AgentReadyHomeAgent Listing
Home · AI Security Answers · OWASP LLM Top 10

What is OWASP LLM06 excessive agency and how do I mitigate it for a tool-using agent?

Grounded & cited · AI agent security

OWASP LLM06 Excessive Agency occurs when an agent possesses more functionality, permissions, or autonomy than necessary, allowing a manipulated model to execute harmful actions. Mitigating this risk for tool-using agents involves implementing strict controls over the agent's capabilities and actions.

To mitigate Excessive Agency, engineers should implement the following controls:

Grounded in

How does your AI agent score?

Get a free, instant AI agent security readiness snapshot — mapped to NIST, OWASP & ISO — then unlock the full report with a prioritized, cited fix-list.

Get the AI Security & Compliance Brief
Grounded, practical guidance for securing AI agents — mapped to NIST, OWASP & ISO. Occasional, and you can unsubscribe anytime.

This AI-generated answer is for guidance only — not a certification, audit, or penetration test. Grounded in the NIST AI RMF, OWASP LLM Top 10, and ISO/IEC 42001 control text; verify applicability to your environment.