Last updated:
A vulnerability where an AI system is granted too much autonomy, too many tools, or over-privileged access relative to its intended function.
Excessive Agency (LLM06:2025) is the primary enabler of ASI02 (Tool Misuse). It occurs when developers give agents broad access to APIs or databases just in case, allowing a hijacked agent to perform destructive actions - like deleting production data - that were never part of its original mission.
Real world example:
An internal HR chatbot is given Write Access to the entire employee database; an attacker uses a prompt injection to make the bot delete the records of the executive team.




