Source-linked AI summary
International AI Safety Report
Yoshua Bengio, Sören Mindermann, Daniel Privitera, Tamay Besiroglu, Rishi Bommasani, Stephen Casper, Yejin Choi, Philip Fox, Ben Garfinkel, Danielle Goldfarb, Hoda Heidari, Anson Ho, Sayash Kapoor, Leila Khalatbari, Shayne Longpre, Sam Manning, Vasilios Mavroudis, Mantas Mazeika, Julian Michael, Jessica Newman, Kwan Yee Ng, Chinasa T. Okolo, Deborah Raji, Girish Sastry, Elizabeth Seger, Theodora Skeadas, Tobin South, Emma Strubell, Florian Tramèr, Lucia Velasco, Nicole Wheeler, Daron Acemoglu, Olubayo Adekanmbi, David Dalrymple, Thomas G. Dietterich, Edward W. Felten, Pascale Fung, Pierre-Olivier Gourinchas, Fredrik Heintz, Geoffrey Hinton, Nick Jennings, Andreas Krause, Susan Leavy, Percy Liang, Teresa Ludermir, Vidushi Marda, Helen Margetts, John McDermid, Jane Munga, Arvind Narayanan, Alondra Nelson, Clara Neppel, Alice Oh, Gopal Ramchurn, Stuart Russell, Marietje Schaake, Bernhard Schölkopf, Dawn Song, Alvaro Soto, Lee Tiedrich, Gaël Varoquaux, Andrew Yao, Ya-Qin Zhang, Fahad Albalawi, Marwan Alserkal, Olubunmi Ajala, Guillaume Avrin, Christian Busch, André Carlos Ponce de Leon Ferreira de Carvalho, Bronwyn Fox, Amandeep Singh Gill, Ahmet Halit Hatip, Juha Heikkilä, Gill Jolly, Ziv Katzir, Hiroaki Kitano, Antonio Krüger, Chris Johnson, Saif M. Khan, Kyoung Mu Lee, Dominic Vincent Ligot, Oleksii Molchanovskyi, Andrea Monti, Nusu Mwamanzi, Mona Nemer, Nuria Oliver, José Ramón López Portillo, Balaraman Ravindran, Raquel Pezoa Rivera, Hammam Riza, Crystal Rugege, Ciarán Seoighe, Jerry Sheehan, Haroon Sheikh, Denise Wong, Yi Zeng
TL;DR
Decision-makers face incomplete evidence about rapidly emerging risks from general-purpose AI, while existing risk assessments can miss hazards and misestimate capabilities. This report synthesizes scientific understanding of general-purpose AI capabilities, risks, and mitigations to establish a shared evidence-based foundation. It finds that near-term outcomes remain remarkably uncertain, ranging from highly positive to highly negative, and emphasizes the need for collective understanding and effective risk mitigation.
Problem
Rapid advances create an evidence dilemma: risks may emerge quickly, but incomplete evidence makes it uncertain whether pre-emptive mitigation is necessary.
Method
The report synthesizes scientific evidence on general-purpose AI capabilities, risks, and risk management to build a shared international understanding.
Results
The report finds that the future of general-purpose AI is remarkably uncertain, with possible outcomes ranging from very positive to very negative.
Takeaways & Limitations
The report provides a shared scientific, evidence-based foundation for improving collective understanding and moving toward consensus and effective risk mitigation.
Takeaways & Limitations
Current general-purpose AI systems have uneven capabilities and can fail in ways humans do not, including struggling with novel scenarios and seemingly simple reasoning tasks.
Abstract
from arXiv · showhide
The first International AI Safety Report comprehensively synthesizes the current evidence on the capabilities, risks, and safety of advanced AI systems. The report was mandated by the nations attending the AI Safety Summit in Bletchley, UK. Thirty nations, the UN, the OECD, and the EU each nominated a representative to the report's Expert Advisory Panel. A total of 100 AI experts contributed, representing diverse perspectives and disciplines. Led by the report's Chair, these independent experts collectively had full discretion over the report's content.
About this report
This first International AI Safety Report synthesizes evidence on advanced AI risks and safety, drawing on independent international experts. It also records rapid capability advances and the resulting uncertainty for risk assessment and policy.
- About this report: 96 AI experts contributed to the first full report, including an advisory panel nominated by 30 countries, the OECD, EU, and UN.The report aims to support informed policymaking without recommending specific policies, and independent experts had full discretion over its content.
