Analysis
Excessive Agency: Your AI Agent Has Too Much Power | Certified Agentic AI Security Expert
Publication date unknown · Discovered youtube.com
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Excessive agency means a single prompt injection can only do what an agent is permitted to do, so limiting agent permissions directly reduces the damage an attacker can cause.
A YouTube short from Practical DevSecOps explains "excessive agency" (OWASP LLM06) — AI agents granted more tools, permissions, or autonomy than a task requires — and recommends shrinking the blast radius via minimum tools per task, scoped short-lived credentials, and human sign-off on irreversible actions. The content primarily promotes the Certified Agentic AI Security Expert (CAASE) course.