Skip to content

Failure mode · FM-02

Excessive agency & permissions

The agent holds broader authority than the task requires (database write access for a read task, spend authority without limits), so a single mistake or manipulation has outsized blast radius.

Answered by

Least privilege: scope permissions, cap spend and autonomy.

OWASP cross-reference

LLM06:2025 Excessive Agency · ASI03 Identity and Privilege Abuse

ASI03 is described by OWASP as the agentic evolution of Excessive Agency (LLM06:2025).

Sources: OWASP Top 10 for Agentic Applications 2026↗

In the record