Artificial intelligence presents business leaders with a difficult management problem: The risks are numerous and fast-moving and fall unevenly across organizations, sectors, and stakeholders. Some challenges are well known, like the potential for discrimination and the spread of misinformation, while others are emergent, like AI systems that could accelerate cyberattacks, make weapons development easier, or behave in ways that were never intended
A new study from MIT FutureTech and the University of Queensland offers a way to sort through that landscape. For “Prioritization of Risks From Artificial Intelligence,” a research team that included MIT Sloan School of Management principal research scientist asked 272 international AI experts to evaluate 24 AI risks based on their likelihood and severity of harm, and to note which sectors and actors are most vulnerable and who should bear responsibility for addressing the risks
The experts identified five risks — dangerous capabilities, competitive pressures, weapons and cyberattacks, concentrated power, and false information — as the most likely to produce the most severe harms over the next five years. The information and finance sectors are especially vulnerable, the experts said, and the people and organizations most vulnerable to risks are often not best positioned to address them.
“There are many AI risks,” said Peter Slattery, a research scientist with MIT FutureTech and one of the study’s co-authors. “One of the key things behind this work is trying to figure out who needs to do what differently, and in what sort of coordination.”
Understanding the most severe AI risks
The study used the Delphi method, a structured research process that gathers expert judgments over multiple rounds to move toward clearer areas of agreement and disagreement. The researchers used those expert assessments to evaluate risks over a five-year horizon, from 2025 to 2030, under two scenarios: business as usual, in which organizations and governments continue their current paths, and pragmatic mitigation, in which they make cost-effective efforts to reduce AI risks
Under the business-as-usual scenario, experts judged that 18 of the 24 AI risk domains had at least a 10% probability of catastrophic outcomes over the next five years. Catastrophic outcomes were defined as harms that include the potential for more than 1 million deaths, more than $100 billion in financial losses, or comparable civilizational-scale intangible damages
Pragmatic mitigation lowered those estimates but did not eliminate the risk. Even with cost-effective efforts to reduce harm, experts still judged five domains as having at least a 10% probability of catastrophic outcomes:
- AI systems possessing dangerous capabilities (12% probability)
- AI-enabled weapons, cyberattacks, or other mass-harm capabilities (12%)
- Environmental harm (12%)
- Inequality and unemployment (11%)
- Power centralization and unfair distribution of AI’s benefits (11%)
AI-enabled weapons and cyberattacks ranked high because AI is particularly well suited to coding and performing pattern recognition and information synthesis, Slattery said. Most modern infrastructure depends on software, which offers a large attack surface for systems that can help potential hackers identify vulnerabilities, generate code, or accelerate offensive cyber work
“AI is uniquely well equipped to attack those aspects of society and cause harm,” Slattery said. “Coding and hacking are some of the areas where we’re seeing the fastest growth in AI capability.”
Dangerous capabilities are broader: While malicious actors might use AI systems to do harm, advances in those systems could also make it easier to perform difficult, dangerous tasks, such as engaging in persuasion and surveillance, creating deepfakes, and even assisting with building chemical or biological weapons. “These are all things that you could previously do but now could do much more easily,” Slattery said.
Competitive dynamics are different: They’re not a single harmful use of AI but a condition that can intensify other risks. When companies or countries believe that AI will confer major economic or strategic advantage, they may have incentives to move quickly, resist constraints, or underinvest in safety. “This is an instrumental risk that creates other risks,” Slattery said.
Where AI risk may hit the hardest, and who is responsible
The study also points to three sectors that the experts indicated are most vulnerable to AI risk over the next five years: information, national security, and finance. Leaders in those sectors should understand that their exposure is not generic, Slattery said. Each sector is vulnerable in different ways because of its specific characteristics
- Information sector: Risks are closely tied to the flow of content and data, including misinformation, disinformation, privacy loss, manipulation, and the erosion of trust in what people see and read.
- National security: The biggest concerns include cyberattacks, weapons development, surveillance, and the use of increasingly capable AI systems by hostile actors.
- Finance: AI could amplify fraud, cyber risk, market manipulation, privacy breaches, and failures in systems that have broader economic effects.
Across those sectors, AI can make existing risks easier to scale, Slattery said. People who could not previously hack may now be able to do “a range of things related to hacking, while those who can already hack may do things faster or better or more easily,” he said.
