Pith. sign in

REVIEW 3 major objections 6 minor 64 references

Developing a Risk Identification Framework for Foundation Model Uses

T0 review · 3 major / 6 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read This paper argues that a foundation model's use—not the model alone—should decide which risks are relevant, and it proposes a questionnaire-based framework that maps risks to entities and development stages to put that principle into…

desk verdict A useful design-requirements synthesis for use-based FM risk identification, with the central requirement demonstrated only partially; worth reviewing, but the candidate framework needs to show use changing the flagged risks. read the letter →

arxiv 2506.02066 v1 pith:LRBKN3SN submitted 2025-06-01 cs.CR

classification cs.CR
keywords foundationmodelsriskidentificationusagegovernanceAItaxonomyassessmentquestionnairemodelusepotential
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Foundation model risk taxonomies list many possible harms, and benchmarks measure a model's susceptibility to some of them, but neither tells a practitioner which risks actually matter for a given use. This paper claims that use should be the deciding lens: the same model used to summarize a movie review carries different risks than one used to summarize a legal contract. It synthesizes four design requirements for a risk identification framework—covering every entity of the AI system, letting use contextualize risk, mapping risks to entities and lifecycle stages, and staying usable by non-experts—and demonstrates an initial design as three questionnaires deployed at different stages. If the approach holds, practitioners can start from a description of their use and arrive at a shortlist of potential risks to investigate before deployment, reusing risk profiles across contexts.

What carries the argument

The load-bearing mechanism is the risk-to-entity and risk-to-stage mapping. Each risk is attached to one or more of the six usage-governance entities (use case, use, context, data, model, prompt) and to a stage of the development lifecycle; the paper identifies the use definition, model procurement, and implementation stages for its five selected risks. A risk's conditions for being 'potential' are turned into questionnaire questions, and the questionnaires are administered to the role most knowledgeable at that stage. The four design requirements—Entity Risks, Use Contextualizes Risk, Risk Mapping, and Usability—are the constraints the mechanism must satisfy, and the payoff is that entity risk profiles can be reused when a model moves to a new use or context.

What would settle it

Take a held-out set of foundation-model risks from a broad taxonomy, construct uses that should trigger those risks, run the three questionnaires, and check whether they flag the risks; if the questionnaires systematically miss risks that a full expert assessment would identify, then the five-risk, three-stage mapping is not generalizable.

Watch

Extended reading notes

Core claim

The central claim is that a risk identification framework for foundation models must be organized around use, not around the model or the taxonomy alone. The paper establishes four design requirements: risks should be considered across all entities (use case, use, context, data, model, prompt); the use of the system should determine which risks are relevant; risks need to be mapped to the entities and development-lifecycle stages where they can be identified; and the framework must be usable by people who may know little about AI risks. To show feasibility, the paper builds a candidate framework by taking five risks from an existing taxonomy—hallucination, toxic output, susceptibility to prompt injection, model usage restrictions, and personal information in data—and having a panel of AI risk researchers map each risk to entities and stages, state conditions under which the risk becomes a potential risk, and convert those conditions into questionnaire questions at three stages: use definition, model procurement, and implementation. An illustrative example of a visitor-center question-answering agent shows how answers to the questionnaires flag toxic output, prompt-injection susceptibility, and usage-rights violations as potential risks for later review.

Load-bearing premise

The framework's coverage rests on mappings built from only five risks and three development stages, so if that small sample is not representative of the full space of foundation model risks, the three questionnaires will omit relevant risks.

