GLOSSARY logo

GLOSSARY

THE TECHNICAL LANGUAGE OF DIGITAL B2B INFRASTRUCTURE

CONCEPT
CYBERSECURITY

Excessive Agency

An AI-system vulnerability in which excessive functionality, permissions or autonomy enable damaging actions from erroneous or manipulated outputs.


BUSINESS RELEVANCE

It reduces the likelihood or impact of unauthorised access, data loss and service disruption and provides evidence for assurance.


IMPLEMENTATION EXAMPLE

A cross-functional team applies Excessive Agency in a production initiative, defines ownership and success criteria, tests representative scenarios, monitors outcomes and records corrective actions before scaling.


LIMITATIONS

No single control eliminates risk. Misconfiguration, compromised identities, weak recovery and changing threats require defence in depth and continuous review.


TECHNICAL EXPLANATION

An AI-system vulnerability in which excessive functionality, permissions or autonomy enable damaging actions from erroneous or manipulated outputs. The control should be based on identified threats, least privilege, strong identity, logging, monitoring and tested response procedures. Effectiveness depends on implementation and operating context rather than the presence of a product label.


Secondary Topics

AI Governance, Intelligent Automation

Sources

NIST Cybersecurity Framework 2.0 — https://www.nist.gov/cyberframework; OWASP — https://owasp.org/