risk, and assigning responsibility to them risks reinforcing harm by misplacing accountability"; another drew an analogy to social-media platforms in arguing that upstream actors are "the best point of intervention."

Consensus, defined as 90% of responses within ±1 of the median, concentrated at the extremes: 81% of "extremely vulnerable" cells reached consensus against 14% of "moderately vulnerable" cells.

Sector vulnerability and stated concerns

Experts rated the information and national security sectors most vulnerable across risks, with consensus on extreme vulnerability to content-related harms such as disinformation and loss of privacy for the former, and to dangerous capabilities and weapons and cyberattacks for the latter. Finance and insurance were rated similarly high on fraud and scams, AI security vulnerabilities, and AI system safety failures. Health care received a median of 4 on loss of privacy, discrimination, and overreliance and unsafe use. Sectors with lower AI penetration — accommodation and food services, agriculture and manufacturing, arts and entertainment — received medians of 2–3.

Asked separately to name the three domains they were most concerned about, with all experts seeing all 24 rather than only their own domains, the panel dispersed rather than converging: weapons and cyberattacks (26.8%), power centralization (23.5%), disinformation and influence (22.1%), loss of consensus reality (21.6%), and dangerous capabilities (21.6%). The paper flags that this ordering diverges from the severity ranking in places — overreliance and unsafe use ranked 8th on stated concern and 20th by severity — and suggests salience effects outside respondents' expertise, or concerns the severity rubric does not capture, as possible explanations.

AI welfare

Risk to AI welfare was surveyed but omitted from the paper's figures. None of the ten harm areas in the severity rubric treated AI systems as entities that could be harmed, and although survey guidance instructed experts to use the human and civil rights column adjusted for AI systems, qualitative responses confirmed they found the translation difficult. The paper cautions that the low ratings this item received should not be read as expert judgment that the risk is unimportant, and reports the data in supplementary materials only.

Stated interpretation

The paper observes that under common risk-governance frameworks a 10% probability of catastrophic outcome over five years "would be considered 'intolerable', likely triggering mandatory mitigation requirements," and argues that the magnitude of the estimates even under mitigations "suggests significantly more action is required to meet typical 'tolerable' thresholds."

On the vulnerability–responsibility divergence, it argues the pattern is standard in risk governance — the public is most vulnerable to aviation failures, pharmaceutical side effects, nuclear meltdowns, and environmental contamination while engineers, manufacturers, and regulators bear primary responsibility — but that in those industries the gap is bridged by mandatory standards, enforcement, liability regimes, and low societal risk tolerance, and that "comparable mechanisms for AI are nascent or absent. Without them, vulnerable parties have little recourse and responsible parties face little pressure to act."

Stated limitations

The paper devotes a substantial section to limitations, several of which bear directly on how its headline numbers should be read.

On calibration, it states that its panelists "are AI risk specialists, not forecasters with a track record of accurate predictions," and that domain experts in long-range forecasting research "often assign significantly higher probabilities to extreme outcomes than do superforecasters." It further notes that experts who self-nominate for AI risk surveys may be systematically more concerned than the broader expert population, and that respondents rated only their own sub-areas, "where they may have particularly heightened levels of concern." On composition, the panel was 68% male and 79% from Europe or North America.

The paper reports its aggregate judgments as "broadly consistent with estimates from forecasting platforms within an order of magnitude," while recording that direct comparison against forecasting tournaments is difficult because its catastrophic threshold is more lenient — one million deaths against 800 million in Karger et al. — and that those tournaments' estimates were correspondingly lower, at 0.01–0.35% by 2030. The introduction separately notes that forecasters in the Existential Risk Persuasion Tournament estimated roughly a 3% chance of human extinction from AI this century.

Three further limitations are stated. The 24-category taxonomy may mask distinctions within domains — weapons and cyberattacks "spans nation-state autonomous weapons programs and lone actors misusing off-the-shelf AI tools" — and forced distinct labels onto risks that overlap. The study measured severity, vulnerability, and responsibility but not the feasibility, effectiveness, cost, or side effects of mitigations, so its prioritization rests on perceived danger rather than on cost-benefit analysis, and a risk seen as catastrophic yet unmitigable would call for a different response than a moderate but easily fixed one. And agreement was uneven in a way the paper characterizes by type: vulnerability disagreement is "largely empirical" and in principle resolvable by evidence, responsibility disagreement is "largely normative," and severity disagreement was largest in the tails and in domains lacking historical base rates — AI welfare, misalignment, dangerous capabilities, power centralization.

A footnote states explicitly that the finding of ≥10% catastrophic probability across 18 domains "should not be interpreted as experts assessing a high probability that at least one catastrophic outcome will occur; this joint probability was not assessed, and catastrophic outcomes are likely correlated." Another states that the reported values "are panel means of subjective probability distributions elicited against our severity rubric, five-year horizon, and scenario framing; they summarize expert belief rather than calibrated real-world frequencies," and that 10% is used "as a descriptive reference level for comparing twenty-four distributions, not an objective threshold."

Funding and declarations

The work was supported by the Commonwealth Bank of Australia, which the paper states "reviewed the design, but did not influence the collection, analysis, interpretation or reporting of the data." The core research team declares no competing interests; the paper notes that some contributing authors who participated as panelists may hold positions in organizations with commercial or policy interests in AI, that all expert contributions were collected anonymously, de-identified, and reported only in aggregate, and that no authors with competing interests were involved in design or analysis. Large language models were used to assist with presentation and summarization of qualitative feedback, with analysis code, and with manuscript editing, with all content reviewed by the authors.

Provenance

Retrieved in full (94 pages) from the PDF linked on MIT FutureTech's publications page as a related publication of the AI Risk Repository. Figures 1 through 4 are images and were not retrieved; every figure-derived number recorded above comes from body text or from Table 1. The paper carries a June 2026 date on the publications page and is described as a working paper in the MIT Sloan press release of August 13, 2026 that brought it to wider attention (Source: mitsloan.mit.edu). The survey rounds themselves ran September through November 2025, so the estimates are anchored to expert belief as of late 2025 and the five-year horizon runs to September 2030 rather than from the publication date.

The MIT AI Risk Repository's public priorities page presents the same study with per-subdomain mean probabilities under business as usual (Source: airisk.mit.edu).

Relationships

  • supports: AI Existential Risk — a structured panel estimate over a fixed taxonomy, distinct from individual timelines and from model extrapolation.
  • supports: AI Safety Cases and Frameworks — the argument that a 10% five-year catastrophic probability would be treated as intolerable under standard risk-governance frameworks.
  • related: MIT AI Risk Initiative — the taxonomy and the repository the study is built on.
  • related: AI Liability — the vulnerability–responsibility separation and the absence of the liability mechanisms that bridge it in other safety-critical industries.
  • related: AI and Cybersecurity, AI Biosecurity — the weapons and cyberattacks domain, rated joint-highest on severity.
  • related: Track Record — dated, quantified forecasts against a stated horizon of September 2030.