Editorial extensions

If this is right

  • Practitioners can move from a use description to a shortlist of potential risks to investigate, rather than confronting dozens-to-thousands of catalogued risks at once.
  • Risk profiles for entities are reusable: the same model in a different use and context keeps its identified model risks, so reassessment focuses on the new use and context.
  • The questionnaires assign risk identification to the right role at the right stage: product owners and domain experts answer use-definition questions, while data scientists answer model-procurement and implementation questions.
  • When model documentation is silent about a risk (for example, no record of toxicity screening), the framework flags that risk as potential rather than assuming it is absent, shifting the decision to the organization's risk tolerance.
  • Contextual questions about users, affected people, and deployment accompany the risk-flagging questions, giving later reviewers the information they need to judge relevance.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Extending the paper's decomposition, the entity-to-risk mapping could double as a benchmark selector: once a model's risk profile is known, the corresponding quantitative benchmarks are the ones that should be run, linking risk identification to measurement.
  • The same questionnaires could be automated or pre-screened with a language model so that an organization triages many proposed uses before human review; the paper only mentions a conversational agent as one possible usability aid.
  • Because the framework deliberately excludes risks that do not map to system entities (societal, compliance, and environmental impacts), a full governance process would need a complementary identification mechanism for those risks, which the paper leaves to future work.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper addresses the lack of guidance for identifying which risks are relevant to a given foundation model use. Drawing on the notion of usage governance, it formulates four design requirements for a risk identification framework: (1) risks should be considered across the entities of an AI system, (2) use should contextualize which risks matter, (3) risks should be mapped to entities and development stages, and (4) the framework should be usable by non-experts. The authors then present a candidate framework consisting of three staged questionnaires for a small subset of five risks (hallucination, toxic output, prompt injection susceptibility, usage restrictions, and personal information in data) and illustrate it with a visitor-center question-answering agent example. The paper is explicitly positioned as formative work: it claims to deliver requirements and an initial design rather than a fully validated framework.

Significance. The conceptual contribution is useful and timely: it identifies a real gap between risk taxonomies and risk benchmarks, and it translates usage-governance ideas into concrete design requirements. The four requirements give practitioners and researchers a sensible checklist, and the paper is unusually transparent about how the candidate framework was constructed from expert conditions and benchmarks. Its main strength is the clarity of the framing. However, the demonstration that the candidate framework actually instantiates the requirements is only partial. In particular, the questionnaires do not contain any use-dependent triggering conditions, so the paper's central requirement that 'use should decide which risks matter' is not operationalized. The evidence base for the risk-to-stage and risk-to-entity mappings is also thin, being based on a five-person panel including an author with no inter-rater reliability or external validation. These are load-bearing gaps rather than presentation issues, but they are addressable in a revision. As a formative design study, the paper merits publication after substantive revision.

major comments (3)
  1. [§5.1.1, Table 2] The candidate framework does not instantiate design requirement #2 ('Use Contextualizes Risk'). All fourteen expert conditions, including the two quoted for hallucination, are formulated in terms of training-data characteristics, input provenance, or model properties; none reference task-specific properties of the use such as required factual accuracy, domain criticality, or the consequence of a wrong output. Consequently, the questionnaires would flag hallucination as a potential risk for the creative-writing brainstorming use that Section 1 gives as the paradigm case in which hallucination is 'perhaps irrelevant,' and they cannot distinguish legal-contract summarization from low-stakes movie-review summarization. Section 5.1.3 concedes that the questionnaire 'does not help determine which risks are relevant' and defers that determination to an unspecified human review. If use is to decide which risks matter, the flagging conditions must include use-dependent triggers (for example, questions about acceptable error rates or output stakes), and the demonstration should show that the visitor-center and brainstorming examples yield different risk sets for the same model.
  2. [§5.1.1] The risk-to-stage and risk-to-entity mappings rest entirely on a panel of five AI risk researchers, one of whom is an author, with no inter-rater reliability statistic, no elicitation protocol, and no external validation. The paper reports that the panel produced fourteen conditions for five risks and mapped them to three development stages, but the selection process for the five risks is not justified, and the paper itself notes that including other risks might have added stages. Because these mappings are the substantive content of the proposed questionnaires, the generalizability of the framework is not established. At minimum, the paper should report the elicitation instrument and coding procedure, agreement measures among the panelists, and a sensitivity check with at least one independent taxonomy.
  3. [§4.3 and §5.1.1] The demonstration selects IBM's AI Risk Atlas as the taxonomy, one whose authors include two of the present authors, and the panel that creates the mappings also includes an author. The paper states that the framework can start with any suitable taxonomy, but the self-referential choice makes the illustration partly self-confirmatory. To make the taxonomy-agnostic claim credible, the authors should apply the same elicitation process to an independent taxonomy (for example, the MIT AI Risk Repository) and show how the conditions and questionnaire structure change, or at least transparently discuss the conflict-of-interest and its potential effect on the mappings.
minor comments (6)
  1. [Abstract] The sentence 'demonstrate how a candidate framework can addresses these design requirements' contains a subject-verb agreement error ('can addresses' should be 'can address').
  2. [§3.1.9] The phrase 'has the potentially to overwhelm' should read 'has the potential to overwhelm.'
  3. [Table 2, row B4] The phrase 'the the model' contains a duplicated definite article; it should read 'the model.'
  4. [§2] The sentence 'Arda [2] discuses the translation' has a typo; 'discuses' should be 'discusses.'
  5. [§4.3] The phrase 'if a entity exists' should be 'if an entity exists.'
  6. [§5.1.1 and Table 2] The questionnaire names in the text ('use definition stage,' 'model procurement stage,' 'implementation stage') do not match the table headers ('Use Questionnaire,' 'Model Onboarding Questionnaire,' 'Use and Model Questionnaire'); the naming could be harmonized to improve readability.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation: the design is explicitly formative, and the self-cited taxonomy is acknowledged as a replaceable starting point rather than a forced premise.

