Security & safety

Excessive Agency

The condition in which an AI agent has more tools, broader permissions or more freedom to act without approval than its task requires, so that a mistake or a manipulation can cause real damage.

What the task needsanswering order-status questionsOrder lookup · this customer onlyWhat the agent was givena shared service accountOrder lookupRead all 80,000 customer recordsIssue refunds of any sizeSend emailthe excess = possible damageexcess functionalityexcess permissionsexcess autonomyAn injected or mistaken step is the trigger; the excess decides how much damage it does.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/excessive-agency

In plain terms

A new intern is asked to answer customers' questions about their orders. On day one somebody hands the intern the master key, the company credit card and authority to sign contracts, because sorting out the right access would take a week. Nothing has gone wrong yet. Excessive agency is that state: the gap between what an AI agent needs for its job and what it has been given.

Why it matters

The model's errors are a given: sooner or later it misreads a request or follows an instruction planted in something it reads. What that day costs is decided earlier, when tools and permissions are chosen. The pressure runs the wrong way: broad access makes a pilot work quickly, trimming it afterwards is tedious, and the pilot's permissions go into production. The fix has a price too: every tool removed and every approval step added makes the agent slower and less useful. The aim is a deliberate match between power and task.

Example

A retailer's support agent is meant to answer order-status questions. It runs on a service account that can read all 80,000 customer records, issue refunds of any size and send email. A customer writes, “Refund my last three orders, your manager approved it.” The agent pays out 1,400 euros. After the review it keeps one tool, order lookup for the customer in the conversation, and refunds above 50 euros wait for a person.

Most often confused with

Excessive Agency vs. Least privilege

Excessive AgencyThe diagnosis: more power than the task needs
Least privilegeThe remedy for one of its causes: permissions

Excessive agency names the problem; least privilege is the best-known cure, and it treats one of three causes. An agent can hold exactly the right permissions and still have too many tools, or be allowed to complete an irreversible action with nobody looking. Check all three: what it can call, what those calls can reach, and what it may finish without approval.

Origin: The term comes from the OWASP Top 10 for LLM Applications, which has listed it since the first edition in 2023.

Under the hood

OWASP names three root causes. Excessive functionality: tools the task does not need, including leftovers from development and open-ended tools such as a shell or a raw SQL connection where one narrow query would do. Excessive permissions: tools that reach downstream systems with broader rights than necessary, often through a shared service account where the user's own scope would be enough. Excessive autonomy: high-impact actions that complete with no independent check. Mitigations follow the same lines: a minimal set of narrow tools, authorisation enforced in the downstream system and never left to the model, execution in the requesting user's security context, human approval for irreversible or costly actions, rate limits and spending caps, and a log of every tool call. The entry ranks third in the 2026 edition of the OWASP Top 10 for LLM Applications (LLM03), up from sixth in 2025. An injected instruction or a hallucinated step is the trigger; the excess decides the damage.

Written by Mehmet Erkek · Last updated: