Is AI Actually Dangerous? What 1,663 Recorded Incidents Show
Scope: this page reports what public incident databases record about harm that has already occurred. It does not estimate the probability of future catastrophic outcomes, and it does not treat the absence of a recorded incident as evidence of safety. Crowd-sourced databases systematically undercount harm.
Arguments about AI risk tend to collapse two different questions into one. The first is empirical: what harm has AI actually caused, to whom, and through what kind of system? The second is speculative: what could more capable systems cause in future? Only the first question has data attached to it, and the data is more specific than the debate usually allows.
The recorded total, and what it does not include
The AI Incident Database, an open catalogue of AI-related harms and near-misses maintained by the Responsible AI Collaborative, had logged 1,663 incidents as of a September 16, 2026 sync, of which 1,496 were classified against the MIT AI risk taxonomy.
Three caveats come before any interpretation. The database is crowd-sourced and draws heavily on English-language media, so non-English harm is undercounted. It records harm that was noticed and reported, which favors visible incidents over diffuse ones. And it is revised continuously, so totals cited here will drift.
Incidents per year
| Year | Incidents recorded |
|---|---|
| 2019 | 44 |
| 2020 | 91 |
| 2021 | 80 |
| 2022 | 106 |
| 2023 | 174 |
| 2024 | 299 |
| 2025 | 449 |
| 2026 (partial year) | 212 |
The rise should be read carefully. It reflects more deployment, better reporting, and a broader definition of what counts, not only more danger per unit of use. A catalogue that grows because more people are looking is not the same as a catalogue that grows because more harm is occurring.
Misuse outranks malfunction
The single most useful fact in the dataset is also the least discussed: the largest classified category is not systems failing, it is people using working systems badly on purpose.
| MIT risk domain | Incidents |
|---|---|
| Malicious actors and misuse | 566 |
| AI system safety failures | 313 |
| Discrimination and toxicity | 243 |
| Misinformation | 196 |
| Privacy and security | 112 |
| Human-computer interaction | 42 |
| Socioeconomic and environmental | 24 |
This ordering has a policy implication that neither side of the AI safety debate emphasizes. If misuse is the largest recorded category, then controls on deployment interfaces, identity, and access matter at least as much as controls on model internals. A perfectly aligned model handed to someone intent on fraud still produces harm.
The danger is software, not robots
An analysis of 1,406 incidents by Paligo, published April 23, 2026, categorized incidents by system type. The result inverts the popular image of AI risk.
| System type | Share of documented incidents |
|---|---|
| Software-only systems | 49% |
| Vehicles and mobile robots | 15.1% |
| Consumer devices | 9.3% |
| Weapons systems | 1.9% |
Software-only systems — chatbots, recommendation engines, automated publishing tools, and generation platforms — are implicated in roughly half of documented harm, nearly twice the combined total of all physical categories. Weapons systems, which command a large share of policy attention, appear in under two percent of recorded cases.
Concentration matters more than category. Social media platforms collectively appear in about 19 percent of incidents where a system was named, more than any other category; Facebook alone accounts for about 4 percent and ChatGPT for about 4.3 percent of all incidents. A chatbot error affecting one user is an inconvenience. The same error inside a platform reaching hundreds of millions of users is a systemic event.
Severity: mostly moderate, occasionally fatal
One published severity distribution of recorded incidents breaks down as follows.
| Severity | Share |
|---|---|
| Death or major physical harm | ~3% |
| Significant economic or psychological harm | ~22% |
| Moderate harm or rights violations | ~38% |
| Minor or potential harm | ~37% |
Read plainly: the modal AI incident is a rights violation or a financial loss, not a fatality. Roughly three percent involving death or major physical harm is a small share of a large and growing number, which is exactly the kind of statement that both exaggerates and dismisses the problem depending on how it is quoted.
Documented cases worth knowing
Abstract categories are less persuasive than named cases. These appear in the public record:
- Air Canada. A Canadian tribunal ordered the airline to pay damages after its customer service chatbot gave a passenger incorrect bereavement fare information, making it one of the first companies held legally liable for chatbot output.