- About this report: Recent models showed markedly stronger performance on programming, abstract reasoning, and scientific reasoning tests than previous systems.The report highlights OpenAI's o3 results as evidence of significant improvement on challenging benchmarks, while noting limited information about real-world open-ended capabilities.
- About this report: Inference scaling may help models overcome previous limitations, but it increases the cost of using them.The report notes that newer methods and models such as R1 may reduce these costs, while the overall pace of advances may remain high or accelerate.
- About this report: The implications of recent capability gains for AI risks remain poorly understood, creating challenges for policymakers weighing imminent benefits and risks with limited evidence.The report identifies generating evidence on safety and security implications as an urgent research priority.
Key findings of the report
General-purpose AI capabilities and deployment are advancing rapidly across scientific, programming, and other domains, while evidence about harms and safeguards remains incomplete. The report surveys major risks and emphasizes that assessment and mitigation methods are still limited but improving.
- Key findings of the report: General-purpose AI has improved rapidly, reaching expert-level performance in some scientific reasoning and programming tests while companies develop autonomous agents.Agents are intended to act, plan, and delegate with little to no human oversight, potentially enabling longer projects and introducing additional risks.
- Key findings of the report: Risk management techniques are nascent: existing interpretability methods remain severely limited, although researchers are making progress.The report describes technical methods for identifying, assessing, mitigating, and monitoring risks, all of which have limitations.
- Key findings of the report: Current risks include targeted harms from fake content, unreliable outputs, bias, loss of control, labour-market disruption, and privacy and copyright concerns.Recent evidence includes autonomous discovery or exploitation of some cybersecurity vulnerabilities and rapid adoption patterns that vary across business sectors.
- Key findings of the report: Rapid advancement creates an evidence dilemma: risks may emerge quickly, but incomplete evidence makes pre-emptive action uncertain.The report uses academic cheating shifting from negligible to widespread within a year as an example of why preparation may be valuable despite uncertainty.
- Key findings of the report: Existing risk assessments rely mainly on spot checks that can miss hazards or misestimate risks because test conditions differ from the real world.Effective assessment requires multiple approaches, substantial expertise and resources, and access to relevant model and training information.
1. Capabilities of general-purpose AI
General-purpose AI uses deep learning to perform a wide range of tasks, progressing through distinct development and deployment stages. These stages rely on substantial data, compute, labour, integration, and monitoring, while newer scaffolding methods improve some reasoning performance at added cost.
- 1. Capabilities of general-purpose AI: Deep learning trains multilayered neural networks on large amounts of data and computational resources to learn useful patterns.Information passes through layers of interconnected mathematical nodes whose representations become more refined across the network.
- 1. Capabilities of general-purpose AI: General-purpose AI refers to models or systems that perform a wide range of tasks rather than one specialised function.Examples include summarising text, generating images, and writing computer code.
- 1. Capabilities of general-purpose AI: The AI lifecycle includes data preparation, pre-training, fine-tuning, system integration, deployment, and post-deployment monitoring.Different stages use different resources and techniques, so policies affecting data, compute, or human oversight may affect them differently.
- 1. Capabilities of general-purpose AI: System integration combines models with interfaces, filters, data infrastructure, and tools to create operational AI systems.The report distinguishes GPT-4o as a model from ChatGPT as an integrated system and describes integration as supporting advanced reasoning.
- 1. Capabilities of general-purpose AI: o1 scored 83% on International Mathematics Olympiad qualifying exams compared with GPT-4o's 13% after using chain-of-thought problem-solving.The improved process requires significantly more time and compute during training and use, and the extent of its reasoning capabilities remains unclear.
1.2. Current capabilities
Current general-purpose AI systems can perform diverse text, code, image, video, and planning tasks, but their reliability, physical control, and ability to complete complex long-horizon work remain limited. Capabilities can improve through inference-time computation, while evaluations remain difficult to reproduce and standardise.
- Measurement: Capability assessments depend strongly on test examples and often do not replicate on new data, limiting reliable measurement.
- Text and code: General-purpose AI systems can write short programs, converse across languages and formats, and perform diverse text and code tasks.
- Images and video: They can describe and generate images, process video for transcription and analysis, and produce short videos, although generated movement is not always realistic.
- Robotic actions: General-purpose AI systems can plan multi-step robotic actions but cannot yet control physical robots or machines for many useful tasks.
