
A living database of over 800 AI risk mitigations and a preliminary taxonomy
The AI Risk Mitigation Taxonomy has three parts:
The AI Risk Mitigation Taxonomy is part of the MIT AI Risk Initiative, which aims to increase awareness and adoption of best practice AI risk management across the AI ecosystem.
The Draft AI Risk Mitigation Taxonomy classifies mitigations into four categories: Governance & Oversight Controls, Technical & Security Controls, Operational Process Controls, and Transparency & Accountability Controls, with 23 subcategories.
The AI Risk Mitigation Database links each mitigation to the source information (framework title, authors), supporting evidence, and to our Draft AI Risk Mitigation Taxonomy. You can view it below and on Airtable.
The AI Risk Mitigation Taxonomy provides:
We provide examples of how different audiences might use the Mitigation Taxonomy below.
You can view the AI Risk Mitigation Database on Airtable.
We used a systematic search strategy to identify 13 documents proposing AI risk mitigations. We manually extracted 831 mitigations from these documents into a database. We developed our AI risk mitigation taxonomy using an iterative approach, experimenting with several clustering approaches (risk management, AI system lifecycle, actor-based, risk-based, technical vs. socio-technical) before settling on a combination of system lifecycle and socio-technical approach.
We included 13 frameworks: International AI Safety Report (Bengio et al., 2025), A Frontier AI Risk Management Framework (Campos et al., 2025), The Unified Control Framework (Eisenberg et al., 2025), Risk Sources and Risk Management Measures (Gipiškis et al., 2024), Effective Mitigations for Systemic Risks from General-Purpose AI (Uuk et al., 2024), FLI AI Safety Index 2024, Towards Best Practices in AGI Safety and Governance (Schuett et al., 2023), Pitfalls of Evidence-Based AI Policy (Casper et al., 2025), EU AI Act: General Purpose AI Code of Practice, Emerging Processes for Frontier AI Safety (UK Government, 2023), NIST AI Risk Management Framework: Generative AI Profile (NIST, 2024), AI Risk Management Standards Profile for GPAIS (Barrett et al., 2024), and California Senate Bill 1047 (Wiener, 2024). Access detailed bibliographic information on Airtable.
We welcome feedback on this evidence scan and our draft taxonomy. We also welcome recommendations for additional frameworks or documents to include in our review.
Give feedback on the taxonomy or suggest documents to include.
The Repository has several limitations:
see our blog post for a full list and suggestions for future research.
During this synthesis process, we developed a taxonomy that clusters mitigations into four main categories (Governance & Oversight Controls, Technical & Security Controls, Operational Process Controls, and Transparency & Accountability Controls) with 23 subcategories. This structure allows users to filter and explore mitigations at different levels of granularity, from high-level control types to specific mitigation subcategories.
To the best of our knowledge, this is the first comprehensive evidence scan of AI risk mitigation frameworks which extracts their mitigations and releases that data for further adaptation and use. We welcome feedback on anything we may have missed.
Please let us know of anything that we may have missed.
Please let us know of anything that we may have missed.
To reference our work, you can cite the blog post: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy. We will build on this evidence scan with a systematic review of AI risk mitigation frameworks.
We work with governments, companies, and researchers to build better tools for understanding AI risk. Subscribe to our newsletter for updates. Get in touch to explore partnership opportunities.
Sophia's work on this project was funded by the CBAI Summer Research Fellowship.