0 cumulative citations
View corpus contextA wide-ranging review finds nine core domains of AI misuse and concludes that attackers currently hold persistent advantages over defenses; existing technical and regulatory measures leave substantial gaps, particularly around LLM vulnerabilities and socioeconomic harms.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
0 cumulative citations
View corpus contextThe swift evolution of artificial intelligence (AI) has enabled unprecedented capabilities across domains, while simultaneously introducing critical vulnerabilities that can be maliciously exploited or cause unintended harm. Although multiple initiatives aim to govern AI-related risks, a comprehensive and systematic understanding of how AI systems are actively misused in practice remains limited. This paper presents a systematic review of AI misuse across modern AI technologies. We analyze documented incidents, attack mechanisms, and emerging threat vectors, drawing from existing AI risk repositories, prior taxonomies, and empirical case reports. These sources are synthesized into a unified analytical framework that categorizes AI misuse across nine primary domains. Our analysis identifies nine major domains of AI misuse: (1) Adversarial Threats, (2) Privacy Violations, (3) Disinformation, Deception, and Propaganda, (4) Bias and Discrimination, (5) System Safety and Reliability Failures, (6) Socioeconomic Exploitation and Inequality, (7) Environmental and Ecological Misuse, (8) Autonomy and Weaponization, and (9) Human Interaction and Psychological Harm. Within each domain, we examine distinct misuse patterns, providing technical insights into exploitation mechanisms, documented real-world cases with quantified impacts, and recent developments such as large language model vulnerabilities and multimodal attack vectors. We further evaluate existing mitigation strategies, including technical security frameworks (e.g., MITRE ATLAS, OWASP Top 10 for Large Language Models, MAESTRO), regulatory initiatives (e.g., EU AI Act, NIST AI Risk Management Framework), and compliance standards. The findings reveal substantial gaps between the rapid advancement of AI capabilities and the robustness of current defensive, governance, and mitigation mechanisms, with adversaries holding persistent advantages across most attack categories. This work contributes by (i) systematically consolidating fragmented AI risk repositories and misuse taxonomies, (ii) developing a unified taxonomy grounded in both theoretical models and empirical incident data, (iii) critically assessing the effectiveness of existing mitigation approaches, and (iv) identifying priority research gaps necessary for advancing more secure, ethical, and resilient AI systems.
Summary
Main Finding
The paper produces a comprehensive, empirically grounded synthesis of AI misuse, consolidating fragmented taxonomies and incident repositories into a unified nine‑domain taxonomy. It finds that AI misuse is widespread across technical and socio‑economic realms, that adversaries retain persistent advantages across most attack categories, and that existing defensive, governance, and mitigation mechanisms (technical and regulatory) are insufficiently mature—creating large unresolved economic externalities and regulatory/market frictions.
Key Points
- Unified nine‑domain taxonomy of AI misuse:
- Adversarial Threats (e.g., evasion, poisoning, supply‑chain attacks)
- Privacy Violations (reconstruction, membership inference, biometric misuse)
- Disinformation, Deception & Propaganda (deepfakes, synthetic media, LLM‑driven campaigns)
- Bias & Discrimination (algorithmic unfairness in health, finance, justice)
- System Safety & Reliability Failures (safety‑critical adversarial failures)
- Socioeconomic Exploitation & Inequality (automation harms, manipulation, labor impacts)
- Environmental & Ecological Misuse (energy footprint, abuse of environmental models)
- Autonomy & Weaponization (autonomous weapons, escalatory risks)
- Human Interaction & Psychological Harm (manipulation, dependency, emotional abuse)
- Empirical grounding: synthesizes academic literature, industry reports, and incident repositories (e.g., MIT AI Risk Repository, MITRE ATLAS, OWASP LLM Top 10, AI Incident Database, OECD AI Incident Monitor, AGILE Index).
