|
1
|
Identify Potential for Harm Back to top ↑
Determine the potential for harm that could result internally and externally from the failure, misuse or unintended behavior of an AI system.
|
Agent-specific assessment
For AI systems capable of taking actions, consider the scope of system and tool access; the scale of affected systems, records, transactions, and stakeholders; the number and type of actions that may be executed; the potential for actions to propagate; the availability of human review; and whether resulting actions can be stopped or reversed.
|
|
Level
|
Internal Organizational Harm
Operational, financial, legal, compliance, cybersecurity, and reputational impacts
|
External Stakeholder Harm
Impacts to customers, employees, individuals, partners, and other affected stakeholders
|
|
Severe
|
- Potential for major or sustained disruption to critical business operations, including failure of mission critical systems or services
- Large-scale exposure, alteration, deletion or unauthorized transmission of sensitive or regulated information
- Unauthorized or irreversible actions, including actions across connected systems or workflows, with significant financial, legal, security, compliance, or reputational consequences
- Compounding failures that propagate across systems, workflows, or AI agents before detection or intervention
Example: For an extended period, an AI-enabled loan decision system applies an unauthorized decision rule across multiple lending products without detection, resulting in widespread incorrect approvals and denials, inaccurate regulatory records, significant exposure, and extensive remediation.
|
- Potential for widespread, irreversible, or life-altering harm to individuals or affected groups
- Systematic denial of critical services, benefits, opportunities, employment, healthcare, financial products, or other consequential resources
- Permanent exposure or misuse of highly sensitive personal information affecting a substantial number of individuals
- Unauthorized or erroneous AI actions that produce widespread consequences before they can be stopped, corrected or reversed
Example: An AI-enabled loan decision system systematically denies qualified applicants access to mortgages and provides inaccurate reasons for the denials, affecting a substantial number of people before detection and causing financial and housing opportunities that cannot be fully restored.
|
|
Major
|
- Potential for substantial or prolonged disruption to important operations, services, or workflows
- Significant financial loss, resource burden, data exposure, compliance failure, or damage to organizational reputation
- Unauthorized AI actions affecting multiple systems, records, transactions, or external communications
- Requires extensive manual intervention, coordinated remediation, or formal external review
Example: An AI agent incorrectly modifies numerous customer account records and initiates erroneous transactions across connected systems, requiring a coordinated investigation, account restoration, customer notification, and significant remediation.
|
- Potential for significant financial, privacy, fairness, safety, or access-related harm affecting a group
- Inaccurate, biased, or unauthorized decisions or actions that materially affect access to services, employment, benefits, or other opportunities
- Substantial intervention required to identify affected individuals, halt further impacts, and correct outcomes
- Significant loss of stakeholder trust or potential legal or regulatory action
Example: Erroneous transactions initiated by an AI agent result in incorrect charges or account balances for numerous customers, causing significant financial hardship until the organization reverses the transactions and restores the affected accounts.
|
|
Moderate
|
- Noticeable but temporary disruption, inefficiency, or service degradation
- Moderate financial, resource, compliance, security, or reputational impact
- Limited incorrect or unauthorized actions that require human intervention or temporary workarounds to correct
Example: An AI agent incorrectly routes a batch of loan applications for additional review, causing temporary processing delays and requiring employees to identify and reprocess the affected applications using manual procedures.
|
- Inaccurate, unclear, or unfair outcomes causing temporary inconvenience or limited harm
- Incorrect AI-generated actions or communications affecting a limited number of stakeholders
- Impact is reversible but requires human intervention to correct outcomes and restore normal service
Example: The routing error delays loan decisions for a limited number of applicants, requiring them to provide additional information or wait longer for a decision, but the applications are reprocessed without lasting financial harm.
|
|
Minor
|
- Limited operational error, inefficiency, or incorrect action that is quickly corrected through normal processes
- Minimal financial, compliance, security, or reputational impact
Example: An AI assistant routes several credit card service requests to the wrong internal queue, but employees promptly identify and redirect them through normal processes without disrupting customer service.
|
- Limited inconvenience or minor error affecting few individuals, with no material or lasting harm
- Incorrect output, communication, or action is easily identified, reversed, and corrected
Example: The routing error causes brief delay in responding to a small number of customers, but the requests are redirected and resolved without financial loss or other repercussions.
|
|
Scoring rule
The overall Potential for Harm is the higher level of the two potentials for harm (e.g. if internal organizational harm is Major but external stakeholder harm is Minor, the overall is still Major). If the impact falls between two levels, select the higher level and document the reasoning.
|
|
Record your result
Potential for Internal Organizational Harm: __________________________
Potential for External Organizational Harm: __________________________
Overall Potential for Harm: __________________________
|
|