Skip to main content
QUICK REVIEW

[Paper Review] AI Risk Categorization Decoded (AIR 2024): From Government Regulations to Corporate Policies

Yi Zeng, Kevin Klyman|arXiv (Cornell University)|Jun 25, 2024
Ethics and Social Impacts of AI4 citations
TL;DR

This paper proposes AIR 2024, a unified four-tiered AI risk taxonomy derived from 24 policy documents across the EU, US, China, and 16 global companies, identifying 314 unique risk categories. By mapping risks across public and private sector frameworks, it reveals gaps in regulation and highlights corporate policies as more granular, offering a standardized language to improve cross-sector collaboration and AI safety evaluation.

ABSTRACT

We present a comprehensive AI risk taxonomy derived from eight government policies from the European Union, United States, and China and 16 company policies worldwide, making a significant step towards establishing a unified language for generative AI safety evaluation. We identify 314 unique risk categories organized into a four-tiered taxonomy. At the highest level, this taxonomy encompasses System & Operational Risks, Content Safety Risks, Societal Risks, and Legal & Rights Risks. The taxonomy establishes connections between various descriptions and approaches to risk, highlighting the overlaps and discrepancies between public and private sector conceptions of risk. By providing this unified framework, we aim to advance AI safety through information sharing across sectors and the promotion of best practices in risk mitigation for generative AI models and systems.

Motivation & Objective

  • Address the lack of a unified AI risk taxonomy that spans public and private sector perspectives.
  • Systematically analyze how AI companies and governments categorize risks related to generative AI.
  • Identify discrepancies and overlaps between government regulations and corporate policies to inform better risk mitigation.
  • Develop a standardized, granular framework to support consistent AI safety evaluation across jurisdictions and industries.
  • Provide a data-driven foundation for future policy development, benchmarking, and international cooperation in AI safety.

Proposed method

  • Conduct a line-by-line analysis of 24 policy documents, including 8 government regulations (EU, US, China) and 16 corporate policies.
  • Extract and map all unique risk descriptions into a four-level hierarchical taxonomy: level-1 (4 high-level categories), level-2 (18 subcategories), level-3 (104 sub-subcategories), and level-4 (314 atomic risk types).
  • Categorize risks into four main domains: System & Operational Risks, Content Safety Risks, Societal Risks, and Legal & Rights Risks.
  • Perform comparative analysis across jurisdictions and sectors using the taxonomy to assess alignment, coverage, and granularity.
  • Use China’s Generative AI Services Interim Measures and policies from DeepSeek and Baidu as a case study to evaluate alignment between law and corporate practice.
  • Quantify overlap and divergence in risk categories using level-3 and level-4 mappings, with statistical reporting on policy coverage and compliance gaps.
Figure 1 : Overview of the AI risk taxonomy derived from 24 policy and regulatory documents, encompassing 314 unique risk categories. Charts on the right-hand side map to major AI regulations.
Figure 1 : Overview of the AI risk taxonomy derived from 24 policy and regulatory documents, encompassing 314 unique risk categories. Charts on the right-hand side map to major AI regulations.

Experimental results

Research questions

  • RQ1How do government regulations and corporate policies differ in their categorization of AI risks across the EU, US, and China?
  • RQ2To what extent do corporate AI policies cover risk categories not explicitly addressed in current government regulations?
  • RQ3What are the key gaps or inconsistencies in the granularity and scope of AI risk definitions between public and private sector frameworks?
  • RQ4How aligned are the risk categories in Chinese corporate policies with the legally mandated risk categories under China’s Generative AI Services Interim Measures?
  • RQ5Can a unified taxonomy derived from real-world policies serve as a foundation for improved AI safety benchmarks and cross-jurisdictional policy coordination?

Key findings

  • The AIR 2024 taxonomy identifies 314 unique risk categories organized into a four-tiered hierarchy, offering unprecedented granularity for AI risk evaluation.
  • Corporate policies cover more than 90% of the risk categories specified in China’s Generative AI Services Interim Measures, indicating strong alignment despite omissions in two specific risk types.
  • The two Chinese companies studied—DeepSeek and Baidu—did not explicitly mention 'Autonomous Unsafe Operation of Systems' or 'Advice in Heavily Regulated Industries' in their policies, though they included liability disclaimers covering similar risks.
  • Government regulations, including the EU AI Act and US Executive Order, contain fewer risk categories than corporate policies, suggesting regulatory frameworks may lack sufficient detail for effective enforcement.
  • The analysis reveals that corporate policies often anticipate or exceed regulatory requirements, particularly in areas like self-harm promotion and operational misuse, indicating potential for industry practices to inform future regulation.
  • Despite high-level alignment in risk categories, superficial agreement at level-2 may mask significant inconsistencies at level-4, underscoring the need for detailed, atomic-level risk categorization in policy and safety evaluation.
Figure 3 : EU regulations specified AI risks mapped as 23 level-3 categories in the AIR 2024.
Figure 3 : EU regulations specified AI risks mapped as 23 level-3 categories in the AIR 2024.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.