full rationale

The paper makes no derivational claim that reduces to its own inputs. The four design requirements are synthesized from external governance sources (EU AI Act, NYC Local Law 144, NIST, prior questionnaires) and from the paper's own usage-governance decomposition; the latter is a conceptual framing, not a fitted or predicted quantity. The candidate questionnaires are explicitly constructed from expert-panel conditions, and Section 6's example is an illustration of that construction, not an independent prediction: the questionnaire is derived from the same conditions it is shown to trigger. The choice of IBM's AI Risk Atlas [5] is a self-citation, but Section 5.1 states 'This process can start with any suitable taxonomy of AI risks,' so the Atlas is a replaceable design input, not a load-bearing cited theorem. The panel includes an author, but the five-risk mapping is presented as expert elicitation for an 'initial design,' with acknowledged scope limits (Section 5.1.1: 'Including other risks may have resulted in additional stages being considered'), and the paper does not claim empirical validation. The Skeptic's observation that the fourteen conditions do not include truth-sensitivity or task-specific triggers is an implementation gap relative to design requirement #2, not a circular reduction: the framework's failure to fully instantiate 'use contextualizes risk' is an incompleteness, not an equivalence between premise and conclusion. No equation, fitted parameter, or uniqueness theorem is imported from the authors' prior work to force the result. Hence no significant circularity.

Assumptions & free parameters 2 free parameters · 5 assumptions · 1 invented entities

This conceptual paper has no numerical free parameters; the 'free parameters' listed are hand-chosen structural selections that shape the framework. The axioms are domain assumptions borrowed from usage governance and the authors' own taxonomy. The most fragile is the assumption that the five-risk expert panel mapping generalizes. The paper itself flags the scope limitation in Section 4.3 for non-entity risks.

free parameters (2)
  • Selected risk subset = five risks: hallucination, toxic output, prompt injection, usage restrictions, personal information in data
    Hand-picked in Section 5.1.1 to cover different categories and entities; the paper notes other risks might add stages, so this choice shapes the framework.
  • Development stage subset = use definition, model procurement, implementation
    The expert panel mapped the selected risks to only these stages; Section 5.1.1 says other risks may need evaluation, deployment, and monitoring stages.
assumptions (5)
  • domain assumption Use is the primary determinant of which risks are relevant for a foundation model.
    Stated in Section 3 and throughout; the entire framework rests on this premise. It is plausible but not empirically established in the paper.
  • domain assumption Risks can be decomposed by usage governance entities and mapped to stages of the AI development lifecycle.
    Section 3.1 and Section 4.3. The paper assumes such mapping is feasible and that benchmarks and taxonomies provide evidence for it.
  • domain assumption The IBM AI Risk Atlas, authored by several of the same authors, is a suitable taxonomy for grounding the framework.
    Section 5.1.1. The authors select it because it already maps risks to entities; this choice is convenient and not compared with other taxonomies.
  • domain assumption Expert opinion from a five-person panel is valid evidence for mapping risks and deriving conditions.
    Section 5.1.1. No inter-rater reliability or external validation is provided; one panelist is an author.
  • domain assumption Risks that do not map to AI system entities can be deferred to other processes.
    Section 4.3 explicitly scopes them out. The framework's completeness depends on this boundary, which the authors flag.
invented entities (1)
  • Potential risk
    purpose: A risk judged likely from available information but requiring further evaluation for confirmation; used to avoid demanding perfect certainty from questionnaire users.
    Defined in Section 4.4. It is a conceptual device, not a measurable quantity, and the paper provides no external falsifiable handle.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Developing a Risk Identification Framework for Foundation Model Uses." pith.science (2026). https://pith.science/paper/LRBKN3SN

