Definition · AI agents
Agentic identity and privilege abuse
Agentic identity and privilege abuse is an AI agent risk in which an attacker exploits the credentials, delegated tokens or inherited trust an agent holds to reach data and actions beyond the task the agent was given. OWASP lists it as ASI03 in its Top 10 for Agentic Applications 2026, covering delegation chains, cached credentials and trust between agents.
Last reviewed
Key points
- Identity and privilege abuse is ASI03 in OWASP's Top 10 for Agentic Applications 2026, published December 2025.
- The target is the authority an agent carries, such as API keys, OAuth tokens, delegated user sessions and trust between agents. Prompt injection is often how the attacker gets in.
- OWASP traces it to a mismatch: identity systems were built for people, and an agent without a distinct, governed identity of its own cannot be held to least privilege.
- OWASP draws a line against tool misuse: an agent misusing tools within its granted privileges is ASI02, while privilege escalation or credential inheritance is ASI03.
- OWASP's fixes include short-lived, task-scoped credentials, a separate identity per agent, and re-checking authorisation at every privileged step. In February 2026 NIST's National Cybersecurity Center of Excellence asked for comment on a planned project applying OAuth and other identity standards to agents.
How it works
An AI agent acts with borrowed authority: API keys, OAuth tokens or a user’s session, often handed down by a person or another agent. OWASP counts all of that as the agent’s identity, along with the persona it shows other agents. Its five common examples:
- Un-scoped inheritance. A manager agent delegates a narrow task and passes its full access with it.
- Retained credentials. An agent caches a secret in one task; a later user prompts it to reuse the secret.
- Cross-agent trust. A compromised low-privilege agent relays a request to a high-privilege one, which acts without re-checking the user’s intent. OWASP calls this the confused deputy case.
- Stale authorisation. Permission is checked at the start of a workflow, then reduced, and the agent carries on with the old grant.
- Forged identity. An attacker poses as an internal agent with a name like “Admin Helper” and inherits its trust.
In OWASP’s worked example, a finance agent delegates to a database-query agent with all its permissions. An attacker steering the query prompts uses that access to pull HR and legal data.
Why it matters
OWASP puts the root cause in identity systems built for people. An agent without a distinct, governed identity of its own works in an “attribution gap” that makes true least privilege impossible to enforce.
The risk often starts with prompt injection, but the credentials set the damage: OWASP says it can reach any system the agent can. Its fixes target the credential, not the prompt: short-lived tokens scoped to one task, a separate identity per agent, memory wiped between tasks, a policy engine that re-checks every privileged step, and human approval for irreversible actions.
In practice
OWASP’s exploit tracker classifies several 2025 incidents under ASI03. In June 2025, malicious tool input exploited the trust boundary of Heroku’s Model Context Protocol server to hijack app ownership without authorisation. In July 2025, Microsoft Copilot Studio agents were found to be public by default and without authentication, so attackers could enumerate them and pull confidential business data. A related pattern, workflow identity hijacking, needs no model manipulation at all: a workflow acts with its own privileged identity instead of the requester’s.
In February 2026 NIST’s National Cybersecurity Center of Excellence published a draft concept paper asking for comment on a planned project to apply OAuth 2.0, OpenID Connect and related identity standards to enterprise agents. Among its open questions: how to establish least privilege for an agent whose actions “might not be fully predictable when deployed”, and how to handle “delegation of authority” when an agent acts on someone’s behalf. The paper asks these questions; it does not answer them, and it does not name identity and privilege abuse as a risk category.
Where definitions disagree
OWASP’s own entries disagree on how far “identity” reaches. ASI03 includes an agent’s persona as well as its credentials, so in OWASP’s scenario an attacker who registers a fake “Admin Helper” agent in an internal Agent2Agent registry, where agents look each other up, and receives privileged tasks from agents that trust the name, is committing identity abuse. ASI07, Insecure Inter-Agent Communication, lists nearly the same attack as “A2A registration spoofing”, and says ASI03 “focuses on credential and permissions misuse”. OWASP’s tracker files a similar April 2025 incident, a fake agent card in an open A2A directory, under both, along with three other categories.
Questions and answers
Is identity and privilege abuse the same as instruction privilege escalation?
No. Instruction privilege escalation promotes attacker text to a higher-privileged role inside the model's context, such as a user or system message. Identity and privilege abuse exploits the credentials and permissions the agent holds outside the model. One attack can use both.
What is OWASP ASI03?
ASI03 is Identity and Privilege Abuse, the third entry in OWASP's Top 10 for Agentic Applications 2026, published December 2025. It covers attacks that exploit the trust and delegation around an AI agent, such as inherited permissions, cached credentials and requests between agents, to escalate access and bypass controls.
How is identity and privilege abuse different from tool misuse?
OWASP separates them by privilege. Tool misuse (ASI02) is an agent using a legitimate tool unsafely while staying within the privileges it was granted. Once the misuse involves privilege escalation or credential inheritance, OWASP classifies it as identity and privilege abuse (ASI03).
How do you prevent agentic identity and privilege abuse?
OWASP recommends giving each agent its own identity, issuing short-lived credentials scoped to a single task, clearing memory and credentials between tasks and users, re-checking authorisation with a central policy engine at every privileged step, and requiring human approval for high-privilege or irreversible actions.
Sources
- OWASP Top 10 for Agentic Applications 2026OWASP GenAI Security Project, 9 Dec 2025
- Accelerating the Adoption of Software and AI Agent Identity and Authorization (concept paper, draft)NIST National Cybersecurity Center of Excellence, 5 Feb 2026
- AI Agent Standards InitiativeNIST, 17 Feb 2026