{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"ai_governance","domain":["AI Governance","Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["owasp-llm-top10-2025","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-agent-unauthorized-actions","description":"AI agents with excessive permissions or weak action controls execute tool calls, transactions, or code outside their authorized task scope — through prompt injection, misinterpretation, or emergent behaviour — causing data loss, financial loss, or irreversible changes in connected systems.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"ai-agent-unauthorized-actions","taxonomies":["owasp-llm-top10-2025","iso-23894-ai-risk"],"treatment":"mitigate"},"id":"risk:ai-agent-unauthorized-actions","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-agent-unauthorized-actions","sourceIds":["aiuc-1","eu-ai-act","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Unauthorized or unsafe autonomous agent actions and tool calls","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:629deb63d191633ca0dbe5669e4f258edc0469168b578352a61bb274419588de","properties":{"rationale":"Tool allow-lists, task-scoped permissions, approval gates for irreversible actions, and sandboxed execution are the direct inverse of excessive agency.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-agent-unauthorized-actions-194415b8.json","targetId":"risk:ai-agent-unauthorized-actions","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb036db59a6b451454b08226e01ad570abab18c7af1b1fe4d5ddf6c7ad461e80","properties":{"rationale":"Human overseers who can halt or override the system are the backstop when an agent acts outside its intended scope.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-16-b95e2895.json","sourceId":"uc:UC-AI-16","targetDetailPath":"/data/v1/records/risk-ai-agent-unauthorized-actions-194415b8.json","targetId":"risk:ai-agent-unauthorized-actions","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ee49bd21d5d9a068a75ee78a17c814da423e578682ac0adbb51894dd5349652c","properties":{"rationale":"Independent testing of tool calls surfaces unsafe or unauthorized agent actions before customers do.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/risk-ai-agent-unauthorized-actions-194415b8.json","targetId":"risk:ai-agent-unauthorized-actions","type":"mitigates"}],"schemaVersion":1}
