Glossary / AI security

Excessive Agency

The failure is not that the model turns hostile; it follows instructions literally while holding more power than the task requires. A hallucination or a prompt injection then turns that power into a wrong action.

You do not fix Excessive Agency with a smarter model or a better prompt. You fix it structurally: minimize the tools an agent can call, scope its permissions to the task, and require human approval for high-impact actions.

A concrete example: an agent granted broad CRM write and send access "just in case" reads a misleading instruction and overwrites or deletes records, or emails the wrong customer. The scope, not the intent, is the vulnerability. Least privilege plus a human approval gate on irreversible actions removes the blast radius while leaving the agent useful for everything reversible.

What are the three root causes of excessive agency?

OWASP names excessive functionality, excessive permissions, and excessive autonomy. Functionality is the agent having tools it does not need for its job. Permissions is those tools being scoped wider than the task, such as delete rights on an agent that only proposes changes. Autonomy is the agent being able to execute high-impact actions without a human decision. Each is fixed separately, and fixing one does not cover the others.

Why does a smarter model not fix excessive agency?

Because model quality is not on the list of causes. The problem is not that the agent reasons badly, it is that it can act, and a more capable actor with unchecked write access is a larger blast radius rather than a smaller one. Excessive agency is a permissions and design problem, and it is solved with scoping and approval rather than with a model upgrade.

How do you reduce excessive agency without making the agent useless?

Remove tools the agent does not use, narrow every remaining tool to the minimum scope it needs, and require human approval only on the high-impact actions rather than on all of them. The agent keeps its speed on the reversible majority of its work and loses it only where a mistake would be expensive, which is the trade you want.

From definition to a working system

Mindlyft is the approval and audit layer over your AI GTM agents, every action drafted, human-approved, reversible, and logged. Start with a free 30-minute GTM Engineering Review.

Get your free review

Free GTM Engineering Review

Thirty minutes on your GTM engine.Free. No pitch deck.

A working session, not a sales call. We map where your company's knowledge lives, where promises leak, and the first systems we would build, and we tell you straight if it is not worth doing yet.

Or pick a time