risk

Unauthorized or unsafe autonomous agent actions and tool calls

AI agents with excessive permissions or weak action controls execute tool calls, transactions, or code outside their authorized task scope — through prompt injection, misinterpretation, or emergent behaviour — causing data loss, financial loss, or irreversible changes in connected systems.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

category
ai_governance
domain
  • AI Governance
  • Access Control & Identity Management
taxonomy
  • owasp-llm-top10-2025
  • iso-23894-ai-risk
inherent_rating
high

Details

risk_id
ai-agent-unauthorized-actions
category
ai_governance
likelihood
high
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • owasp-llm-top10-2025
  • iso-23894-ai-risk

Source

No record-specific source URL is provided.

Connections