[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-166699-105":53,"doc-detail-166699-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","mapping-the-generative-ai-risk-space-january-2026-research-briefing","Mapping the Generative AI Risk Space - January 2026 research briefing","","January 2026 MIT CISR research briefing examines how generative AI risk emerges across the full stack—from training data and foundation models to user prompts, hidden system prompts, and the resulting outputs. Using insights from 62 semi-structured interviews with data and technology executives, the briefing explains why GenAI risks scale during experimentation to deployment and toward AI agents. It provides guidance for leaders to recognize where errors, bias, hallucinations, updates, and prompt-based security threats originate, and how to govern safely to realize value.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":11,"@type":70,"position":76},"https://docshare.wps.com/template/presentations/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/mapping-the-generative-ai-risk-space-january-2026-research-briefing/166699/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/mapping-the-generative-ai-risk-space-january-2026-research-briefing/166699.png","ImageObject",442,249,{"name":88,"@type":89},"นรินทร์","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-29","2026-08-31",true,{"@type":98,"interactionType":99,"userInteractionCount":76},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"Where do generative AI risks emerge according to the briefing?","Question",{"text":108,"@type":109},"Risks arise across core components: training data, foundation models, user prompts, hidden system prompts, and the way outputs are evaluated and used.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"Why can hallucinations be difficult to manage in foundation models?",{"text":113,"@type":109},"Foundation models are probabilistic and can generate plausible but factually wrong content, and their internal reasoning is opaque, which makes diagnosis and correction challenging.",{"name":115,"@type":106,"acceptedAnswer":116},"How can prompt-related attacks create security risks?",{"text":117,"@type":109},"Users may unintentionally leak sensitive information in prompts, and malicious prompt injection can manipulate model behavior through hidden instructions in documents or websites.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},166699,1788198424,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":8,"category_name":11,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":76,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":47,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":125,"read_time":73},2336475104957,"https://ap-avatar.wpscdn.com/avatar/22000c4c6bd8a5076e1?x-image-process=image/resize,m_fixed,w_180,h_180&k=1787554080175789136","Speaker 1:\tWelcome to the MIT CISR Research Briefing series. The Center for Information Systems Research is based at the Sloan School of Management at MIT. We study digital trans-formation.\nNick van der Meulen: \tHi, I’m Nick van der Meulen, a research scientist with MIT CISR. Today I’m pleased to share with you the January 2026 research briefing that I co-authored with Hippolyte Lefebvre and Barb Wixom—\nMapping the Generative AI Risk Space\nThe risks entailed in using generative artificial intelligence (or GenAI) have increased markedly as organizations have progressed from experimentation with GenAI tools, to deployment of GenAI solutions, and finally to exploration of AI agents. Exposure to these risks has been amplified by massive, decentralized demand. GenAI’s natural language interface makes it easy to use; its cloud infrastructure makes it ubiquitously available at low cost; and its general-purpose nature makes it applicable to myriad tasks.\nTo govern GenAI effectively, leaders must first understand where the risks emerge. This briefing therefore explores the Generative AI risk space: the set of components that give rise to risk, from the training data that shapes model behavior to the human decisions that determine how model outputs are used. Drawing on sixty-two semi-structured interviews with data and technology executives, we describe these risks and offer guidance for leaders seeking to realize GenAI’s value safely.\nIdentify Risks in Core GenAI Components\nTo make GenAI risks concrete, consider a specific example: a hiring manager using GenAI to draft a job description for a new role. What seems like a simple task—type a request, receive a polished draft—involves multiple components, each introducing distinct risks.\nTraining data: Foundation models have been trained on massive datasets, primarily scraped from across the internet. For our hiring manager, this means the model has absorbed millions of job descriptions and résumés, but also outdated HR practices, biased language, and inaccuracies. As such, the risk is that the model can confidently generate requirements that are incorrect for the hiring manager’s industry or region, or that the output reflects outdated norms rather than current best practices. The organization doesn’t control the training data; it inherits whatever the model’s developer used.\nFoundation model: The foundation model (typically a large language model, or LLM) distills training data into patterns it uses to generate responses. These models are inherently probabilistic, meaning that if the hiring manager provides the exact same input to the model multiple times they’ll obtain different outputs each time. Foundation models also run the risk of generating “hallucinations”: plausible-sounding content that is factually wrong. And because the reasoning inside these models is opaque, organizations can’t determine why a particular output was generated—which makes such errors difficult to diagnose and correct.\nModels also change significantly as vendors push updates, sometimes without adequate notice. One executive described the challenge of keeping pace: “[Model provider] employees are not allowed to present a deck to a customer if it is more than 48 hours old... Because [the provider is] moving so fast, the information in that deck is no longer current.” The risk is thus that what works today may fail after an update.\nUser prompt: For GenAI tools to be effective, users must know how to properly “prompt” the model. The hiring manager needs to provide the right context for the job description, as well as clear instructions and examples of what a good job description looks like. Without clear direction, the model’s output likely won’t meet expectations.\nUsers can also introduce risks unknowingly. When using public GenAI tools, users may inadvertently disclose sensitive information by including confidential data, proprietary strategies, or personally identifiable information in prompts. Or the user coul","cbCaibt3er7kl55W","https://ap.wps.com/l/cbCaibt3er7kl55W","docx",34200,"English","# Mapping the Generative AI Risk Space\n## Identify Risks in Core GenAI Components\n### Training data\n### Foundation model\n### User prompt\n### System prompt\n### Output","[{\"question\":\"Where do generative AI risks emerge according to the briefing?\",\"answer\":\"Risks arise across core components: training data, foundation models, user prompts, hidden system prompts, and the way outputs are evaluated and used.\"},{\"question\":\"Why can hallucinations be difficult to manage in foundation models?\",\"answer\":\"Foundation models are probabilistic and can generate plausible but factually wrong content, and their internal reasoning is opaque, which makes diagnosis and correction challenging.\"},{\"question\":\"How can prompt-related attacks create security risks?\",\"answer\":\"Users may unintentionally leak sensitive information in prompts, and malicious prompt injection can manipulate model behavior through hidden instructions in documents or websites.\"}]","Mapping the Generative AI Risk Space - January 2026 research briefing | DOCX"]