@misc{pith2026250602066,
  author       = {Pith},
  title        = {Pith review of: Developing a Risk Identification Framework for Foundation Model Uses},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/LRBKN3SN}},
  note         = {Machine review of arXiv:2506.02066}
}
read the original abstract

As foundation models grow in both popularity and capability, researchers have uncovered a variety of ways that the models can pose a risk to the model's owner, user, or others. Despite the efforts of measuring these risks via benchmarks and cataloging them in AI risk taxonomies, there is little guidance for practitioners on how to determine which risks are relevant for a given foundation model use. In this paper, we address this gap and develop requirements and an initial design for a risk identification framework. To do so, we look to prior literature to identify challenges for building a foundation model risk identification framework and adapt ideas from usage governance to synthesize four design requirements. We then demonstrate how a candidate framework can addresses these design requirements and provide a foundation model use example to show how the framework works in practice for a small subset of risks.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

64 extracted references · 45 canonical work pages

  1. [1]

    Sayre, Ushnish Sengupta, Arthit Suriyawongkul, Ruby Thelot, Sofia Vei, and Laura Waltersdorfer

    Gavin Abercrombie, Djalel Benbouzid, Paolo Giudici, Delaram Golpayegani, Julio Hernandez, Pierre Noro, Harshvardhan Pandit, Eva Paraschou, Charlie Pownall, Jyoti Prajapati, Mark A. Sayre, Ushnish Sengupta, Arthit Suriyawongkul, Ruby Thelot, Sofia Vei, and Laura Waltersdorfer. 2024. A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation...

  2. [2]

    Sinan Arda. 2024. Taxonomy to Regulation: A (Geo)Political Taxonomy for AI Risks and Regulatory Measures in the EU AI Act. arXiv:2404.11476 [cs.AI] Developing a Risk Identification Framework for Foundation Model Uses https://arxiv.org/abs/2404.11476

  3. [3]

    Arnold, R

    M. Arnold, R. K. E. Bellamy, M. Hind, S. Houde, S. Mehta, A. Mojsilović, R. Nair, K. Natesan Ramamurthy, A. Olteanu, D. Piorkowski, D. Reimer, J. Richards, J. Tsay, and K. R. Varshney. 2019. FactSheets: Increasing Trust in AI Services through Supplier’s Declarations of Conformity.IBM Journal of Research & Development 63, 4/5 (Sept. 2019)

  4. [4]

    David Atkinson and Jacob Morrison. 2024. A Legal Risk Taxonomy for Generative Artificial Intelligence. arXiv:2404.09479 [cs.CY] https://arxiv.org/abs/2404.09479

  5. [5]

    Frank Bagehorn, Kristina Brimijoin, Elizabeth M. Daly, Jessica He, Michael Hind, Luis Garces-Erice, Christopher Giblin, Ioana Giurgiu, Jacquelyn Martino, Rahul Nair, David Piorkowski, Ambrish Rawat, John Richards, Sean Rooney, Dhaval Salwala, Seshu Tirupathi, Peter Urbanetz, Kush R. Varshney, Inge Vejsbjerg, and Mira L. Wolf-Bauwens. 2025. AI Risk Atlas: ...

