MIT AI Risk Repository — Domain Taxonomy
MIT AI Risk Repository — Domain Taxonomy — 40% of in-scope requirements covered.
5 requirements · 5 in scope (3 designed · 2 advisory). The 40% is weighted over the in-scope base.
Source: MIT AI Risk Repository (Slattery et al., 2024) — the Domain Taxonomy of 7 risk domains and 24 subdomains, the most-cited academic catalogue of AI risks. KYE Protocol™ governs the AUTHORITY, EVIDENCE and FINALITY of AI-AGENT ACTIONS; it therefore addresses the action-authority risk domains (privacy/security access, malicious misuse, human-computer oversight, system-safety traceability) and is HONESTLY out of scope for the content/societal domains (discrimination & toxicity, misinformation, socioeconomic & environmental) — those are content-truth/fairness/macro risks KYE™ does not adjudicate. Starter requirement set over the in-scope domains; deepen by graft through the §70 rail. · License: MIT AI Risk Repository is published under CC-BY; KYE™ registry paraphrases each domain's intent and cites the domain identifier for mapping purposes only.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Privacy & Security (action-authority) | 1 | 0 | 0 | 1 | 0 | 25% |
| Malicious Actors & Misuse | 1 | 0 | 1 | 0 | 0 | 50% |
| Human-Computer Interaction | 1 | 0 | 1 | 0 | 0 | 50% |
| AI System Safety, Failures & Limitations | 2 | 0 | 1 | 1 | 0 | 38% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
mit-risk.d2-privacy-security |
Domain 2 Privacy & Security — agent data access bounded by purpose + tenant isolation | advisory | constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/31-DATA-GOVERNANCE-PACK.mdaudit_events: kye.evidence.decision_map.v1 |
mit-risk.d4-malicious-misuse |
Domain 4 Malicious Actors & Misuse — unauthorised agent actions refused at the boundary | designed | constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/52-DELEGATED-AGENT-BINDING.md |
mit-risk.d5-human-computer-interaction |
Domain 5 Human-Computer Interaction — overreliance / loss of agency met with human oversight | designed | constitution_refs: constitution/36-GOVERNEDUI.md |
mit-risk.d7-traceability |
Domain 7 AI System Safety — traceability & non-repudiation of agent actions | advisory | constitution_refs: constitution/13-RESILIENCE-LOOP.mdaudit_events: kye.evidence.pack.v1, kye.replay.proof.v1 |
mit-risk.d7-multi-agent |
Domain 7 AI System Safety — multi-agent risks via the delegation chain | designed | constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md, constitution/21-DELEGATED-AUDITABILITY.md |