- Hong Kong deepfake transfer. A finance worker was reported to have been defrauded of roughly $25 million through a deepfake video conference impersonating company executives.
- Deloitte report refund. A $439,000 report submitted to the Australian government was found to contain fabricated academic citations attributed to AI use, with the firm reportedly refunding part of the fee.
- Child safeguarding report. A child protection worker in Victoria, Australia used ChatGPT to help draft a court report; the resulting document reportedly introduced inaccuracies and downplayed risks in a live safeguarding case.
- Formal-record failures. The AI Incident Database's May–July 2026 roundup lists 19 incidents involving fabricated citations or AI-assisted errors in legal filings and policy documents.
What these share is not sophistication. In each case a capable-seeming tool was used in a context requiring verification, and no verification step existed. That is a process failure as much as a model failure.
Where the evidence stops
Everything above describes systems that exist today. It says nothing about systems that do not exist yet, and it should not be used in either direction.
- The incident record cannot estimate the probability of future catastrophic outcomes, because it contains no observations of such outcomes.
- The incident record cannot rule them out either. Absence from a crowd-sourced catalogue built from media reports is not evidence of safety, particularly for harms that are diffuse, classified, or slow.
- Generative systems now dominate new entries — roughly 58 percent of 2025 entries, up from about 5 percent in 2021 — so the record increasingly describes the technology currently under debate rather than the older systems it replaced.
The honest summary is narrow and still useful: AI today causes mostly moderate, mostly software-mediated, mostly misuse-driven harm at growing volume, and the question of what more capable systems might cause remains genuinely open because there is no data that settles it.
What to do with this
For anyone deploying AI rather than debating it, the distribution above points to specific controls:
- Verify before it ships. Most documented harm in the formal-record category came from unverified generated content in legal, policy, or clinical settings. Require a citation or a human check for anything that becomes an official record.
- Assume misuse, not malfunction. Since misuse is the largest category, threat-model your deployment against an intentional abuser, not only against a broken model.
- Watch the platform effect. If your system sits on a large platform, a single error scales. Rate limits, audit logs, and rollback paths matter more than marginal accuracy gains.
- Log incidents internally. Your own near-miss log is more relevant to your risk than any public database.
Frequently asked questions
How many AI incidents have been recorded?
The AI Incident Database had logged 1,663 incidents as of a September 16, 2026 sync, with 1,496 classified by MIT risk domain. The database is crowd-sourced and understood to undercount real-world harm.
What causes the most documented AI harm?
Malicious actors and misuse, at 566 classified incidents, ahead of AI system safety failures at 313. People misusing working systems cause more recorded harm than systems failing.
Are robots and self-driving cars the main AI danger?
No. Software-only systems were implicated in about 49 percent of 1,406 analyzed incidents, versus 15.1 percent for vehicles and mobile robots and 1.9 percent for weapons systems.
How severe are recorded AI incidents?
By one distribution, about 3 percent involved death or major physical harm, 22 percent significant economic or psychological harm, 38 percent moderate harm or rights violations, and 37 percent minor or potential harm.
Does the incident record prove anything about existential risk?
No. The database records harm that has already occurred from deployed systems. It is evidence about the present, not about hypothetical future capabilities.
Primary sources
- AI Incident Database — primary catalogue, incident counts and taxonomy
- AI Incident Roundup, May–July 2026 — recent incident categories
- AI Policy Tracker — AI incidents — yearly trend and MIT risk domain breakdown
- Paligo analysis of 1,406 incidents (April 23, 2026) — system-type distribution
- Pacing the Frontier debate — how these risks are being argued about in September 2026
Bottom line
The recorded evidence describes a real but unglamorous problem: harm that is mostly moderate in severity, mostly software-mediated, and mostly caused by people misuse rather than systems malfunctioning. That profile argues for verification steps, misuse threat models, and platform-level controls — not for either complacency or panic. On the larger question of what more capable systems might do, the databases are silent, and no amount of quoting them changes that.