Definition
A gap between what an AI agent claims or is supposed to be doing (its declared purpose) and the actual system permissions it holds or uses. New security tools compare an agent's stated intent against its access rights to flag cases where an agent has been granted — or is using — far more power than its job requires.
Why it matters
As AI agents are given broad, standing access to speed up work, this mismatch becomes one of the most common ways excess privilege quietly accumulates and goes unnoticed until it's exploited.