Excessive Agency
An AI system can take actions that exceed its reliability, authorization, or oversight model.
agents authorization human approval
Risk Catalogue / exposure layer
Observed exposure paths where generative AI connects language to data, identity, tools, permissions, or decisions before governance has enough grip.
An AI system can take actions that exceed its reliability, authorization, or oversight model.
AI systems call tools or APIs without sufficient validation, authorization, rate limits, or operational safeguards.
Untrusted instructions enter an AI workflow and compete with the system's intended authority.
Unapproved or unknown AI use removes visibility from data handling, identity, procurement, and incident response.
Sensitive business, personal, regulated, or secret data moves through prompts, outputs, logs, retrieval, or connected tools.