The experts said that AI developers and governance actors, such as governments and regulators, have the primary responsibility for addressing AI risks. But AI system users and the stakeholders such systems affect are most vulnerable to those risks. Given that those who are most responsible for addressing risks are not those who are most vulnerable, there are misaligned incentives for taking action.
Artificial Intelligence for Financial Services
Register Now
What leaders should do now
Slattery said the research isn’t intended to predict the future with certainty but to help leaders focus on the AI risks that experts believe are both serious and plausible in the near term. “We’re not saying these things are definitely going to happen,” he said. “We’re saying these are the things that experts think are worth paying attention to now.”
For business leaders, the top risks point to two immediate questions: what increasingly capable AI systems can now do, and whether competitive pressure is pushing organizations to deploy them faster than their governance practices can be updated. The concern is that companies, sectors, and governments may feel pressure to move quickly even when the risks are not fully understood
That’s what makes the findings especially useful for business leaders, Slattery said, especially considering that many organizations are still treating AI risk as either a compliance issue or distant concern. Leaders should evaluate AI at the business process level, looking at where it could create return on investment, where it could change the broader ecosystem, and whether it could disrupt the products or services their organization provides
Executives should start by recognizing that AI risk is not business as usual. Slattery cautioned against abandoning what already works but said that leaders should treat AI as a new paradigm that could replace many human tasks, introduce new vulnerabilities, and create “ecosystem-wide, society-wide opportunities and vulnerabilities.”
The response can’t be just a one-time adjustment, either. “It’s continuous and constant from now on because AI is moving so quickly that organizations need to be significantly more attentive and responsive to this technology and the related risks and opportunities than they have been with previous technologies,” Slattery said
The larger message is that organizations do not need to wait for perfect forecasts or regulations before acting, Slattery said. They can begin by paying closer attention to the most severe and likely harms, and by making AI risk part of the same governance conversations they’re already having around cybersecurity, privacy, safety, and business continuity.
Explore the findings about AI risks prioritization from the MIT AI Risk Initiative
“Prioritization of Risks From Artificial Intelligence” has 188 co-authors, with a core research team of Alexander K. Saeri, Jess Graham, Michael Noetel, Peter Slattery, and Neil Thompson
The research is part of the MIT AI Risk Initiative by the MIT FutureTech lab. MIT FutureTech is an interdisciplinary group affiliated with the MIT Sloan School of Management and the MIT Computer Science and Artificial Intelligence Lab that studies the economic and technical foundations of progress in computing
The MIT AI Risk Initiative aims to provide authoritative data and frameworks to help identify, prioritize, and manage the risks from AI. It includes the AI Risk Repository, a continuously updated database of more than 1,600 AI risks organized by cause and risk domain that is used by policymakers, technologists, and organizations to inform AI governance
Neil Thompsonis a principal research scientist at theMIT Computer Science and Artificial Intelligence Laboratoryand theMIT Initiative on the Digital Economy, where he is head of the Artificial Intelligence, Quantum and Beyond research group. He is also the director of theMIT FutureTechlab
Peter Slatteryis a research scientist at MIT FutureTech. He works on the MIT AI Risk Initiative, which includes the MIT AI Risk Repository. Building on that initiative, he is now working on the AI Risk Index, which will pinpoint important risk-response gaps by comparing expert recommendations on best-practice AI risk management against what model developers, enterprises, and governance bodies are actually doing in practice
Alexander K. Saeriis a researcher at MIT FutureTech, where he directs the MIT AI Risk Initiative, as well as a senior research project manager at the University of Queensland. He uses a mix of applied behavioral science and social science methods to understand and address complex challenges, including the governance of AI. He has expertise in implementation science, the scale-up of effective interventions, group processes, systems thinking, and sociotechnical transitions
Jess Grahamis a senior research coordinator at the University of Queensland and a researcher at MIT FutureTech, where she works on the MIT AI Risk Initiative. Her current work is focused on improving efforts to classify and address risks from AI. She uses applied social science to make risks from advanced AI comparable and governable, with the aim of preventing large-scale harm
Michael Noetelis a senior researcher with the MIT AI Risk Initiative, a research affiliate at MIT FutureTech, and an associate professor at the University of Queensland. He works at the intersection of psychology, evidence synthesis, and AI governance, with a mission to reduce the worst risks from advanced AI.
For more infoSara BrownSenior News Editor and Writersbrown1@mit.edu

Ideas Made to Matter5 ways to make agentic AI a competitive advantage
Ideas Made to MatterWho will own the AI agent economy?
Ideas Made to Matter5 investments to close the gap between AI wealth and welfare