- Documented impacts cited (representative): deepfake‑enabled fraud (>$25M), large‑scale disinformation affecting elections, wrongful arrests from facial recognition, algorithmic discrimination with large population impacts; adversarial attacks on safety‑critical systems.
- Evaluated mitigation instruments: technical security frameworks (MITRE ATLAS, OWASP for LLMs, MAESTRO), and regulatory frameworks (EU AI Act, NIST AI RMF). Conclusions: partial coverage, uneven adoption, gaps in technical detail, enforcement, and cross‑jurisdictional harmonization.
- Key conclusion: there is a durable mismatch between rapidly improving AI capabilities and lagging detection, governance, and market incentives to prevent misuse.
Data & Methods
- Method: systematic literature and incident review synthesizing technical papers, security taxonomies, policy documents, and incident repositories into an integrated analytic framework.
- Sources: academic literature (LLM, generative AI, adversarial ML, socio‑technical studies), industry/regulatory taxonomies (MIT AI Risk Repository, AIR 2024, Foundation Model Risk Taxonomy), security knowledge bases (MITRE ATLAS, ENISA), LLM security guidance (OWASP Top 10 for LLMs), and incident databases (AI Incident Database, AIAAIC, OECD Monitor, AGILE Index).
- Scope/timeframe: cross‑cutting coverage of modern AI technologies with incident data spanning approximately mid‑2010s through 2024–25 (paper received 2025, published 2026).
- Analytic steps: map documented incidents and attack mechanisms to thematic categories; extract technical exploitation patterns and quantify (when available) economic or social impacts; assess mitigation frameworks against the taxonomy to identify coverage and gaps.
- Limitations acknowledged by authors: heterogeneity and incompleteness of public incident reporting; variable technical granularity across sources; emergent threats that may be underreported or not yet codified in regulation.
Implications for AI Economics
- Externalities and market failures
- Many misuse harms (privacy breaches, disinformation, safety failures) create negative externalities that individual deployers do not fully internalize, justifying public intervention and coordination.
- Underreporting of incidents and measurement gaps make private markets ill‑informed about expected harm, impairing efficient risk pricing.
- Insurance, liability, and risk markets
- Adversary advantage and asymmetric information complicate actuarial pricing of cyber/AI insurance; insurers may face correlated risks and tail exposures (e.g., large‑scale disinformation, systemic model failures).
- Ambiguities in liability (model providers vs deployers vs data suppliers) increase transaction costs and can concentrate liability on smaller actors or shift risk to public sector.
- Investment, innovation and competitive dynamics
- Compliance and mitigation costs (technical safeguards, audits, compute for safety testing, insurance premiums) raise barriers to entry and may favor large incumbents with resources—potentially increasing market concentration.
- Conversely, unmet safety needs create market opportunities for firms specializing in verification, monitoring, red‑teaming, provenance, and secure model supply chains.
- Regulatory fragmentation (e.g., differing EU/US/China regimes) can distort global competition and influence locus of AI R&D and deployment.
- Labor, distributional effects and welfare
- Socioeconomic exploitation and automation risks can exacerbate inequality; harms from algorithmic discrimination can impose large welfare costs (health, credit, employment).
- Costs of remediation (litigation, compliance, retraining) will be borne unevenly across sectors and populations, impacting social welfare assessments of AI deployment.
- Adoption, diffusion, and demand
- Evidence of high‑profile misuse may reduce trust and slow adoption in sensitive sectors (healthcare, justice), lowering aggregate welfare benefits from AI.
- Conversely, cheap and accessible misuse tools (e.g., LLMs for phishing) increase the social cost of AI diffusion.
- Public goods and governance economics
- Need for public‑good investments: standardized incident reporting, open vulnerability databases, shared benchmarks for safety, and independent auditing capacity—markets underprovide these.
- Harmonized regulation and internationally coordinated norms can reduce cross‑border arbitrage and mitigate asymmetric risks to global public goods (e.g., democratic processes, biosafety).
