What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

Least-Agency

Least-Agency is the security principle, set out by OWASP in its Top 10 for Agentic Applications, that organisations should avoid giving AI agents autonomy a task does not need. OWASP's reasoning is that agentic behaviour deployed where it is not needed expands the attack surface without adding value. Least-Agency expands on least privilege and excessive agency.

Last reviewed

Key points

  • OWASP sets out Least-Agency in its Top 10 for Agentic Applications, dated December 2025 and labelled the 2026 edition.
  • The advice is to avoid unnecessary autonomy: agentic behaviour where it is not needed "expands the attack surface without adding value".
  • It expands on least privilege, which limits what access a program holds, and on excessive agency, which names too much autonomy as one of its usual root causes.
  • OWASP pairs it with observability. Without seeing what agents do and why, unnecessary autonomy can turn minor issues into system-wide failures.
  • OWASP's statement of it gives no test for how much autonomy a task needs. Nearby OWASP guidance sets autonomy by risk and by whether an action can be undone.

How it works

OWASP states the principle in one paragraph of its OWASP Agentic Top 10: “We expand on the concepts of Least-Privilege and Excessive Agency by citing Least-Agency. This captures our advice to organizations to avoid unnecessary autonomy; deploying agentic behavior where it is not needed expands the attack surface without adding value.”

Least-Agency builds on two older ideas. Least privilege limits the access a program holds. Excessive agency is an entry in OWASP’s LLM Top 10: LLM06 in the 2025 edition the agentic list cites, LLM03 in 2026. Its root cause is typically too much functionality, too many permissions, too much autonomy, or a mix. There, excessive autonomy means an app that acts on high-impact decisions without verification or approval, such as deleting a user’s documents without asking. Least-Agency asks the question earlier: does the task need an agent acting on its own at all?

Why it matters

Autonomy a task does not need widens what an attacker can use and adds nothing in return. In OWASP’s words, it “expands the attack surface without adding value”. The letter opens the point with the wider observation that “Agents amplify existing vulnerabilities.”

OWASP ties Least-Agency to observability. Without clear visibility into what agents are doing, why, and which tools they call, “unnecessary autonomy can quietly expand the attack surface and turn minor issues into system-wide failures.”

In practice

Three examples from OWASP’s guidance fit the principle. Only the first uses its name:

  • Tools. The first mitigation for tool misuse (ASI02) is “Least Agency and Least Privilege for Tools”: per-tool profiles of scopes, rate limits and egress allowlists, such as read-only database queries and “no send/delete rights for email summarizers”.
  • Oversight. ASI09, human agent trust exploitation, recommends continuously adjusting “the level of agent autonomy and required human oversight based on contextual risk scoring.”
  • Approval. The excessive agency entry requires human in the loop approval before high-impact actions. Low-consequence or easily reversible actions can auto-approve.

Trade-offs

OWASP’s statement of Least-Agency is advice, not a test. It does not say how to judge how much autonomy a task needs. The nearest answers sit in other entries: ASI09 sets autonomy by contextual risk scoring, and the excessive agency entry separates reversible actions from irreversible ones. Where the name does appear in a mitigation, in ASI02, it is paired with least privilege in a single item.

Questions and answers

What is the difference between Least-Agency and least privilege?

Least privilege limits the access a program or user holds. OWASP's Least-Agency, from its Top 10 for Agentic Applications, expands on it by advising against autonomy an AI agent's task does not need, including deploying agentic behaviour where no agent is needed. In OWASP's own tool guidance the two are applied together.

Where does the term Least-Agency come from?

The OWASP GenAI Security Project sets it out in the leaders' letter of its Top 10 for Agentic Applications 2026, dated December 2025, as an expansion of least privilege and excessive agency. The letter says it is "citing" Least-Agency and does not say who first used the term.

Sources

  1. OWASP Top 10 for Agentic Applications 2026, Letter from the Agentic Top 10 LeadersOWASP GenAI Security Project, Dec 2025
  2. LLM03:2026 Excessive AgencyOWASP GenAI Security Project