Versatile AI Risk Assessment

AI threat catalogueAgentic and Autonomous AIProduction

Excessive Agency

An AI system is granted more permissions or freedom to act than its task requires. Faulty or manipulated outputs then directly trigger consequential actions such as payments, data deletion, or system changes.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 7 verified sources

Description

Many AI assistants are connected to other systems through interfaces and can act there on their own, for example sending emails, changing records, or placing orders. The threat arises when the system is given more functions than it needs, operates with overly broad permissions, or may carry out consequential steps without human confirmation. Language models do not reliably separate instructions from the content they process. A prompt injection (hidden instructions embedded in processed content), an ambiguous request, or a plain model error can therefore trigger a damaging action. The system then technically acts within its granted permissions, so conventional access controls do not stop the damage.

Possible impact

Possible consequences include unwanted financial transactions, deleted or altered data, and interference with production systems, depending on what the AI system is connected to. If personal or confidential data leaks in the process, data protection violations and notification obligations follow. The EU AI Act requires effective human oversight for high-risk systems, including the ability to override outputs and to stop the system.

Example

An AI assistant is meant only to summarize incoming emails but also has permission to send email. A crafted message containing hidden instructions makes it forward confidential messages from the mailbox to an external address. The incident is noticed only after the data has already left the company.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM06:2025NIST AI RMF Section 3.5MITRE ATLAS AML.T0048EU AI Act Article 14(4)(d) · Article 9(1), 9(2)(a), 9(2)(d)BSI R28 · R3

Verified references (7)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Agentic and Autonomous AI.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Excessive Agency”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/excessive-agency/

← Back to the full catalogue