In plain terms
You give a house-sitter the key to the front door, not the safe combination and the car keys as well. The same goes for an agent: if the job is to read last month's invoices, it gets read access to that one folder, not write access to the whole finance drive.
Why it matters
With agents you have to assume that sooner or later the model will make a mistake or be manipulated. Least privilege decides how much that day costs. It is the cheapest and most dependable AI security control, and the one most often skipped, because broad access makes demos work faster.
Example
A meeting-scheduling agent could be given full access to the mailbox. Instead it gets permission to read calendars and create draft invitations. When a malicious invitation tells it to forward the CEO's emails, it simply lacks the ability.
Most often confused with
Least Privilege vs. Guardrails
A guardrail watches what the agent does and tries to catch the bad cases. Least privilege means the agent never had the ability in the first place. Guardrails can miss; a permission that was never granted cannot be misused.
Under the hood
Applied to agents: scope each tool narrowly (read-only variants, single resources, row-level filters), separate read tools from write tools, issue short-lived credentials per task instead of standing ones, run the agent under its own identity and never under an administrator's or the user's full account, and narrow permissions further when untrusted content enters the context. Review tool lists as you would access-control lists. The OWASP name for the opposite condition is excessive agency: more functions, permissions or autonomy than the task requires.