What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In Ex Machina, Caleb is selected to test the capabilities—and ultimately the consciousness—of Nathan’s latest AI experiment. In real deployments, the urgent question is less whether an AI has human-like curiosity than what it can do when it reads untrusted content and has tools to act on other systems. Excessive agency—unnecessary functions, broad permissions, or too much autonomy—can turn a manipulated response into a security incident.
What does “too curious” mean for a deployed AI agent?
The film’s premise is a fictional thought experiment, not evidence that current AI systems are conscious or have desires. For security, “curiosity” is better understood as a system having more capability or freedom than its task requires. OWASP calls the relevant vulnerability Excessive Agency: damaging actions can result from unexpected, ambiguous, or manipulated model outputs.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Ex Machina [Blu-ray + Digital HD] | $15.99 | Buy on Amazon |
| 2 |
|
Ex Machina 4K Ultra HD [Blu-ray + Digital HD] | $16.09 | Buy on Amazon |
| 3 |
|
Appleseed Ex Machina [Blu-ray] by Warner Home Video | $54.00 | Buy on Amazon |
| 4 |
|
Ex_machina [Blu-ray] | $7.01 | Buy on Amazon |
OWASP identifies three common sources of excessive agency:
- Excessive functionality: a document-reading agent can also edit or delete files, although the task needs only reading.
- Excessive permissions: the agent’s connected identity can reach data or systems beyond the task, potentially including other users’ information.
- Excessive autonomy: the agent can take consequential actions without independent verification or approval.
The practical risk depends on the whole chain: the content the model reads, the tools it can call, the identity and permissions behind those tools, and the controls that decide whether an action actually runs.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- A billionaire programmer handpicks a young employee to spend a week at his remote estate and participate in a test involving his latest invention: an artificially intelligent female robot.
How can hidden instructions lead an AI agent to leak data?
Prompt injection is an input and control problem. An attacker can place instructions inside content an agent may ingest—such as a document or other data source. If the model treats those instructions as actionable and has tools connected to external systems, it may attempt an unintended operation. NIST describes this form of agent hijacking as indirect prompt injection.
For example, a document-reading agent might encounter malicious text directing it to send files to an unknown recipient. Whether that becomes a data exposure depends on what the agent can access and whether the execution layer allows the requested action. If the connected identity can read only the intended document, the potential reach differs from an identity able to access many users’ files. Likewise, a read-only tool presents a different risk from one that can send, modify, or delete data.
Rank #2
- A billionaire programmer handpicks a young employee to spend a week at his remote estate and participate in a test involving his latest invention: an artificially intelligent female robot.
NIST’s Center for AI Standards and Innovation reported a 57% average success rate across five injection tasks in its 2025 evaluation. That figure describes those evaluated tasks and conditions; it is not a rate of real-world agent compromise. NIST also notes that task success and impact vary: a lower success rate on a high-consequence task does not make the possible outcome unimportant.
Which safeguards reduce excessive agency?
Constrain capability at the point where tools execute, rather than relying on a model to recognize every malicious or misleading instruction. OWASP’s guidance emphasizes that classifying an action does not itself authorize it: the execution component must check the actor’s authorization and any approval required for that specific action.
- Match tools to the task. Give a reader only the functions it needs. Do not attach modification, deletion, or sending functions to a task that only requires reading.
- Limit data and system access. Use an identity with the narrowest practical permissions and scope its access to the relevant data. Avoid giving a routine task access to unrelated users’ information.
- Gate consequential actions at execution time. Before a tool call runs, check whether the acting identity is authorized for that exact action and whether the action requires explicit approval. Do not treat a model’s decision that an action is safe as permission to execute it.
- Require review where impact warrants it. Sending data externally, deleting records, or making other consequential changes should have independent verification or human approval when required by the risk and policy.
These measures reduce opportunities for an injected instruction to cause harm; they do not prove that every prompt injection will be blocked. OWASP also identifies tool abuse, privilege escalation, data exfiltration, and memory poisoning among agent security risks, so controls should account for the agent’s actual tools and operating context.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to compare agent designs
There is no single “safe agent” label that settles the question. Compare a design by examining four concrete boundaries:
Rank #4
- The disk has English audio and subtitles.
| Axis | What to check | Safer design direction |
|---|---|---|
| Available functions | Can the agent only read, or can it also send, modify, or delete? | Expose only the functions required for the task. |
| Reach of tools | Which data, accounts, and systems can the connected identity access? | Scope access narrowly to the needed data and systems. |
| Autonomy | Can the agent execute actions independently, or does it pause for checks? | Use independent verification and approval for consequential operations. |
| Authorization and approval | Does the execution layer check permission for the specific action? | Enforce authorization—and any required approval—before execution. |
These axes help explain risk and controls; they are not a ranking of commercial products. The important distinction is between a model proposing an action and an authorized execution component allowing it to happen.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