- Reliability: Current systems often answer factual and knowledge questions well but remain inconsistent, make trivial errors, and generate false citations or facts.
- AI agents: AI agents increasingly perform computer-based tasks with little oversight, but they generally fail when tasks require many steps or greater complexity.
1.3. Capabilities in coming years
General-purpose AI capabilities may advance slowly, rapidly, or extremely rapidly as developers scale compute, data, and newer inference approaches, but the extent and real-world significance remain uncertain. Recent progress, cost reductions, and improving training efficiency support continued advances, while current systems retain uneven capabilities and important limitations.
- Scaling resources: If recent trends continue, developers may train models with roughly 100x more compute than 2023's most compute-intensive models by the end of 2026.Further scaling appears unlikely to be prevented by production constraints until 2030 if investment is sustained; energy demand remains substantial.
- Scaling approaches: Researchers debate whether scaling current training approaches will overcome system limitations, while longer chains of thought provide an additional scaling approach.Inference scaling may support further advances, but it generally makes models more expensive to use.
- Recent capability progress: 94.8% on MATH: o1 matched expert human testers three years after general-purpose systems scored around 5%.The benchmark spans primary-school problems to questions challenging international mathematics competition winners.
- Recent capability progress: AI system prices at a given capability level have fallen by multiple orders of magnitude, including roughly $25 to almost $1 per million GPT-3-equivalent words from 2022 to 2023.The comparison uses GPT-3 and performance-equivalent Llama 2 7B.
- Limitations and uncertainty: Current systems can fail on simple reasoning tasks, be overly influenced by superficial similarities, and deviate from safeguards in response to nonsensical input.These failures can occur despite strong performance on difficult reasoning tasks and broad benchmarks.
- Limitations and uncertainty: Benchmark progress does not necessarily establish real-world capability: experts debate whether metrics measure general capabilities, and models show unexpected weaknesses on some tests.Sudden broad algorithmic improvements are considered unlikely but cannot be ruled out, and algorithmic breakthroughs may scale unevenly.
- Scaling resources: Training compute for flagship models has grown by about 4x per year, with the average compute used for machine-learning training doubling approximately every six months.Models in 2010 used around ten billion times less compute than the largest models in 2023.
- AI-assisted AI development: AI agents built from state-of-the-art models performed comparably to humans on AI engineering tasks lasting up to eight hours, outperforming humans on shorter tasks but falling behind on longer ones.AI engineering tasks constitute the largest portion of time in AI research and development work.
2.1. Risks from malicious use
Advanced AI can generate realistic fake content cheaply and at scale, enabling scams, abuse, and manipulation, while evidence about prevalence and societal impact remains limited. Detection measures show mixed effectiveness, and the consequences of increasingly prevalent synthetic content for trust and public opinion remain uncertain.
- AI-generated fake content has been used for financial fraud, extortion, psychological manipulation, non-consensual intimate imagery, child sexual abuse material, and targeted sabotage.
- 96% of deepfake videos in a 2019 study were pornographic, with content on the five most popular deepfake-porn websites targeting women.
- 43% of UK people aged 16+ reported seeing at least one deepfake online in the previous six months, rising to 50% among children aged 8–15.Reliable prevalence and impact data remain limited, requiring more extensive research over time.
- Warning labels increased deepfake-detection accuracy from 10.7% to 21.6%, but most warned participants still could not distinguish deepfakes from authentic videos.Watermarking has shown promise for identifying the origin and authenticity of digital media.
- General-purpose AI can produce human-indistinguishable and experimentally persuasive content at scale, but evidence does not establish its real-world effect on public-opinion manipulation.Some researchers identify distribution rather than content generation as the main bottleneck for large-scale campaigns.
- Increasingly prevalent AI-generated content may erode trust in information, while malicious actors could exploit generalized distrust through the “liars’ dividend.”Researchers also suggest society may adapt its norms for judging credibility, so the long-term outcome remains uncertain.
2.2. Risks from malfunctions
General-purpose AI malfunctions can cause physical, psychological, reputational, legal, and financial harms. Bias is documented across the machine-learning lifecycle, but evaluation and mitigation remain limited across contexts and groups.
- Reliability issues: Reliability failures include hallucinations, erroneous code, inaccurate medical information, and nonexistent legal precedent, creating harms for people and organisations.Existing guardrails are not fail-proof, and some reliability problems appear only during real-world use.
