"A Taxonomy of Systemic Risks from General-Purpose AI" is a November 2024 academic paper (arXiv:2311.14641) that systematically reviews the literature on systemic risk from general-purpose AI and organizes it into 13 risk categories and 50 contributing sources of risk. It was written by Uuk, Gutierrez, Guppy, Lauwaert, Kasirzadeh, Velasco, Slattery, and Prunkl, with affiliations spanning the Future of Life Institute, KU Leuven, Google Research, the Alan Turing Institute, Oxford Martin, MIT FutureTech, and Utrecht University. The taxonomy adopts the EU AI Act's definition of systemic risk and was designed to inform compliance under that framework.
Method and scope
The paper is a systematic review of 1,781 documents, of which 86 were selected after screening. The authors describe the result as the first comprehensive academic taxonomy of systemic risks from general-purpose AI. The review follows the EU AI Act's definition of systemic risks as "large-scale threats that can affect entire societies or economies," linking the academic risk mapping to the EU regulatory framework.
The 13 risk categories
| Category | Description |
|---|---|
| Control | AI acting against human interests due to misalignment, loss of control, or rogue AI scenarios |
| Democracy | Erosion of democratic processes and public trust in social/political institutions |
| Discrimination | Creation, perpetuation, or exacerbation of inequalities and biases at large scale |
| Economy | Large labor market impacts, exacerbated wealth inequality, financial instability, labor exploitation |
| Environment | Climate change impact, energy consumption, pollution |
| Fundamental rights | Large-scale erosion or violation of human rights and freedoms |
| Governance | Regulatory and oversight failures due to AI complexity and rapid evolution |
| Harms to non-humans | Large-scale harms to animals; development of AI capable of suffering |
| Information | Influence on communication systems and epistemic processes; misinformation |
| Irreversible change | Profound long-term changes to social structures, cultural norms, human relationships |
| Power | Concentration of military, economic, or political power among AI-controlling entities |
| Security | International/national security threats: cyber warfare, arms races, geopolitical instability |
| Warfare | AI amplifying nuclear, chemical, biological, and radiological weapon effectiveness |
The 50 sources of systemic risk
Alongside the categories, the paper identifies 50 recurring sources that drive systemic risks. Key examples include complexity-induced knowledge gaps, in which the opacity of AI networks prevents understanding of failure modes; challenges in perceiving harm, where harms accumulate gradually or are diffuse across populations; cumulative effects of AI practices, where individually benign decisions compound into systemic harm; unclear attribution of responsibility, where distributed deployment chains obscure liability; and governance framework limitations, where regulation lags capability development. Among the technical factors identified are opaque networks, rapid operational speeds, and evolving capabilities enabling human substitution.
Comparison with other risk frameworks
The taxonomy can be mapped against other frameworks, including Hendrycks' Introduction to AI Safety and Amodei's "Adolescence" essay:
| Risk Area | Hendrycks (Intro to AI Safety) | Amodei (Adolescence) | This Taxonomy |
|---|---|---|---|
| Autonomous AI | Rogue AIs, power-seeking | AI autonomy risk | Control |
| Bioweapons | Malicious use (bioterrorism) | AI biosecurity | Warfare |
| Authoritarianism | Concentration of power | AI and authoritarianism | Power |
| Labor disruption | — | AI labor disruption | Economy |
| Race dynamics | AI race | (implicit) | Governance |
| Democracy/misinformation | Persuasive AIs | Indirect effects | Information, Democracy |
| Environment | — | — | Environment (unique) |
| Non-human harm | — | — | Harms to non-humans (unique) |
Relative to Amodei's and Hendrycks' frameworks, the taxonomy covers environmental harm and non-human harms as distinct categories, two areas the authors note receive little attention in the policy debate. The International AI Safety Report 2025, chaired by Bengio, offers a compressed governmental counterpart with a three-category risk taxonomy (malicious use, malfunctions, systemic risks) against this 13-category academic taxonomy.
Relation to policy
The paper was designed to inform EU AI Act compliance guidance. The GPAI Systemic Risk Threshold of 10^25 FLOP in the EU AI Act points toward this taxonomy as a framework for identifying what "systemic risk" means in practice, and providers of GPAI models with systemic risk must demonstrate how they assess and mitigate the categories the taxonomy sets out.
Relationships
- related: EU AI Act — taxonomy follows EU Act definitions; informs GPAI systemic risk compliance obligations
- related: AI Autonomy Risk — the "Control" category maps directly; the 50 sources include opacity and oversight limitations
- related: AI and Authoritarianism and AI Race Dynamics — the "Power" and "Security" categories
- related: AI Labor Disruption — the "Economy" category
- related: AI Environmental Impact — the "Environment" category
- related: Open Problems in Technical AI Governance — complementary mapping of governance gaps
- related: International AI Safety Report 2025 — compressed governmental counterpart taxonomy