Excessive Agency
The condition where an AI system is granted unnecessary autonomy, permissions, or capabilities that increase operational and security risks.
What is Excessive Agency?
Excessive agency can arise when an AI agent is given broad access to tools, APIs, data, systems, or actions without sufficient restrictions. If the model makes an incorrect decision, follows a malicious instruction, or is manipulated through prompt injection, these permissions may allow it to perform unintended actions with real-world consequences.
Why is Excessive Agency Important?
As AI agents become capable of independently executing tasks, excessive permissions can significantly increase the impact of errors and attacks. Limiting agents to the minimum capabilities required for their tasks helps reduce risk. Controls such as least-privilege access, human approval, scoped permissions, and action monitoring can provide additional safeguards.
Common use cases
Excessive agency is particularly relevant to AI agents, autonomous workflows, tool-enabled LLMs, MCP-based systems, enterprise assistants, and AI applications connected to external services.