Excessive agency
An OWASP Top 10 for LLM Applications risk category describing an AI agent granted more functionality, permission, or autonomy than its assigned task requires, broken into excessive functionality (tools beyond task scope), excessive permissions (broader privileges than necessary), and excessive autonomy (high-impact actions with no human checkpoint).
Defined in 3 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
An OWASP Top 10 for LLM Applications risk category describing an AI agent granted more functionality, permission, or autonomy than its assigned task requires, broken into excessive functionality (tools beyond task scope), excessive permissions (broader privileges than necessary), and excessive autonomy (high-impact actions with no human checkpoint).
An LLM risk in which a system can take consequential actions (send messages, issue refunds, change records) with more autonomy than is safe, so an attacker who steers the model can trigger an action a human should have approved. The reason the red-team must probe what a system can do, not only what it can say.
OWASP's term for giving an AI too many permissions or capabilities relative to its task; the root condition that makes Reach and Escalation dangerous. Answered by least privilege and human approval of consequential actions.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Agent-Specific Security Concerns and Mitigation · AI Security Fundamentals, AI Literacy & Professional Conduct
- The agent's trail: who acted, on whose authority, using what, and why, recorded for every autonomous touch of your estate · Access and the Keys, AI Data Governance: The Data Chair
- Red-teaming your own system: attacks a motivated user will find · Evaluation and Trust, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.