NEXIUS RISK GUIDE / BUSINESS PROCESS CONTROLS

Know the risks
before agents act.

Prompt injection and tool poisoning are gateway threats. This guide maps the wider business-process dangers that appear when agents can access data, use tools, remember context, and act across real systems.

Explore the risk landscape
17 RISKS / CONTROLS / OWNERSHIP

THE WIDER RISK LANDSCAPE

Every new capability creates
a corresponding control decision.

A chatbot can say the wrong thing. An agent can do the wrong thing. The practical response is not to avoid agents, but to govern them like junior operators with scoped roles, limited permissions, clear procedures, approval gates, evidence requirements, audit trails, and escalation rules.

01

Authority and data

Limit what an agent can access, decide, and change.

CRITICAL

Over-permissioned agents

Broad tools or credentials allow a mistake or attack to create consequences far beyond the intended task.

CRITICAL

Data leakage and cross-channel exposure

Sensitive information can move into prompts, logs, messages, third-party tools, or the wrong communication channel.

HIGH

Unauthorised external actions

An agent may send, publish, delete, spend, deploy, or modify a business record without sufficient review.

02

Decisions and accountability

Make evidence, ownership, and uncertainty visible.

HIGH

Silent wrong decisions

Plausible classifications or recommendations may be accepted without the confidence, evidence, or exception signals needed for review.

HIGH

Hallucinated business facts

Invented policies, figures, customer facts, or transaction details can enter real work and influence decisions.

HIGH

Weak accountability and auditability

The organisation cannot reconstruct what the agent saw, which tools it used, who approved the action, or what changed.

03

Memory and isolation

Prevent old or unrelated context from contaminating new work.

HIGH

Persistent memory poisoning

Incorrect or malicious information can persist and influence later tasks after the original context has disappeared.

HIGH

Cross-client or workspace contamination

Context, files, credentials, or memories from one client or business unit can appear in another agent session.

04

Reliability and cost

Ensure the operating loop stops, fails visibly, and stays economical.

MEDIUM-HIGH

Runaway loops and cost overruns

Repeated retries, recursive delegation, or excessive model calls consume time and budget without producing an acceptable outcome.

MEDIUM-HIGH

Brittle integrations and silent tool failure

A connector may time out, return partial data, or report success while the business system remains unchanged.

MEDIUM

Poor human-agent handoffs

People cannot tell whether work is waiting, complete, blocked, or requires a decision, so tasks stall or are duplicated.

05

Reputation and governance

Keep agent behaviour aligned with brand, law, and organisational policy.

MEDIUM

Reputational damage

Poorly judged, inaccurate, or insensitive communication can reach customers, partners, employees, or the public.

MEDIUM

Provider and data-residency risk

Model routing can expose sensitive data to a provider, region, or retention policy the organisation did not intend to use.

MEDIUM

Agent impersonation and social engineering

Attackers or poorly identified agents can misrepresent authority, request secrets, or create false confidence in an action.

MEDIUM

Compliance and legal drift

Agent behaviour may gradually diverge from updated regulations, contracts, internal policy, or record-keeping obligations.

THE CONTROL MODEL

Eight governance layers
contain the blast radius.

Model safeguards matter, but they cannot stand alone. Organisational and technical controls must overlap so one missed attack or faulty decision does not become a business-wide failure.

See Agent Governance in the Nexius Path
  1. 01Role design
  2. 02Tool permissions
  3. 03Data boundaries
  4. 04Approval gates
  5. 05Evidence capture
  6. 06Audit trail
  7. 07Monitoring
  8. 08Escalation

EVIDENCE AND FURTHER READING

Use established guidance
alongside operating evidence.

This Nexius interpretation is informed by the supplied AI Agent Business Process Risk Report and supported by primary security and risk-management guidance.

OWASP GENAI SECURITY PROJECTLLM01:2025 Prompt InjectionOWASP GENAI SECURITY PROJECTLLM06:2025 Excessive AgencyNISTAI Risk Management Framework

COMMON QUESTIONS

Assess agent risk
before applying it.

The central risk is excessive authority: a mistake, attack, or poor decision can create real consequences when the agent has broad access or can act without proportionate review.

START WITH THE GATEWAY THREATS

Prompt injection and tool poisoning can redirect the agent.

One attacks through the content an agent reads. The other attacks through the capability layer it trusts. Both become more dangerous when the agent has broad permissions or can take actions without review.

Read the control and governance guide