- Cost‑benefit and policy design considerations
- Policymakers require better econometric estimates of incidence rates, damages, and mitigation efficacy to design optimal regulation (e.g., how strict liability, mandatory audits, or certification should be).
- There is a trade‑off between innovation incentives and precautionary rules; economic analysis should quantify dynamic effects (R&D, diffusion, first‑mover advantage) of safety regulation.
- Research & market gaps the paper highlights (economics‑relevant)
- Empirical quantification of social costs of different misuse types (monetary and non‑monetary).
- Models of adversary incentives and market structure for misuse (cybercrime as a service, black‑market models).
- Insurance market design under correlated AI risks and ambiguity.
- Welfare analysis of regulatory regimes (comparing prescriptive rules, outcome‑based liability, and market instruments).
- Cost‑effectiveness studies of technical mitigations and certification regimes.
- Distributional analysis of compliance burdens across firms and countries.
Overall, the review implies that AI economics must incorporate the heterogeneous and systemic nature of AI misuse into models of firm behavior, market structure, regulation design, insurance, and social welfare—moving beyond productivity‑only assessments to include persistent negative externalities, measurement challenges, and the public‑goods character of safety infrastructure.
Assessment
Claims (8)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| This paper identifies nine major domains of AI misuse: (1) Adversarial Threats, (2) Privacy Violations, (3) Disinformation, Deception, and Propaganda, (4) Bias and Discrimination, (5) System Safety and Reliability Failures, (6) Socioeconomic Exploitation and Inequality, (7) Environmental and Ecological Misuse, (8) Autonomy and Weaponization, and (9) Human Interaction and Psychological Harm. Ai Safety And Ethics | positive | categorization of AI misuse domains |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The analysis draws on documented incidents, attack mechanisms, and emerging threat vectors from existing AI risk repositories, prior taxonomies, and empirical case reports to produce the unified framework. Ai Safety And Ethics | positive | breadth and provenance of evidence supporting the taxonomy |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Within each domain the paper examines distinct misuse patterns, provides technical insights into exploitation mechanisms, documented real-world cases with quantified impacts, and recent developments such as large language model vulnerabilities and multimodal attack vectors. Ai Safety And Ethics | positive | coverage of misuse patterns and vulnerability types (including LLM and multimodal attacks) |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The paper evaluates existing mitigation strategies, including technical security frameworks (e.g., MITRE ATLAS, OWASP Top 10 for Large Language Models, MAESTRO), regulatory initiatives (e.g., EU AI Act, NIST AI Risk Management Framework), and compliance standards. Governance And Regulation | positive | evaluation of mitigation strategies and regulatory initiatives |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Findings reveal substantial gaps between the rapid advancement of AI capabilities and the robustness of current defensive, governance, and mitigation mechanisms. Ai Safety And Ethics | negative | mismatch between AI capability advancement and defensive/governance robustness |
Reading fidelity
high
Study strength
medium
|
not reported
|
| Adversaries hold persistent advantages across most attack categories. Ai Safety And Ethics | negative | relative advantage of adversaries versus defenders across attack categories |
Reading fidelity
high
Study strength
medium
|
not reported
|
| The paper contributes by (i) consolidating fragmented AI risk repositories and misuse taxonomies, (ii) developing a unified taxonomy grounded in theoretical models and empirical incident data, (iii) critically assessing the effectiveness of existing mitigation approaches, and (iv) identifying priority research gaps for more secure, ethical, and resilient AI systems. Ai Safety And Ethics | positive | scholarly contributions (consolidation, taxonomy development, assessment, gap identification) |
Reading fidelity
high
Study strength
medium
|
not reported
|
| A comprehensive and systematic understanding of how AI systems are actively misused in practice remains limited prior to this work. Ai Safety And Ethics | negative | state of the literature (comprehensiveness and systematic understanding of AI misuse) |
Reading fidelity
high
Study strength
low
|
not reported
|