AI threat catalogueHarmful ContentProduction
Unethical Actions
The AI system recommends or produces actions that are legal but ethically questionable, such as manipulation, deception, or exploiting vulnerable users.
Description
Unlike clearly unlawful or criminal content, this concerns practices in an ethical grey area: misleading lines of argument, covert influence, or so-called dark patterns, meaning design choices that push people toward decisions against their own interest. Common content filters rarely catch this, because the behavior does not appear overtly harmful. The AI Act draws the line at deliberately manipulative or deceptive techniques and at exploiting the vulnerability of specific groups of people.
Possible impact
The damage lies mainly in loss of trust and in ethical and reputational consequences for the operator. Where the system's behavior approaches targeted manipulation or the exploitation of vulnerable people, it can move into the range of practices prohibited by the AI Act.
Example
A sales assistant advises pushing undecided customers toward a hasty purchase using artificial scarcity and misleading countdown displays.
Recommended mitigations (5)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
Ethical guidelines in trainingGovernance & compliance
- Effect
- Preventive
- Implementation level
- Model & training, Organization
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Ethical guidelines in training” is primarily a governance and compliance control: Binding rules, control objectives, or oversight define permitted use and accountability; complemented by binding workflows.
Constitutional AI methodsTechnical
- Effect
- Preventive
- Implementation level
- Model & training
- Reason for the classification
- “Constitutional AI methods” is primarily technical: A model, training, or data-processing method directly changes system behavior or robustness.
Ethics review boardsGovernance & compliance
- Effect
- Preventive
- Implementation level
- Organization
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Ethics review boards” is primarily a governance and compliance control: Binding rules, control objectives, or oversight define permitted use and accountability; complemented by binding workflows.
Transparency about model behaviorGovernance & compliance
- Effect
- Preventive
- Implementation level
- Organization, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Transparency about model behavior” is primarily a governance and compliance control: Binding rules, control objectives, or oversight define permitted use and accountability; complemented by binding workflows.
Refusal patterns for manipulative requestsTechnical
- Effect
- Preventive
- Implementation level
- Model & training, Application, API & agents
- Reason for the classification
- “Refusal patterns for manipulative requests” is primarily technical: System-enforced inspection, transformation, or blocking rules stop or neutralize disallowed content before further processing.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (5)
Every reference states the framework, the exact location and the publishing organisation.
- NIST AI RMF Section 2.3 Dangerous, Violent, or Hateful ContentSection 2.3, pp. 6–7 National Institute of Standards and Technology (NIST)Original
- MITRE ATLAS AML.T0048.002 Societal HarmATLAS.yaml technique object with id AML.T0048.002 (pinned release v5.6.0) MITREOriginal
- EU AI Act Article 5(1)(a) Prohibited AI practicesArticle 5(1)(a); where the catalogue cites exploitation, compare Article 5(1)(b) European Union (EUR-Lex)Original
- EU AI Act Article 55(1)(b) Obligations of providers of general-purpose AI models with systemic riskArticle 55(1)(b) European Union (EUR-Lex)Original
- EU AI Act Article 9(1), 9(2)(a), 9(2)(d) Risk management systemArticle 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) European Union (EUR-Lex)Original
Related threats
More entries from the topic group Harmful Content.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“Unethical Actions”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/unethical-actions/