  6. [6]

    Bender and Batya Friedman

    Emily M. Bender and Batya Friedman. 2018. Data Statements for Natural Lan- guage Processing: Toward Mitigating System Bias and Enabling Better Science. Transactions of the Association of Computational Linguistics(2018)

  7. [7]

    Manish Bhatt, Sahana Chennabasappa, Cyrus Nikolaidis, Shengye Wan, Ivan Evti- mov, Dominik Gabi, Daniel Song, Faizan Ahmad, Cornelius Aschermann, Lorenzo Fontana, Sasha Frolov, Ravi Prakash Giri, Dhaval Kapil, Yiannis Kozyrakis, David LeBlanc, James Milazzo, Aleksandar Straumann, Gabriel Synnaeve, Varun Von- timitta, Spencer Whitman, and Joshua Saxe. 2023...

  8. [8]

    Lukas Bieringer, Kevin Paeth, Jochen Stängler, Andreas Wespi, Alexandre Alahi, and Kathrin Grosse. 2025. Position: A taxonomy for reporting and describing AI security incidents. arXiv:2412.14855 [cs.CR] https://arxiv.org/abs/2412.14855

Show all 64 references
  1. [9]

    Longbing Cao. 2022. AI in Finance: Challenges, Techniques, and Opportunities. ACM Comput. Surv.55, 3, Article 64 (Feb. 2022), 38 pages. doi:10.1145/3502289

  2. [10]

    Subhajit Chaudhury, Sarathkrishna Swaminathan, Chulaka Gunasekara, Maxwell Crouse, Srinivas Ravishankar, Daiki Kimura, Keerthiram Murugesan, Ramón Fernandez Astudillo, Tahira Naseem, Pavan Kapanipathi, and Alexander Gray

  3. [11]

    2024.The CLEAR Documentation Framework: AI Transparency Recommendations for Practitioners in Context for Policymakers

    Kate Chmielinski. 2024.The CLEAR Documentation Framework: AI Transparency Recommendations for Practitioners in Context for Policymakers. Technical Re- port. Shorenstein Center on Media, Politics and Public Policy, Harvard Kennedy School. https://shorensteincenter.org/wp-conten...

  4. [12]

    Chmielinski, Sarah Newman, Matt Taylor, Joshua Joseph, Jessica Yurkof- sky Kemi Thomas, and Yue Chelsea Qiu

    Kasia S. Chmielinski, Sarah Newman, Matt Taylor, Joshua Joseph, Jessica Yurkof- sky Kemi Thomas, and Yue Chelsea Qiu. 2020. The Dataset Nutrition Label (2nd Gen): Leveraging Context to Mitigate Harms in Artificial Intelligence. InNeurIPS 2020 Workshop on Dataset Curation and Security

  5. [13]

    Credo AI. 2025. Credo AI. https://www.credo.ai/product

  6. [14]

    Leon Derczynski, Hannah Rose Kirk, Vidhisha Balachandran, Sachin Kumar, Yulia Tsvetkov, Mark R Leiser, and Saif Mohammad. 2023. Assessing language model deployment with risk cards.arXiv preprint arXiv:2303.18190(2023)

  7. [15]

    Benj Edwards. 2025. Company apologizes after AI support agent invents policy that causes user uproar. https://arstechnica.com/ai/2025/04/cursor-ai-support- bot-invents-fake-policy-and-triggers-user-uproar/

  8. [16]

    European Union. 2024. Regulation (EU) 2024/1689 of the European Parliment and of the Council of the Euorpean Union. https://eur-lex.europa.eu/legal- content/EN/TXT/?uri=CELEX%3A32024R1689

  9. [17]

    Timnit Gebru, Jamie Morgenstern, Briana Vecchione, Jennifer Wortman Vaughan, Hanna Wallach, Hal Daumé, III, and Kate Crawford. 2018. Datasheets for Datasets. InProceedings of the Fairness, Accountability, and Transparency in Machine Learn- ing Workshop. Stockholm, Sweden

  10. [18]

    Timnit Gebru, Jamie Morgenstern, Briana Vecchione, Jennifer Wortman Vaughan, Hanna Wallach, Hal Daumé III, and Kate Crawford. 2021. Datasheets for Datasets. Commun. ACM64, 12 (Dec. 2021), 86–92

  11. [19]

    Delaram Golpayegani, Joshua Hovsha, Leon W. S. Rossmaier, Rana Saniei, and Jana Mišić. 2022. Towards a Taxonomy of AI Risks in the Health Domain. In2022 Fourth International Conference on Transdisciplinary AI (TransAI). 1–8. doi:10.1109/TransAI54797.2022.00007

