← AI security in plain English

LLM06

OWASP Top 10 for LLMs / Excessive Agency

An LLM is handed too much power, too many tools, or too broad a set of permissions, so a bad decision or a hijacked prompt can trigger real-world actions well beyond what was needed.

Think of it likeGiving the house-sitter the keys to your car, your safe, and your bank account when all they needed was to feed the cat.

In plain English

When an AI is allowed to take actions and touch systems far beyond its job, a single mistake or manipulation can cause outsized real-world damage.