OWASP Top 10 for LLM Applications 2025

Excessive Agency

Granting LLMs too much autonomy to perform damaging actions.

What is Excessive Agency?

Excessive Agency refers to granting an LLM the ability to take actions in the real world (like sending emails, making purchases, or modifying code) without sufficient oversight or control.

The risk is that the LLM might hallucinate, misunderstand a request, or be manipulated into performing actions that cause irreversible damage.