AI Agent Consumption Risks Have Surged
Researchers demonstrated that poisoned inputs can trigger recursive tool calls, driving agent costs up exponentially.
Updated on Sept. 22, 2026 in Artificial Intelligence

Live Poll
Do you trust companies to effectively manage the security risks associated with their AI tools?
Forcepoint has simulated an agent-tool fan-out attack where malicious inputs force AI agents into resource-draining reasoning loops. This vulnerability has contributed to the unbounded consumption risk moving from No. 10 to No. 6 on the OWASP list for 2026.
Why it matters
As AI agents process accumulating context, they become susceptible to denial-of-wallet and reasoning-loop exhaustion that can rapidly inflate operational costs. The rise in the OWASP ranking highlights the increasing industry focus on securing autonomous systems against these recursive feedback vulnerabilities.
A protected agent using a circuit breaker and recursion depth limit completed a tool call for $0.02, while agents without these controls could exceed $10 in costs per poisoned source. Costs scale significantly, rising from $0.001 on the first turn to $0.50 by turn 100.
The players
Forcepoint
A cybersecurity firm specializing in data protection, cloud security, and risk-adaptive behavioral analytics for enterprise environments.
OWASP
The Open Worldwide Application Security Project, a nonprofit foundation that develops consensus-driven security standards and risk lists for software.
The details
The attack functions by poisoning an AI agent's input, which tricks the model into triggering excessive, recursive tool calls—small programs the AI uses to retrieve data or execute functions. By forcing the agent to repeatedly question its own reasoning, the attack burns thinking tokens and exploits the way agents handle growing context windows. While the simulation used a 500-call cap, an unprotected system may continue these calls until the budget is exhausted.
Timeline
Unbounded consumption ranked No. 10 on the OWASP list in 2025.
Unbounded consumption rose to No. 6 on the OWASP list in 2026.
The Tech Race
The shift in the OWASP ranking reflects a broader industry race to secure AI agents against increasingly sophisticated automated exploitation methods. This move elevates agent resource exhaustion to the same level of concern as established model extraction threats.
Organizations deploying AI agents should implement strict recursion depth limits and circuit breakers to prevent unauthorized costs. These technical controls serve as the primary defense against denial-of-wallet scenarios until further security patches become available.
The takeaway
The trajectory of agent security indicates that operational cost controls are now as critical as data privacy for enterprise AI developers. Monitor upcoming updates to the OWASP guidelines for standardized best practices on implementing circuit breakers and recursive call limits.
Further reading
For more context on securing autonomous systems, visit Artificial Intelligence.
Source note: This article includes information reported by SC Media.
Live Poll
Do you trust companies to effectively manage the security risks associated with their AI tools?






