Versatile AI Risk Assessment

AI threat catalogueAgentic and Autonomous AIProduction

Agentic AI / Autonomous Agents

AI agents plan multi-step tasks on their own and carry them out with tools such as email, databases, or code execution. The less human involvement there is, the further planning errors, manipulated content, and knock-on failures spread.

As of: July 2026 · Catalogue version 2026.07.17.3 · 7 mitigations · 13 verified sources

Description

An AI agent breaks a task into individual steps, autonomously calls tools and interfaces, and feeds the results into the next step. Several risks compound along this chain: planning and judgment errors propagate from step to step, and attackers can redirect the agent through content it reads while working, for example via prompt injection (hidden instructions in emails, documents, or web pages). A redirected or misguided agent then uses its legitimate tools for harmful actions, executes code, or sends data outside the organization. In systems of multiple agents, a single fault can cascade across further agents and workflows.

Possible impact

Everything the agent can reach is exposed: unwanted transactions, data leakage, deleted files, and outages of entire workflows. Cascading effects can spread the damage beyond a single system. For high-risk systems, the EU AI Act requires that humans can effectively oversee, intervene in, and halt the system; for large general-purpose AI models, the regulation names the degree of autonomy and access to tools among the factors influencing systemic risks.

Example

A development agent with command-line access works through tasks from project files. A crafted file contains hidden instructions that the agent treats as an assignment: it runs a delete command and destroys data on the system. Throughout, it stays entirely within its regular tool permissions.

Recommended mitigations (7)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 ASI01:2026 · ASI02:2026 · ASI08:2026 · LLM01:2025 · LLM06:2025NIST AI RMF Section 3.5MITRE ATLAS AML.T0051EU AI Act Article 14(4)(d) · Article 26(5) · Article 55(1)(a) · Article 9(1), 9(2)(a), 9(2)(d)BSI R28BIML BIML78 system:5

Verified references (13)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Agentic and Autonomous AI.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Agentic AI / Autonomous Agents”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/autonomous-agents/

← Back to the full catalogue