Skip to main content
Category: Risk Assessment & Analysis

Harm Taxonomy

Also known as: AI Harm Taxonomy, Harm Framework, Taxonomy of Harms
Simply put

A harm taxonomy is a structured classification system that organizes the different types of damage or negative impacts that can result from AI systems, data processing, or related technologies. It groups harms into categories, such as harm to physical health or safety, financial loss, property damage, or interference with individual rights, so they can be identified and discussed consistently. Different organizations publish different taxonomies, so the specific categories vary depending on the framework and its intended context.

Formal definition

A harm taxonomy is a categorization framework that systematically characterizes the types, and sometimes the affected entities and technologies, associated with adverse outcomes from AI or data-driven systems. As commonly defined across published examples, such taxonomies enumerate harm categories including physical health or safety harm, financial or economic loss, property damage, psychological harm, reputational harm, social and societal harm, environmental damage, and interference with fundamental rights. Specific taxonomies differ in scope and structure: the CSET AI Harm Taxonomy characterizes harms, entities, and technologies involved in AI incidents; the ICO's harm framework addresses harms in a data protection context; and cyber-harm taxonomies organize impacts under themes such as physical or digital, economic, psychological, reputational, and social and societal harm. Because these frameworks are issued by different bodies for different purposes, category definitions and boundaries are not interchangeable, and a taxonomy supports harm identification and analysis rather than measuring or eliminating risk itself.

Why it matters

AI systems can produce a wide range of adverse outcomes, and without a shared vocabulary, organizations struggle to identify, discuss, and compare those outcomes consistently. A harm taxonomy addresses this by giving practitioners a structured set of categories, such as physical health or safety harm, financial loss, property damage, psychological harm, reputational harm, and interference with fundamental rights, so that different teams and stakeholders can name the same problem in the same way. This consistency supports downstream activities such as risk assessment, incident reporting, and impact analysis.

The practical value of a taxonomy depends heavily on its source and intended context. The CSET AI Harm Taxonomy, for example, is oriented toward characterizing the harms, entities, and technologies involved in documented AI incidents, while the ICO's harm framework addresses harm specifically in a data protection context. Cyber-harm taxonomies, such as the one developed by Agrafiotis and colleagues, organize impacts under broad themes including physical or digital, economic, psychological, reputational, and social and societal harm. Because these frameworks are issued by different bodies for different purposes, their categories are not interchangeable, and applying one taxonomy's definitions to another's context can produce misleading conclusions.

It is important to recognize what a harm taxonomy does and does not do. A taxonomy supports the identification and analysis of harm; it does not by itself measure the likelihood or severity of a given harm, and it does not eliminate or reduce risk. Treating the existence of a taxonomy as evidence that harms have been managed is a common error. The taxonomy is a starting point for structured discussion, not a substitute for the assessment, mitigation, and monitoring activities that follow from it.

Who it's relevant to

AI risk and model risk managers
Those responsible for identifying and analyzing risks arising from AI systems can use a harm taxonomy to structure the range of adverse outcomes under consideration. It is worth noting that a taxonomy aids harm identification and does not itself measure risk or substitute for assessment and mitigation work, so it functions as one input to broader risk processes rather than a complete solution.
Data protection and privacy specialists
Professionals working in a data protection context may find harm frameworks developed for that setting, such as the ICO's harm framework, more directly applicable than general-purpose or incident-focused taxonomies. Because these frameworks are scoped to particular purposes, their categories should not be assumed to transfer to other contexts without adaptation.
Incident analysts and cataloguers
Those documenting and classifying AI incidents can use taxonomies designed for that purpose, such as the CSET AI Harm Taxonomy used with the AI Incident Database, which characterizes the harms, entities, and technologies involved. A consistent taxonomy supports comparable incident records, though analysts should note which edition or version of a taxonomy they are applying.
Governance and policy professionals
Those developing organizational policies, oversight structures, or standards can draw on published harm taxonomies to establish shared vocabulary across teams. Because different bodies publish different taxonomies with non-interchangeable categories, policy professionals should be explicit about which framework they adopt and its intended context.
Auditors and assurance practitioners
Those reviewing AI systems can reference a harm taxonomy to check whether an organization has considered a reasonably comprehensive range of adverse outcomes. Auditors should treat the presence of a taxonomy as evidence of structured consideration rather than as evidence that risks have been measured, mitigated, or eliminated.

Inside Harm Taxonomy

Harm categories
A structured set of classes into which potential adverse outcomes from an AI system are grouped, such as physical, psychological, financial, reputational, societal, or rights-related harms. Categories vary across frameworks and organizations, and there is no single authoritative categorization that applies universally.
Affected stakeholders
Identification of who may experience a given harm, including individuals, groups, organizations, or society at large. A taxonomy typically maps harm types to the parties that bear them, since the same system behavior can affect different stakeholders differently.
Severity and scale dimensions
Attributes commonly used to characterize a harm's magnitude, such as how serious an individual instance is and how many people or systems could be affected. These dimensions support prioritization but their thresholds are typically defined by the adopting organization rather than by a common standard.
Likelihood or exposure attributes
Descriptors of how probable a harm is or the conditions under which it may arise. When combined with severity, these attributes are often used to inform risk assessment, though a harm taxonomy itself typically classifies harms rather than quantifying risk.
Reversibility and duration
Whether a harm can be remediated or reversed and how long its effects persist. In many frameworks these characteristics help distinguish transient impacts from lasting or irreversible ones.
Causal or mechanism linkage
The connection between a system behavior, failure mode, or design choice and the resulting harm. This linkage helps distinguish the harm outcome from its cause, which supports the design of mitigations.

