Analysis · curated 27 Jul 2026
Managing Excessive Agency Risks in Enterprise AI Systems | Intecracy Group
First reported · updated · 2 reports intecracy.com
Coverage timeline
Why it matters
Excessive Agency in autonomous AI agents given broad API and system access can lead to unauthorized data access, sensitive information disclosure, or unintended execution of critical business operations, making architectural containment a defender priority.
An explainer from Intecracy Group discusses mitigating 'Excessive Agency' risk—recently added to the OWASP Top 10 for LLM and GenAI apps 2025—in enterprise AI agents that execute business processes. It argues for constraining agent autonomy through BPMN 2.0 orchestration, DMN decision tables, and role-based access control rather than relying on prompt engineering, citing scenarios like agents approving payments beyond limits or bypassing compliance routes.