September 15, 2026
IBM Mapped 99 AI Risks Across Five Categories. Here Is What Surprised UsNearly a quarter of the risks in IBM's AI Risk Atlas sit in a category that did not exist eighteen months ago. Most enterprises are still running their first handful of agent pilots. The risk taxonomy is already ahead of them.
We have spent time going through the AI Risk Atlas in detail as we build our own practical mapping of it for regulated UK, EU, and GCC firms, and three things stood out enough to be worth sharing before that fuller work is ready.
The AI Risk Atlas is a taxonomy built by IBM Research, first published as a formal reference in 2025 and maintained as an open, actively updated project since. It collects risks from prior research, real-world incidents, and domain experts, and organises them into five categories based on where each risk originates: training data, inference, output, non-technical, and agentic. Within each category, risks are further grouped into dimensions such as fairness, privacy, robustness, or explainability, which lets a practitioner focus on the dimensions relevant to a specific use case rather than wading through the entire catalogue.
The Atlas currently lists 99 individual risks. IBM Research's own published paper on the taxonomy, current as of July 2025, put the figure at 95 by our count of its category breakdown, which tells you this is a living document rather than a fixed checklist. It has grown by a handful of entries in little over a year, almost entirely in the newest category. It also sits underneath IBM's watsonx.governance product and the open-source Risk Atlas Nexus tooling, which maps it against other frameworks including the NIST AI RMF and the EU AI Act.
The agentic category is already one of the largest, and enterprises have barely started using agents. At the point IBM Research published its taxonomy paper, the agentic category held 22 of the 95 risks then catalogued, more than any other single category except output risk. That is a striking allocation of attention for a category describing systems most regulated firms are only beginning to pilot. It suggests IBM's own researchers see agentic autonomy as a bigger expansion of the risk surface than the jump from traditional machine learning to generative AI was, not a smaller one.
Governance concerns outweigh narrowly technical ones, even inside a taxonomy built by AI researchers. Within the agentic category, governance is the single largest risk dimension, ahead of privacy, robustness, and fairness individually. Zoom out to the non-technical category, covering legal compliance, governance, and societal impact, and it holds nearly as many risks as any of the purely technical categories. A taxonomy written by engineers and researchers, not compliance professionals, still finds that questions of accountability, oversight, and process make up a comparable share of the risk surface to questions of model behaviour. That is not the framing most AI risk conversations start from.
Most "agentic" risks are not new categories of harm. They are familiar risks that autonomy changes the shape of. Bias, privacy leakage, and misuse all already existed as risks before agents. What the agentic category adds is not a new list of harms but a new set of ways those same harms occur: bias introduced through an agent's own actions rather than its training data, confidential information shared with a tool rather than disclosed in an output, oversight failures that stem from an agent's decisions being untraceable rather than a model's decisions being unexplainable. The names change. The underlying concerns are the ones governance teams already have vocabulary for, which is a more tractable problem than an entirely novel risk category would be.
The Atlas itself is deliberately general. It is built to apply across machine learning, generative AI, and agentic systems, in any sector, in any jurisdiction, and it makes no attempt to weight risks by what matters most to a bank, an insurer, or a firm operating under SM&CR, DIFC Regulation 10, or the EU AI Act's high-risk regime. That is a reasonable design choice for a taxonomy meant to serve every kind of organisation. It also means the Atlas will not tell a UK Risk lead which of its 99 risks map onto a PRA SS1/23 obligation, or which of the agentic-category risks a DIFC-regulated entity needs to evidence first.
That gap is exactly what we are working on closing, building a practical crosswalk between the Atlas's risk categories and the specific regulatory obligations firms in our markets carry, so that studying the taxonomy leads somewhere more concrete than a longer reading list. We will share more as that work is ready.
Is the IBM AI Risk Atlas specific to IBM's own AI products? No. The Atlas is a general taxonomy of AI risk, applicable to machine learning, generative AI, and agentic systems regardless of vendor. It underpins IBM's watsonx.governance product and integrates with the open-source Risk Atlas Nexus tooling, but the risk definitions themselves are not tied to any particular platform.
Does a risk appearing in the agentic category mean it only applies to autonomous agents? Mostly, yes, though the boundary is not absolute. IBM tags each risk as either specific to agentic AI or amplified by agentic AI, meaning some risks already existed for generative AI but become more severe or more likely once a system can act autonomously rather than only generate text.
How often is the Atlas updated? It is maintained as an active, open project rather than a fixed publication. The difference between the 95 risks documented in IBM Research's July 2025 paper and the 99 currently listed shows meaningful growth in a little over a year, concentrated in the newest category, so a count taken today should not be assumed to hold indefinitely.
The full [AI Risk Atlas] (https://www.ibm.com/docs/en/watsonx/w-and-w/2.4.x?topic=ai-risk-atlas) is available directly from IBM, and is well worth the read in full. As an IBM Gold Partner combining watsonx.governance with our own runtime governance layer in Altrum AI, we will be publishing our full crosswalk between the Atlas and UK, EU, and GCC regulatory obligations as that work is completed. If this maps onto a live problem in your organisation, Aligne runs business alignment calls to talk through where you are, and where relevant, show how Altrum AI approaches it. Book a call: https://www.aligne.ai/schedule-business-alignment-call
Stay Informed: Engage with our Blog for Expert Analysis, Industry Updates, and Insider Perspectives

.png)
.png)

September 15, 2026
IBM Mapped 99 AI Risks Across Five Categories. Here Is What Surprised Us.png)
September 10, 2026
The UK Enterprise AI Governance Gap: What the Data Actually Showslet’s design the governance framework your AI strategy deserves
.webp)
Let's Talk