Summary: The Code of Practice’s taxonomy of what makes an AI risk systemic — five risk types, five defining characteristics, three source categories, and four named specified risks including cyber offence and loss of control.
Sources: raw/Laws/Overview of the Code of Practice...md (Appendix 1); raw/AI-regulations/Regulation - EU - 2024_1689.md (Art 3(65), Art 51)
Last updated: 2026-07-28
Five types of risk
Under Art 3(65) AI Act, risks are classified under five primary types “which may overlap” (source: Overview of the Code of Practice…md):
- Risks to public health
- Risks to safety
- Risks to public security
- Risks to fundamental rights
- Risks to society as a whole
Examples given: “threats to critical infrastructure, public mental health, freedom of expression, data privacy, economic security, the environment, and democracy,” plus disinformation, non-consensual intimate imagery (NCII), and child sexual abuse material (CSAM).
What makes a risk systemic
Essential characteristics — all three required. A risk is systemic when it:
- “Is specific to high-impact AI capabilities,”
- “Has significant effects across the EU market, and”
- “Can scale through the AI value chain.”
The third is the one that separates systemic risk from ordinary product risk: propagation through the supply chain of models, integrators and deployers.
Contributing characteristics:
- Capability- or reach-dependence — “Risk grows with model power or use.”
- High velocity — “Rapid onset, outpacing mitigations.”
- Cascading impact — “Triggers chain reactions.”
- Irreversibility — “Persistent or permanent harm.”
- Asymmetry — “Few actors can cause large-scale effects.”
This list is a usable severity rubric on its own, independent of EU compliance. It is notably better suited to AI incidents than CVSS, which has no concept of velocity, cascade or asymmetry.
Three sources of systemic risk
Model capabilities — “Offensive cyber or CBRN capabilities,” “persuasive or deceptive interaction,” “autonomy, self-replication, or planning,” “tool use and control of physical systems,” “self-reasoning and evasion of oversight.”
Model propensities — “Misalignment with human intent or values,” “discriminatory bias, hallucinations, or lawlessness,” “goal persistence or power-seeking,” “collusion or conflict with other systems.”
Affordances and other sources — “Access to powerful tools or infrastructure,” “weak security, poor oversight, or misuse,” “wide-scale deployment or user base,” “vulnerabilities in release strategies,” “inadequate explainability or transparency.”
The capability/propensity/affordance split is doing real work. A capability is what the model can do, a propensity is what it tends to do, an affordance is what its environment lets it do. Three different mitigation surfaces:
- Capability → evaluation and elicitation
- Propensity → training and alignment
- Affordance → deployment architecture and security controls
Most of the agentic attack surface is an affordance problem, which is the one an integrator — not the model provider — controls.
The four specified systemic risks
Treated as specified risks for identification purposes (Measure 2.1):
- CBRN risk — “AI lowering barriers or increasing the impact of chemical, biological, radiological, or nuclear attacks.”
- Loss of control — “Human inability to modify or shut down models due to misalignment, autonomy, or resistance.”
- Cyber offence — “AI enabling advanced cyber-attacks, especially on critical infrastructure.”
- Harmful manipulation — “Strategic persuasion or deception targeting populations or decision-makers, potentially undermining democratic processes or fundamental rights.”
Cyber offence and harmful manipulation are the two that connect directly to this vault’s attack corpus. Harmful manipulation is PITAX’s persuasion cluster pointed outward — the same levers, applied to humans at scale rather than to models.
Note what is not on the list: prompt injection, agent hijacking, and tool poisoning are not specified systemic risks. They would arrive via the “weak security, poor oversight, or misuse” affordance source or as enablers of cyber offence, but they are not named.
The classification threshold
Art 51(2) presumes high-impact capability above 10²⁵ FLOP cumulative training compute, amendable by delegated act. Art 51(1)(b) allows Commission designation on capability or impact equivalence per Annex XIII, including “following a qualified alert from the scientific panel.” See GPAI and systemic risk and governance bodies.
Acceptance and safety margins
Commitment 4 requires determining risk acceptability “applying defined risk-tier frameworks with built-in safety margins,” and Commitment 1 requires forecasting “when models are anticipated to surpass the current highest risk tier” (source: Overview of the Code of Practice…md).
Appendix 2’s “similarly safe or safer models” mechanism allows benchmarking against a “safe reference model” — a comparative rather than absolute standard, which is the same logic as the Commitment 6 exclusion for models no more capable than an already-public open-weight one.