Harm Taxonomy
A harm taxonomy is a structured classification system that organizes the different types of damage or negative impacts that can result from AI systems, data processing, or related technologies. It groups harms into categories, such as harm to physical health or safety, financial loss, property damage, or interference with individual rights, so they can be identified and discussed consistently. Different organizations publish different taxonomies, so the specific categories vary depending on the framework and its intended context.
A harm taxonomy is a categorization framework that systematically characterizes the types, and sometimes the affected entities and technologies, associated with adverse outcomes from AI or data-driven systems. As commonly defined across published examples, such taxonomies enumerate harm categories including physical health or safety harm, financial or economic loss, property damage, psychological harm, reputational harm, social and societal harm, environmental damage, and interference with fundamental rights. Specific taxonomies differ in scope and structure: the CSET AI Harm Taxonomy characterizes harms, entities, and technologies involved in AI incidents; the ICO's harm framework addresses harms in a data protection context; and cyber-harm taxonomies organize impacts under themes such as physical or digital, economic, psychological, reputational, and social and societal harm. Because these frameworks are issued by different bodies for different purposes, category definitions and boundaries are not interchangeable, and a taxonomy supports harm identification and analysis rather than measuring or eliminating risk itself.
Why it matters
AI systems can produce a wide range of adverse outcomes, and without a shared vocabulary, organizations struggle to identify, discuss, and compare those outcomes consistently. A harm taxonomy addresses this by giving practitioners a structured set of categories, such as physical health or safety harm, financial loss, property damage, psychological harm, reputational harm, and interference with fundamental rights, so that different teams and stakeholders can name the same problem in the same way. This consistency supports downstream activities such as risk assessment, incident reporting, and impact analysis.
The practical value of a taxonomy depends heavily on its source and intended context. The CSET AI Harm Taxonomy, for example, is oriented toward characterizing the harms, entities, and technologies involved in documented AI incidents, while the ICO's harm framework addresses harm specifically in a data protection context. Cyber-harm taxonomies, such as the one developed by Agrafiotis and colleagues, organize impacts under broad themes including physical or digital, economic, psychological, reputational, and social and societal harm. Because these frameworks are issued by different bodies for different purposes, their categories are not interchangeable, and applying one taxonomy's definitions to another's context can produce misleading conclusions.
It is important to recognize what a harm taxonomy does and does not do. A taxonomy supports the identification and analysis of harm; it does not by itself measure the likelihood or severity of a given harm, and it does not eliminate or reduce risk. Treating the existence of a taxonomy as evidence that harms have been managed is a common error. The taxonomy is a starting point for structured discussion, not a substitute for the assessment, mitigation, and monitoring activities that follow from it.
Who it's relevant to
Inside Harm Taxonomy
Common questions
Answers to the questions practitioners most commonly ask about Harm Taxonomy.