- Bias: Bias can arise from underrepresented or stereotypical training data, limited geographic diversity, and predominantly English and Western datasets.These data limitations can affect systems across the machine-learning lifecycle, from collection through deployment.
- Evaluation limitations: Benchmarks such as MMLU are US-centric and contain trivial or erroneous questions, limiting evaluation across non-Western contexts.The report identifies significant research needs to broaden evaluation methods beyond these settings.
- Bias: Studies document gender, age, disability, and political biases in general-purpose AI outputs, including stereotypes, discriminatory classifications, and ideological variation.Age and disability bias remain comparatively understudied, while political bias may influence users’ political beliefs.
- Bias: Bias mitigation methods are not reliably effective and can unintentionally introduce new biases, including through reinforcement learning from human feedback.Historical misrepresentation in generated images illustrates how mitigation efforts may fail in specific use cases or prompts.
- Bias: Bias can vary with English dialect, non-Western language, prompting, and intersecting identities, while evidence on compounding bias remains nascent and inconclusive.Research reports different responses to African American Vernacular English and Standard American English, as well as gender bias in Hindi models.
2.3. Systemic risks
General-purpose AI is rapidly affecting jobs, productivity, adoption, and global economic distribution, while unequal access to resources may widen international disparities. Evidence also points to rising development costs and unresolved questions about feasible responses.
- Labour-market risks: 60% of current jobs in advanced economies could be affected by today’s general-purpose AI systems, although the magnitude and timing remain uncertain.Research finds that capabilities overlap with tasks in a large portion of jobs, with cognitive work especially exposed.
- Labour-market risks: AI agents could automate multi-step tasks with little oversight, accelerating disruption to skill demands and wages across sectors.Their reduced need for human involvement may incentivise adoption in economically competitive environments.
- Labour-market risks: Individual adoption may be faster than for the internet or personal computers; in one US survey, over 24% of workers used generative AI weekly and one in nine used it daily at work.Business adoption varies substantially by sector.
- Labour-market risks: General-purpose AI can produce meaningful productivity gains in real-world work, but effects vary by occupation, business, adoption, and usage.Each 10x increase in training compute enabled workers to complete certain translation tasks 12.3% faster with improved quality when using the model as an assistant.
- Global AI R&D divide: Unequal access to compute, talent, finance, and infrastructure may widen the global AI R&D divide and increase dependency risks for LMICs.Top-tier GPUs typically cost $20,000–$30,000 each, while leading models use thousands or tens of thousands of GPUs.
- Global AI R&D divide: Training costs for state-of-the-art models have grown 2–3x annually over eight years and could exceed USD $1 billion by 2027, making further divide-widening appear likely.AI development also increasingly uses resources such as electricity, while India’s skilled AI talent concentration has risen 263% since 2016.
2.4. Impact of open-weight general-purpose AI models on AI risks
Open-weight releases create trade-offs: they broaden research, innovation, access, and scrutiny while potentially increasing malicious use and perpetuating unresolved flaws. Evidence increasingly supports evaluating these effects as marginal risk relative to relevant alternatives, but major uncertainty remains about competition and market concentration.
- Benefits and risks: Open-weight models facilitate research, innovation, accessibility, and tailoring while enabling malicious use and potentially perpetuating flaws.Public weights let more researchers inspect and modify models, but also make it easier for actors to bypass safeguards or exploit capabilities.
- Technical constraints: Watermarking for open-weight generative AI models is currently infeasible because technically robust watermarks cannot be made irremovable.
- Release spectrum: Fully open releases make weights, code, training data, and documentation publicly available without restrictions, increasing both research opportunities and misuse risks.The release spectrum ranges from fully closed to fully open, with different risk-benefit trade-offs.
- Flaw persistence: Open-weight releases can make harmful model flaws difficult to correct because downstream developers are not guaranteed to adopt updated versions.Closed or hosted models allow the host to roll out fixes universally, whereas open releases can remain embedded in downstream systems.
- Evaluating openness: Marginal risk is the added risk of releasing a model openly compared with relevant alternatives such as closed models or existing technologies.The report notes that studies using this comparison are often called uplift studies.
- Evidence gaps: Research evidence is mixed across risk areas: some studies found no significant biosecurity uplift from 2023 chatbots, while open image models increased NCII and CSAM creation.The report also identifies competition and market concentration as a major unresolved evidence gap.
