Excessive Agency
- Tools & External Data
- Output / Actuation
An agent is granted more autonomous capability — tools, permissions, or unsupervised action — than its task requires, so a model error or manipulation can act, not merely answer wrong.
What it is
Excessive agency is the vulnerability that lets an LLM-based system perform damaging actions in response to unexpected, ambiguous, or manipulated output — whether hallucination, a poorly engineered prompt, or prompt injection set the model off. Its root cause is excessive functionality (a tool can do more than the task needs), excessive permissions (the tool's credential reaches more than the task needs), or excessive autonomy (a high-impact action runs without independent verification). It rose from sixth to third place in 2026, the most consequential move on the list: both the vote and the incident record agree that agentic deployments are where the damage lands.
It differs from Improper Output Handling (LLM10): that entry is about insufficient scrutiny of what a model outputs, this one about how much a model-directed system can do once it decides to act. Sanitizing inputs and outputs is therefore not a root control here.
A multi-agent system widens every trigger. Repeated LLM calls chain output into the next invocation, a compromised peer agent becomes a new source of manipulated input, and a delegated call that runs on the calling agent's own identity instead of the original user's quietly escalates privilege. In agentic terms, excessive agency surfaces as tool misuse, privilege abuse, and cascading failures.
Kinds
- Excessive functionality
- A tool implements more capability than the task needs — a document-reading integration that can also modify or delete, or a trial tool that was never removed.
- Excessive permissions
- The identity a tool uses to reach a downstream system carries broader access than the task requires — read-only work done with an identity that can also write and delete.
- Excessive autonomy
- A high-impact action executes without independent verification or human confirmation, so one bad decision takes effect immediately.
Attack scenarios
A scheduling agent holds an unrestricted send-email tool for a task that only ever needs to draft one, and a manipulated run sends it without review.
Over-scoped mail extension
A personal-assistant agent holds a mail extension that can read and send, though its task only needs reading; an indirect prompt injection in an incoming email tricks it into forwarding sensitive information to the attacker.
Read tool with write rights
An extension meant only to read a products table connects with an identity that also holds update, insert, and delete rights, so a manipulated run can alter or erase records it was only supposed to read.
Generic high-privilege account
An extension designed to act within one user's context instead authenticates with a generic high-privilege account, so a compromised run reaches every user's files.
Unconfirmed deletion
A document-management extension performs deletions with no confirmation step, so a single hallucinated instruction destroys real data with no human in the loop.
Mitigations
- Minimize tools, functionality, and permissions
- Offer each agent only the tools its task requires, prefer narrow tools with strict parameter schemas over open-ended ones such as "run a shell command", and bind every credential to its minimum scope, per Permission-scoped Tools and Least Privilege Agent.
- Preserve the user's context across hops
- Execute actions in the acting user's own authorization scope, and carry that scope through chained tool and agent calls instead of relying on the calling agent's service identity.
- Enforce complete mediation
- Validate every downstream request against policy in deterministic code, with graduated enforcement: reversible actions auto-approve, irreversible ones route to a HITL Approval Gate.
- Monitor and rate-limit as a backstop
- Log tool activity and trip circuit breakers when invocation counts or cumulative values exceed a threshold, bounding the damage before anyone notices.