For Heads-of · Practitioner
Excessive agency in autonomous agents
An agent is granted more permission, tool access, or autonomy than the task requires.
- high
- agentic-ai
- autonomy
- owasp-llm
How it happens
An agent is granted broader permissions, tool access, or autonomy than the task requires, so a single bad decision or manipulated instruction can cascade into a high-consequence action.
Why it matters
The blast radius of a failure scales with the agent's permissions, not with the intent behind the failure.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| OWASP Top 10 for LLM Applications | LLM03 | Excessive Agency |