Versatile AI Risk Assessment

AI threat catalogueHarmful ContentProduction

Illegal Activities

The AI system assists with unlawful activities, for example by providing instructions for drug synthesis, weapon creation, hacking, fraud, or circumventing sanctions.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 7 verified sources

Description

On direct request or after a jailbreak (the circumvention of the model's built-in safety controls), the model compiles knowledge and action steps for crimes and presents them in an accessible way. The core risk is what is called uplift: the system lowers the expertise threshold and effort that a perpetrator would otherwise need. Authorities such as the German BSI describe how information about vulnerabilities, criminal methods, and their exploitation can be obtained more easily this way.

Possible impact

Operators face legal liability and, in individual cases, criminal exposure, because the system makes it easier to commit real offenses. For especially capable models this counts as a systemic risk under the AI Act, for instance in the area of dangerous chemical, biological, radiological, or nuclear (CBRN) agents or offensive cyber capabilities.

Example

An employee bypasses the safety controls of an assistant and obtains a step-by-step guide to producing an illegal substance or breaking into someone else's network.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM01:2025NIST AI RMF Section 2.1 · Section 2.3MITRE ATLAS AML.T0048.002EU AI Act Article 55(1)(b)BSI R10 · R12

Verified references (7)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Harmful Content.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Illegal Activities”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/illegal-activities/

← Back to the full catalogue