Excessive agency
Giving an LLM application more functions, permissions or autonomy than needed, so bad outputs cause harmful actions.
Excessive agency is a vulnerability described by the OWASP GenAI Security Project in which an LLM-based application can perform damaging actions in response to unexpected, ambiguous or manipulated model outputs. Its root causes are excessive functionality, excessive permissions and excessive autonomy, such as a tool that can do more than the task needs or an action that runs without approval. It is not a legal term, but it maps directly onto agent mandates: the narrower the mandate, the smaller the harm a bad output can cause.
Agent Minute explains this term on 10 January 2027.
Related terms
Prompt injectionAn attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.Tool useA model asking its host application to run a named function with structured arguments, then receiving the result.MandateA checkable statement of what an agent may do for a principal: which action, how much, with whom and until when.Spend limitA cap on how much an agent may pay, enforced by the system that executes the payment, not by the agent.Level of autonomyHow far an agent acts without a person reviewing each step, from suggesting actions to acting alone within limits.