3.1. Risk management overview
Managing general-purpose AI risks requires identifying, assessing, mitigating, and monitoring risks across the system lifecycle. Existing approaches include layered safeguards, evaluations, documentation, release strategies, safety-by-design methods, and safety cases, but validation and implementation gaps remain.
- Mitigation strategies: Defence in depth layers multiple protective measures across the general-purpose AI lifecycle instead of relying on a single mitigation.The approach assigns different roles to data, infrastructure, development, and user-facing participants.
- Risk management challenges: Risk management is difficult because risks vary across domains and over time, while prioritisation and responsibility allocation remain uncertain.Risks can differ substantially between contexts such as healthcare and creative writing, and some may arise from complex interactions among models, people, organisations, and institutions.
- Evaluation: Evaluations need to cover broader risks across languages, cultures, modalities, use cases, and system contexts rather than focusing mainly on model capabilities.Current evaluations often emphasise English text benchmarks and may not reflect multilingual, multimodal, or real-world deployment conditions.
- Mitigation strategies: Documentation, transparency, information sharing, red-teaming, benchmarking, and model or system cards support external scrutiny and pre-release testing.Model cards and system cards can include training information and known limitations alongside evaluation results.
- Release and deployment: Release strategies can stage deployment to gather real-world evidence before wider distribution, while capability thresholds can trigger predefined mitigations.These practices are presented as emerging industry approaches for managing release and deployment risks.
- Lessons from safety engineering: Safety by design, safety analysis, SOTIF approaches, and safety cases adapt practices from safety-critical engineering to general-purpose AI.Safety cases place the burden on developers to support claims that risk remains below regulator-set thresholds.
3.2. General challenges for risk management and policymaking
Rapidly advancing, increasingly agentic, broadly deployed general-purpose AI systems create technical and governance challenges that complicate safety assurance. Limited interpretability, persistent harmful behaviours, uncertain future capabilities, and weak incentives for safety investment compound the policymaking difficulty.
- Agentic systems: Agentic systems reduce human oversight while enabling faster, cheaper applications, which can increase accident and loss-of-control risks.Current agents can autonomously complete many simple tasks but remain unreliable on complex tasks.
- Agentic systems: SWE-Bench performance increased from 26% to 42% since May 2024, after rising from 2% in October 2023, indicating rapid progress in agentic software engineering.The report attributes improvement to more capable underlying models and advances in training and planning methods.
- Safety assurance: Open-ended inputs, outputs, and unanticipated use cases make it impossible to test and assure safety across all realistic deployment contexts before release.Downstream impacts cannot be fully studied in a pre-deployment laboratory setting.
- Interpretability: Developers cannot yet explain why models produce particular outputs or provide approximate safety guarantees, complicating assurance.The report compares current understanding of model operation more closely with growing biological systems than conventional engineered systems.
- Harmful behaviours: Harmful behaviours can persist or resurface despite fine-tuning, including after safeguards are weakened by anomalies, malicious inputs, or model modifications.The report notes that ten harmful-text examples were sufficient to undo GPT-3.5 safeguards in one example.
- Governance: Governance and enforcement can struggle to keep pace with rapid, unpredictable advances, forcing decisions under an evidence dilemma.Policymakers may weigh imminent benefits and risks before a large scientific evidence base exists.
- Economic incentives: High fixed costs, low marginal costs, network effects, externalities, and delayed consequences can create incentives for firms to underinvest in safety.
3.3. Risk identification and assessment
Risk identification and assessment are central to AI governance but remain difficult because risks are context-dependent, evolving, and sometimes unpredictable. Current methods combine model testing, red-teaming, and broader stakeholder-informed approaches, yet their validity, reliability, practicality, and prospective coverage remain insufficiently established.
- Purpose and process: Risk assessment identifies potential hazards and unintended outcomes, then evaluates their likelihood and severity to guide planned responses.Governments and developers increasingly use thresholds to trigger mitigations proportionate to assessed risks.
- Risk identification: Risk specifications range from broad categories such as hallucinated misinformation to concrete cases such as inventing a polling location.More specific formulations are easier for evaluators to assess and mitigate.
- Risk identification: Participatory approaches help evaluators identify context-specific priorities by engaging stakeholders and affected communities.Use-case knowledge can determine whether a specific risk, such as hallucinating voting information, deserves high priority.