  12. [20]

    Government of Canada. 2023. Canada Artificial Intelligence and Data Act. https://ised-isde.canada.ca/site/innovation-better-canada/en/artificial- intelligence-and-data-act-aida-companion-document

  13. [21]

    Viviane Herdel, Sanja Šćepanović, Edyta Bogucka, and Daniele Quercia. 2024. ExploreGen: Large Language Models for Envisioning the Uses and Risks of AI Technologies. arXiv:2407.12454 [cs.HC] https://arxiv.org/abs/2407.12454

  14. [22]

    IBM. 2023. AI Risk Atlas. https://www.ibm.com/docs/en/watsonx/saas?topic=ai- risk-atlas

  15. [23]

    IBM AI Ethics Board. 2024. Foundation models: Opportunities, risks and mitiga- tions. https://www.ibm.com/downloads/documents/us-en/10a99803d8afd656

  16. [24]

    Inter-Parliamentary Union. 2025. Risk management: Risk assessment question- naires. https://www.ipu.org/ai-guidelines/risk-management-risk-assessment- questionnaires

  17. [25]

    ISO. 2023. ISO/IEC 42001:2023. https://www.iso.org/standard/81230.html

  18. [26]

    Leonie Koessler and Jonas Schuett. 2023. Risk assessment at AGI companies: A review of popular risk assessment techniques from other safety-critical industries. arXiv:2307.08823 [cs.CY] https://arxiv.org/abs/2307.08823

  19. [27]

    George Kour, Marcel Zalmanovici, Naama Zwerdling, Esther Goldbraich, Ora Nova Fandina, Ateret Anaby-Tavor, Orna Raz, and Eitan Farchi. 2023. Unveiling Safety Vulnerabilities of Large Language Models.arXiv preprint arXiv:2311.04124(2023)

  20. [28]

    Stephanie Lin, Jacob Hilton, and Owain Evans. 2022. TruthfulQA: Measuring How Models Mimic Human Falsehoods. arXiv:2109.07958 [cs.CL] https://arxiv. org/abs/2109.07958

  21. [29]

    Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. 2024. Formalizing and benchmarking prompt injection attacks and defenses. In33rd USENIX Security Symposium (USENIX Security 24). 1831–1847

  22. [30]

    Qichao Ma, Rui-Jie Zhu, Peiye Liu, Renye Yan, Fahong Zhang, Ling Liang, Meng Li, Zhaofei Yu, Zongwei Wang, Yimao Cai, et al . 2024. Inner-Probe: Discov- ering Copyright-related Data Generation in LLM Architecture.arXiv preprint arXiv:2410.04454(2024)

  23. [31]

    Alex Mallen, Akari Asai, Victor Zhong, Rajarshi Das, Daniel Khashabi, and Hannaneh Hajishirzi. 2023. When Not to Trust Language Models: Investigating Effectiveness of Parametric and Non-Parametric Memories. InProceedings of the 61st Annual Meeting of the Association for Comput...

  24. [32]

    Margaret Mitchell, Simone Wu, Andrew Zaldivar, Parker Barnes, Lucy Vasserman, Ben Hutchinson, Elena Spitzer, Inioluwa Deborah Raji, and Timnit Gebru. 2019. Model Cards for Model Reporting. InProceedings of the ACM Conference on Fairness, Accountability, and Transparency. Atlanta, USA

  25. [33]

    MITRE. 2021. MITRE Atlas. https://atlas.mitre.org/matrices/ATLAS

  26. [34]

    Brian T. Molloy. 2021. Project Governance for Defense Applications of Artificial Intelligence: An Ethics-Based Approach.PRISM9, 3 (2021), 106–121. https: //www.jstor.org/stable/48640749

  27. [35]

    https://apnews.com/article/artificial-intelligence- chatgpt-fake-case-lawyers-d6ae9fa79d0542db9e1455397aef381c

    Larry Neumeister. 2023. Lawyers submitted bogus case law created by ChatGPT. A judge fined them $5,000. "https://apnews.com/article/artificial-intelligence- chatgpt-fake-case-lawyers-d6ae9fa79d0542db9e1455397aef381c"

