AI threat catalogueAgentic and Autonomous AIProduction
Excessive Agency
An AI system is granted more permissions or freedom to act than its task requires. Faulty or manipulated outputs then directly trigger consequential actions such as payments, data deletion, or system changes.
Description
Many AI assistants are connected to other systems through interfaces and can act there on their own, for example sending emails, changing records, or placing orders. The threat arises when the system is given more functions than it needs, operates with overly broad permissions, or may carry out consequential steps without human confirmation. Language models do not reliably separate instructions from the content they process. A prompt injection (hidden instructions embedded in processed content), an ambiguous request, or a plain model error can therefore trigger a damaging action. The system then technically acts within its granted permissions, so conventional access controls do not stop the damage.
Possible impact
Possible consequences include unwanted financial transactions, deleted or altered data, and interference with production systems, depending on what the AI system is connected to. If personal or confidential data leaks in the process, data protection violations and notification obligations follow. The EU AI Act requires effective human oversight for high-risk systems, including the ability to override outputs and to stop the system.
Example
An AI assistant is meant only to summarize incoming emails but also has permission to send email. A crafted message containing hidden instructions makes it forward confidential messages from the mailbox to an external address. The incident is noticed only after the data has already left the company.
Recommended mitigations (5)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
Least privilege for agent actionsTechnical
- Effect
- Preventive, Impact-limiting
- Implementation level
- Application, API & agents
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Least privilege for agent actions” is primarily technical: Machine-enforced identity, permission, or scope rules constrain unauthorized access and actions; complemented by binding workflows.
Human-in-the-loop approval for critical actionsOrganizational & process-based
- Effect
- Preventive
- Implementation level
- Application, API & agents, Use & operations
- Complementary control type
- People & competence
- Reason for the classification
- “Human-in-the-loop approval for critical actions” is primarily organizational and process-based: A binding workflow requires an accountable human decision before use or execution; complemented by human expertise and judgment.
Action audit loggingTechnical
- Effect
- Detective
- Implementation level
- Application, API & agents, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Action audit logging” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Rate limits on agent operationsTechnical
- Effect
- Preventive, Impact-limiting
- Implementation level
- Application, API & agents
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Rate limits on agent operations” is primarily technical: Automated resource controls, budget limits, or runtime boundaries constrain overload, abuse, cost, and cascading failures; complemented by binding workflows.
Reversibility and rollback capabilitiesTechnical
- Effect
- Impact-limiting, Restorative
- Implementation level
- Application, API & agents, Use & operations
- Reason for the classification
- “Reversibility and rollback capabilities” is primarily technical: Versioned states or rollback mechanisms enable controlled recovery.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (7)
Every reference states the framework, the exact location and the publishing organisation.
- OWASP LLM Top 10 LLM06:2025 Excessive AgencyLLM06:2025 Excessive Agency, official category page OWASP FoundationOriginal
- NIST AI RMF Section 3.5 Security of AgentsSection 3.5, p. 54 National Institute of Standards and Technology (NIST)Original
- MITRE ATLAS AML.T0048 External HarmsATLAS.yaml technique object with id AML.T0048 (pinned release v5.6.0) MITREOriginal
- EU AI Act Article 14(4)(d) Human oversightArticle 14(4)(d); for automation bias, Article 14(4)(b) European Union (EUR-Lex)Original
- EU AI Act Article 9(1), 9(2)(a), 9(2)(d) Risk management systemArticle 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) European Union (EUR-Lex)Original
- BSI R28 Indirect Prompt Injections (Text)Kap. 4, R28, p. 33 Bundesamt für Sicherheit in der Informationstechnik (BSI)Original
- BSI R3 Fehlerhafte Reaktion auf Eingaben (Text, Bild, Video)Kap. 4, R3, p. 14 Bundesamt für Sicherheit in der Informationstechnik (BSI)Original
Terms on this page
Glossary terms that occur in this entry. Every link leads to the full explanation.
- Prompt Injection Manipulated input or planted content redirects a language model.
Related threats
More entries from the topic group Agentic and Autonomous AI.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“Excessive Agency”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/excessive-agency/