Common questions

Answers to the questions practitioners most commonly ask about Harm Taxonomy.

Is a harm taxonomy the same as a risk register?
No, though the two are related and often confused. A harm taxonomy is a structured classification of the types of harm an AI system could cause (for example, categories and subcategories of harms and the parties affected). A risk register, by contrast, is typically an operational document that records identified risks along with their likelihood, impact, owners, and mitigation status. A taxonomy provides the vocabulary and categories; a risk register applies that vocabulary to specific, assessed risks in a given system. Using a taxonomy does not by itself constitute risk assessment or management.
Does classifying a harm in a taxonomy mean the harm has been mitigated or eliminated?
No. A harm taxonomy is a descriptive and organizational tool for identifying and categorizing potential harms; it is not itself a control. Categorizing a harm does not reduce, mitigate, or eliminate it. Mitigation depends on separate governance, model risk management, and control measures, and even those typically reduce or manage risk rather than eliminate it. Treating placement in a taxonomy as evidence of resolution is a common error.
At what stage of the AI lifecycle should a harm taxonomy be applied?
In many practices, a harm taxonomy is most useful early, during design and impact assessment, so that potential harms are identified before development choices are locked in. It is also commonly revisited at validation, pre-deployment review, and during ongoing monitoring, since new harm types can emerge as use cases, data, or affected populations change. The appropriate cadence tends to depend on organizational policy and the risk profile of the system rather than a single universal schedule.
Who should be responsible for maintaining and applying a harm taxonomy?
Responsibility often spans multiple roles. Under a lines-of-defense structure, first-line teams (such as product and model development) may apply the taxonomy to identify harms in their systems, while second-line functions (such as risk or compliance) may own the taxonomy's definitions and consistency, and third-line functions (such as internal audit) may assess whether it is applied as intended. The specific allocation varies by organization, and the taxonomy is more effective when its ownership and update process are explicitly assigned.
How can a harm taxonomy be kept consistent across different AI systems and teams?
Consistency is typically supported by shared category definitions, documented criteria for classifying a harm, and examples that illustrate boundaries between categories. Because different systems and sectors can interpret the same harm category differently, many organizations pair the taxonomy with guidance on edge cases and a governance process for proposing changes. Consistency is a practical goal supported by process discipline, not something the taxonomy guarantees on its own.
How should a harm taxonomy connect to downstream risk management and controls?
A harm taxonomy generally functions as an input rather than a substitute for risk management. In many frameworks, identified harm categories feed into risk assessment, where likelihood and impact are evaluated, and then into the selection of controls and monitoring measures. Maintaining traceability, so that each identified harm can be linked to an assessment and, where warranted, a mitigation, is a common way to make the taxonomy operationally useful. The taxonomy itself does not prescribe the assessment method or the controls.

Common misconceptions

A harm taxonomy is a standardized, universally accepted classification that applies across all AI systems and jurisdictions.
Harm taxonomies are typically developed or adapted by individual organizations, frameworks, or sectors, and their categories, thresholds, and terminology vary. There is no single authoritative taxonomy that applies universally, and definitions can differ notably between, for example, general enterprise AI contexts and regulated sectors.
Cataloguing harms in a taxonomy measures or reduces the risk those harms pose.
A harm taxonomy is a classification and communication tool; it organizes and describes potential adverse outcomes but does not itself quantify or control risk. Risk assessment, monitoring, and mitigation are distinct activities that a taxonomy can inform but does not replace, and no taxonomy eliminates the underlying risk.
Harm and risk are interchangeable, so a harm taxonomy is the same as a risk register.
Harm typically refers to the adverse outcome itself, while risk combines that outcome with likelihood and other conditions. A harm taxonomy classifies types of adverse outcomes; a risk assessment or register applies severity and likelihood to specific scenarios. Conflating the two can obscure whether an item is being described or being evaluated.

Best practices

Define each harm category functionally and record the source or framework it was adapted from, noting explicitly that the taxonomy reflects organizational choices rather than a universal standard.
Keep the taxonomy's classification function distinct from downstream risk assessment, so that categorizing a harm is not mistaken for measuring or controlling its associated risk.
Map each harm type to the stakeholders who may bear it, since the same system behavior can produce different harms for different affected parties.
Capture supporting dimensions such as severity, scale, reversibility, and duration where relevant, and document the thresholds your organization uses since these are typically locally defined.
Trace each harm to its causal mechanism or failure mode to support the design of targeted mitigations, while framing those mitigations as measures that reduce rather than eliminate risk.
Review and update the taxonomy periodically to reflect new use cases, evolving regulatory treatment, and sector-specific meanings, flagging contested or unsettled categories rather than presenting them as fixed.