  28. [36]

    New York City Council. 2021. NYC Local Law 144. https://legistar.council.nyc. gov/LegislationDetail.aspx?ID=4344524&GUID=B051915D-A9AC-451E-81F8- 6596032FA3F9

  29. [37]

    C Nidhisree, Ananya Paul, Anaswara Venunadh, and Rajat Subhra Bhowmick

  30. [38]

    NIST. 2023. AI Risk Management Framework. https://www.nist.gov/itl/ai- riskmanagement-framework

  31. [39]

    Kyle Orland. 2024. NYC’s government chatbot is lying about city laws and regulations. https://arstechnica.com/ai/2024/03/nycs-government-chatbot-is- lying-about-city-laws-and-regulations/

  32. [40]

    OWASP. 2024. OWASP Top 10 for LLMs and Generative AI Apps. https://genai. owasp.org/llm-top-10/

  33. [41]

    https://techcrunch.com/2023/05/02/samsung-bans-use- of-generative-ai-tools-like-chatgpt-after-april-internal-data-leak/

    Kate Park. 2023. Samsung bans use of generative AI tools like ChatGPT after April internal data leak. "https://techcrunch.com/2023/05/02/samsung-bans-use- of-generative-ai-tools-like-chatgpt-after-april-internal-data-leak/"

  34. [42]

    Alicia Parrish, Angelica Chen, Nikita Nangia, Vishakh Padmakumar, Jason Phang, Jana Thompson, Phu Mon Htut, and Samuel Bowman. 2022. BBQ: A hand- built bias benchmark for question answering. InFindings of the Association for Computational Linguistics: ACL 2022, Smaranda Muresa...

  35. [43]

    AI Incident Database

    Partnership on AI 2025. AI Incident Database. https://partnershiponai.org/workstream/ai-incidents-database/

  36. [44]

    People’s Republic of China. 2025. China AI Law. https://cset.georgetown.edu/wp- content/uploads/t0592_china_ai_law_draft_EN.pdf

  37. [45]

    David Piorkowski, Michael Hind, and John Richards. 2025. Quantitative AI Risk Assessments: Opportunities and Challenges.Seton Hall Journal of Legislation and Public Policy49, 2 (2025). Issue 3. https://scholarship.shu.edu/shlj/vol49/iss3/2

  38. [46]

    David Piorkowski, Soya Park, April Yi Wang, Dakuo Wang, Michael Muller, and Felix Portnoy. 2021. How ai developers overcome communication challenges in a multidisciplinary team: A case study.Proceedings of the ACM on Human- Computer Interaction5, CSCW1 (2021), 1–25. David Pior...

  39. [47]

    Jason Proctor. 2024. Air Canada found liable for chatbot’s bad advice on plane tickets. https://www.cbc.ca/news/canada/british-columbia/air-canada-chatbot- lawsuit-1.7116416

  40. [48]

    Inioluwa Deborah Raji and Jingying Yang. 2020. ABOUT ML: Annotation and Benchmarking on Understanding and Transparency of Machine Learning Life- cycles. arXiv:1912.06166 [cs.CY] https://arxiv.org/abs/1912.06166

  41. [49]

    Nydia Remolina Leon. 2024. Generative AI in finance: Risks and potential solutions.Law, Ethics and Technology1 (2024), 1–18. https://ink.library.smu.edu. sg/sol_research/4612

  42. [50]

    AI Incident Database

    Responsible AI Collaborative 2025. AI Incident Database. https://incidentdatabase.ai/

  43. [51]

    Cátia Rosário. 2025. Benefits and risks of using AI in Human Resource Manage- ment: Literature review.Educational Research (IJMCER)7, 2 (2025), 146–154

  44. [52]

    Jiawen Shi, Zenghui Yuan, Yinuo Liu, Yue Huang, Pan Zhou, Lichao Sun, and Neil Zhenqiang Gong. 2024. Optimization-based prompt injection attack to llm- as-a-judge. InProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 660–674

  45. [53]

    Saeri, Emily A

    Peter Slattery, Alexander K. Saeri, Emily A. C. Grundy, Jess Graham, Michael Noetel, Risto Uuk, James Dao, Soroush Pour, Stephen Casper, and Neil Thompson

  46. [54]

    Alex Tamkin, Amanda Askell, Liane Lovitt, Esin Durmus, Nicholas Joseph, Shauna Kravec, Karina Nguyen, Jared Kaplan, and Deep Ganguli. 2023. Evaluat- ing and Mitigating Discrimination in Language Model Decisions. InNeurIPS 2024 Workshop on Algorithmic Fairness through the Lens ...

