---
term: "Excessive agency"
category: "AI risks and safety"
url: https://agenticopenfinance.com/glossary/excessive-agency
source: AgenticOpenFinance glossary
---

# Excessive agency

> Giving an LLM application more functions, permissions or autonomy than needed, so bad outputs cause harmful actions.

Excessive agency is a vulnerability described by the OWASP GenAI Security Project in which an LLM-based application can perform damaging actions in response to unexpected, ambiguous or manipulated model outputs. Its root causes are excessive functionality, excessive permissions and excessive autonomy, such as a tool that can do more than the task needs or an action that runs without approval. It is not a legal term, but it maps directly onto agent mandates: the narrower the mandate, the smaller the harm a bad output can cause.

Related terms: [Prompt injection](https://agenticopenfinance.com/glossary/prompt-injection.md), [Tool use](https://agenticopenfinance.com/glossary/tool-use.md), [Mandate](https://agenticopenfinance.com/glossary/mandate.md), [Spend limit](https://agenticopenfinance.com/glossary/spend-limit.md), [Level of autonomy](https://agenticopenfinance.com/glossary/agent-autonomy.md)
