← AI Safety & Governance
AI Safety Explainer June 2026 · SCAIO

A Plain-Language Map of AI Risk

Almost every unproductive argument about AI risk is really two people pointing at different risks and assuming they're discussing the same one. A simple map fixes most of it — locate any risk by where it comes from, and how far off it is.

"Is AI dangerous?" is a question with no useful answer, because "AI risk" isn't one thing. It's a category containing harms as different as a scammer cloning your grandmother's voice, a hiring tool quietly screening out qualified applicants, and a hypothesized future system no one can switch off. Treating those as a single topic is why the conversation so often collapses into the doom-versus-denial shouting match this series exists to avoid.

The fix is a map. You can locate almost any AI risk by asking two questions — and once a risk is located, the right response usually becomes obvious, and the wrong arguments fall away.

Question one
Where does the harm come from — a person, a malfunction, or the system as a whole?
Question two
Is it here now, emerging, or over the horizon?

Question one: three sources of harm

Almost every AI risk traces back to one of three sources. They call for genuinely different responses, which is why lumping them together is so costly.

Source one · deliberate

Misuse — people using AI to do harm

The system works exactly as designed; the problem is the human pointing it. The response is mostly law enforcement, deterrence, and access controls — not changes to the model.

Examples: deepfake fraud and non-consensual imagery, AI-generated disinformation, scaled phishing and cyberattacks, surveillance overreach.
Source two · unintended

Malfunction — the system does something we didn't intend

No bad actor required; the system itself behaves badly. The response is engineering: evaluation, testing, human oversight, and reliability standards before deployment.

Examples: biased decisions in hiring or lending, hallucinated facts in high-stakes settings, unsafe behavior from autonomous systems, brittle failures on unfamiliar inputs.
Source three · emergent

Systemic — harms from widespread adoption itself

No single system or actor is at fault; the harm emerges from millions of individually reasonable uses. The response is policy and institutional design, not a bug fix.

Examples: labor disruption, concentration of power in a few firms, dependence and deskilling, erosion of a shared factual baseline.

Notice how different the responses are. You don't "regulate the model" to stop a scammer (that's misuse — a law-enforcement problem). You don't pass a content-moderation law to fix a biased lending model (that's malfunction — an evaluation-and-oversight problem). And you can't engineer your way out of labor disruption (that's systemic — a policy problem). Matching the response to the source is most of the work.

Question two: how far off is it?

The second axis is time — and it's where the doom-and-denial camps do the most damage, by borrowing each other's clocks. Doomers attach the certainty of present harms to speculative future ones; deniers attach the uncertainty of future risks to harms already happening. Keeping the horizons separate keeps everyone honest.

● Here now
Documented, measurable

Happening today, with evidence. Deepfakes, bias, fraud, reliability failures. The response is execution, not debate.

● Emerging
Visible on the trend line

Early signs, scaling fast. Increasingly autonomous agents, AI-driven labor shifts. The response is preparation and monitoring.

● Over the horizon
Uncertain, high-stakes

Plausible but unproven, longer-term. Loss of meaningful human control over very capable systems. The response is research and option-preserving.

None of these three columns should be dismissed, and none should be inflated. A here-now harm deserves action now and doesn't need a theory of the future to justify it. An over-the-horizon risk deserves serious research and humility — and treating it as a certainty is as much an error as waving it away. The honest posture holds all three at once, at their proper sizes.

Doomers borrow the certainty of today's harms for tomorrow's hypotheticals. Deniers borrow the uncertainty of tomorrow for the harms already here. The map's whole job is to stop both moves.

— SCAIO editorial observation

What the map is good for

Next time you read an AI-risk claim, place it: which source, which horizon? A claim that "AI is biased" is a malfunction risk, here now — so the question is what evaluation and oversight applies. A claim that "AI will take all the jobs" is a systemic risk on an emerging horizon — so the question is what workforce and economic policy prepares for it. A claim that "AI could become uncontrollable" is a malfunction-and-systemic risk over the horizon — so the question is what research and governance keeps options open.

Three different claims, three different responses, three different levels of confidence. Stated together as "AI risk," they're a fog. Placed on the map, they're a to-do list.

What this means for South Carolina

The map also clarifies what a state can actually do. South Carolina has real leverage over misuse (it has already criminalized AI-generated CSAM and non-consensual deepfakes) and over malfunction in the systems its own agencies buy and deploy (through procurement, evaluation, and human-review requirements). Its leverage over systemic risk is partial — workforce policy, education, economic development — and its influence over over-the-horizon frontier risk is mostly indirect, exercised through how it joins national conversations.

That's not a counsel of helplessness — it's a focusing device. The most useful thing a state can do is act decisively on the risks it can actually reach, prepare seriously for the ones it can see coming, and resist the temptation to either panic about or dismiss the ones it can't yet measure. That is the whole of SCAIO's posture, applied to risk specifically: benefits in full view, risks in full view, and the right tool aimed at the right problem.

About this piece: Part of SCAIO's AI Safety & Governance series. The source/malfunction/systemic framing and the time-horizon axis are syntheses of standard taxonomies in the AI-safety and governance literature, adapted for plain-language use; they are a working map, not the only possible one. Pairs with the founding editorial, Between Doom and Denial, and the vocabulary primer in Learn. SCAIO welcomes correction.