External Harms
External harms happen when a hacker breaks into a computer system and uses that system's own tools to cause trouble for people or businesses outside of that specific computer, such as stealing money, ruining a company's reputation, or hurting the public.
External harms refer to the downstream negative impacts resulting from an adversary's exploitation of a compromised AI system. By leveraging the system's capabilities, the attacker extends their reach beyond the immediate environment to inflict financial, reputational, or operational damage on the organization, its user base, or the broader public.
External harms are defined as the adverse consequences resulting from an adversary's unauthorized utilization of a compromised system's resources or capabilities to project impact beyond the system boundary. This encompasses systemic risks where the exploitation of AI-driven processes facilitates tangible injury to the organization (e.g., fiscal loss, brand erosion), its users (e.g., privacy violations, physical harm), or the general public (e.g., societal destabilization, misinformation campaigns).