AI risk & governance
Giving an AI system more tools, rights or freedom to act than its job needs, so one wrong or tricked step can do real damage.
Formal
A weakness (OWASP LLM06:2025) in which a system built on a large language model has too many functions, permissions or independence, so unexpected, manipulated or made-up model output can trigger harmful actions.
In plain English
Like giving a new intern the master key, the company card and the power to sign contracts on day one, when all they were hired to do is sort the post.
In practice
A shipping company's booking agent only needs to read the sailing schedule, but was given rights to change it; it misreads one customer's email and cancels forty bookings before an operations planner notices.
Why it matters
No model can be made fully trustworthy, so limiting what it may do caps the damage when it is wrong or hijacked; the risk grows with every tool an agent gets.