Microsoft calls for explicit limits on AI-agent permissions and actions in its Digital Defense Report 2026, introduced on October 1. The official report page identifies excessive agency as a distinct risk class.

Microsoft describes tool allowlists, runtime controls and action policies as countermeasures. Agent identities should be verifiable and receive only the access they need.

The assessment also covers manipulated instructions, data exposure and altered logs. It mainly concerns attackers influencing AI systems or using them as tools. It is not recast as a new unauthorized attack initiated by AI.

This risk signal records a vendor assessment of agent control. The safeguards are not independently validated by their inclusion in the report; Microsoft itself sells security products. The risk classification does not establish incident frequency.