  47. [55]

    UK Department for Science, Innovation, & Technology. 2023. A pro-innovation approach to AI regulation. https://assets.publishing.service.gov.uk/media/ 64cb71a547915a00142a91c4/a-pro-innovation-approach-to-ai-regulation- amended-web-ready.pdf

  48. [56]

    arXiv:2408.12622 [cs.AI] https: //arxiv.org/abs/2408.12622

    The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence. arXiv:2408.12622 [cs.AI] https: //arxiv.org/abs/2408.12622

  49. [57]

    Risto Uuk, Carlos Ignacio Gutierrez, Daniel Guppy, Lode Lauwaert, Atoosa Kasirzadeh, Lucia Velasco, Peter Slattery, and Carina Prunkl. 2024. A Taxonomy of Systemic Risks from General-Purpose AI. arXiv:2412.07780 [cs.CY] https: //arxiv.org/abs/2412.07780

  50. [58]

    Wang, Chinmay Kulkarni, Lauren Wilcox, Michael Terry, and Michael Madaio

    Zijie J. Wang, Chinmay Kulkarni, Lauren Wilcox, Michael Terry, and Michael Madaio. 2024. Farsight: Fostering Responsible AI Awareness During AI Applica- tion Prototyping. InProceedings of the 2024 CHI Conference on Human Factors in Computing Systems(Honolulu, HI, USA)(CHI ’24)...

  51. [59]

    United Nations Interregional Crime and Justice Research Institute. 2024. Risk As- sessment Questionnaire. https://unicri.org/sites/default/files/2024-02/05_Risk% 20Assesment_Questionnaire_Feb24.pdf

  52. [60]

    Xilie Xu, Keyi Kong, Ning Liu, Lizhen Cui, Di Wang, Jingfeng Zhang, and Mohan Kankanhalli. 2024. An LLM can Fool Itself: A Prompt-Based Adversarial Attack. InThe Twelfth International Conference on Learning Representations

  53. [61]

    Giulio Zizzo, Giandomenico Cornacchia, Kieran Fraser, Muhammad Zaid Hameed, Ambrish Rawat, Beat Buesser, Mark Purcell, Pin-Yu Chen, Prasanna Sattigeri, and Kush Varshney. 2024. Adversarial Prompt Evaluation: Systematic Benchmarking of Guardrails Against Prompt Input Attacks on...

  54. [62]

    Laura Weidinger, Jonathan Uesato, Maribeth Rauh, Conor Griffin, Po-Sen Huang, John Mellor, Amelia Glaese, Myra Cheng, Borja Balle, Atoosa Kasirzadeh, Court- ney Biles, Sasha Brown, Zac Kenton, Will Hawkins, Tom Stepleton, Abeba Birhane, Lisa Anne Hendricks, Laura Rimell, Willi...

  55. [2022]

    InProceedings of the 2022 Conference on Empirical Methods in Natural Language Processing, Yoav Goldberg, Zornitsa Kozareva, and Yue Zhang (Eds.)

    X-FACTOR: A Cross-metric Evaluation of Factual Correctness in Abstrac- tive Summarization. InProceedings of the 2022 Conference on Empirical Methods in Natural Language Processing, Yoav Goldberg, Zornitsa Kozareva, and Yue Zhang (Eds.). Association for Computational Linguistic...

  56. [2024]

    In2024 IEEE 6th International Conference on Cybernetics, Cog- nition and Machine Learning Applications (ICCCMLA)

    Generative AI Under Scrutiny: Assessing the Risks and Challenges in Diverse Domains. In2024 IEEE 6th International Conference on Cybernetics, Cog- nition and Machine Learning Applications (ICCCMLA). 243–248. doi:10.1109/ ICCCMLA63077.2024.10871350

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.