Risk · Model & Application Security

Excessive agency in autonomous agents

An agent is granted more permission, tool access, or autonomy than the task requires.

  • high
  • agentic-ai
  • autonomy
  • owasp-llm

How it happens

An agent is granted broader permissions, tool access, or autonomy than the task requires, so a single bad decision or manipulated instruction can cascade into a high-consequence action.

Why it matters

The blast radius of a failure scales with the agent's permissions, not with the intent behind the failure.

Mitigation

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Regulatory context

Framework and clause references

FrameworkClauseTitle
OWASP Top 10 for LLM ApplicationsLLM06Excessive Agency

Ready to talk about your AI governance programme?

Board papers, AIMS build-out, or a second opinion before an audit: start with a message.

Contact Andrew