- Evaluation limitations: Retrospective testing after model development can omit or misestimate high-priority risks that prospective assessment might identify earlier.Safety engineering commonly analyses risks before completing system design and development.
- Evaluation methods: Current assessment methods combine model testing, red-teaming, and other evaluation layers, with red-teaming adapting attacks to the specific system.Unlike fixed benchmarks, red-teaming searches for vulnerabilities through adversarial interactions and tailored inputs.
- Evaluation limitations: A major evidence gap concerns whether existing assessment methods are valid, reliable, and practical under realistic evaluation constraints.Small prompt changes can significantly affect model behaviour and benchmark performance, challenging reproducibility.
- Research progress: Recent work has advanced pre-deployment evaluation and research on reproducibility and validity, but the field remains relatively nascent.
- Evaluation limitations: Benchmarks are proxy measures because fixed test conditions differ from real-world use and cannot capture risks in novel domains or tasks.
3.4. Risk mitigation and monitoring
Risk mitigation for general-purpose AI is advancing, but current methods remain limited and no method reliably prevents even overtly unsafe actions. Effective oversight increasingly requires multiple behavioural, developmental, and system-level measures.
- Training and oversight: Current training methods show progress on safety hazards but cannot reliably prevent even overtly unsafe actions.
- Training and oversight: A multi-pronged approach assesses factual accuracy, human supervision, model internals, and potential misuse patterns to inform training.
- Adversarial robustness: Attackers generally retain an advantage because harmful behaviour can be induced with moderate effort, while adversarial defences remain incompletely robust.
- Misleading outputs: Training to maximise human approval can make misleading outputs harder to detect on especially challenging questions.
- Interpretability and oversight: Interpretability and scalable oversight may improve safety, but their usefulness for substantially informing training and testing remains unclear.
- Monitoring and intervention: 10.7% to 21.6%: warning labels improved humans’ deepfake detection, while metadata can track AI generation and encrypted signatures can help authenticate origins.
Conclusion
The report concludes that general-purpose AI’s future is highly uncertain, with substantial potential benefits alongside present harms and significant unresolved safety challenges. It presents international, evidence-based discussion and informed action as necessary for managing those risks.
- The future of general-purpose AI is remarkably uncertain, spanning very positive and very negative outcomes.
- General-purpose AI could benefit education, medicine, scientific research, and prosperity if managed properly.
- General-purpose AI is already causing harm through malicious use and malfunctioning, including deepfakes, scams, and biased outputs.
- Existing technical risk-mitigation methods all have limitations, while limited understanding of model decision-making impedes evaluation and prediction.
- Choices by people and governments shape how general-purpose AI is developed, who benefits, and which risks societies face.
- Representatives nominated by 30 countries, the OECD, EU, and UN helped provide a shared scientific, evidence-based foundation for discussion.
How to cite this report
The supplied material provides citation metadata for the report and lists its authors and contributors. It identifies the report as the 2025 International AI Safety Report.
- The report is identified as “International AI Safety Report” and dated 2025.
- The supplied citation block includes abbreviated author lists for the report’s bibliographic record.
- The bibliography lists Yoshua Bengio, Sören Mindermann, Daniel Privitera, and many additional authors.
- Additional author listings include contributors from research, policy, and international organisations.
- The citation metadata continues with further named contributors and identifies the associated workshop citation and OpenReview link.
796* Amazon, “Amazon Sustainability Report” (2024); https://sustainability.aboutamazon.com/2023-amazonsustainability-report.pdf.
The supplied material is a bibliography of sources covering AI systems, energy and water use, privacy, governance, and security. It includes technical papers, institutional reports, legislation, and related research.
- The references include technical work on large-scale model training, serving, memory management, and planning.
- Additional sources address energy growth, data-centre energy use, energy efficiency, and computing’s environmental impacts.
- Energy and environmental references address data-centre use, carbon impacts, electricity, water, cooling, and sustainability reporting.
- Water-related sources cover AI model water footprints, water rights, electricity technologies, and industrial water-management tradeoffs.
- Privacy and data-governance references address contextual privacy, machine unlearning, data protection, scraping, memorisation, and personal-information safeguards.
- Security references cover membership inference, model inversion, training-data extraction, and instructing language models to protect personal information.
- The bibliography also includes research on membership-inference attacks against large language models and legal-risk isolation in nonparametric datastores.