For Heads-of · Practitioner

Excessive agency in autonomous agents

An agent is granted more permission, tool access, or autonomy than the task requires.

  • high
  • agentic-ai
  • autonomy
  • owasp-llm

How it happens

An agent is granted broader permissions, tool access, or autonomy than the task requires, so a single bad decision or manipulated instruction can cascade into a high-consequence action.

Why it matters

The blast radius of a failure scales with the agent's permissions, not with the intent behind the failure.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
OWASP Top 10 for LLM ApplicationsLLM03Excessive Agency