Approval fatigue is agent governance's next attack surface
Blog post from WorkOS
Approval fatigue in agentic AI arises when frequent permission requests cause employees to approve actions reflexively, weakening safeguards intended to protect sensitive operations such as database changes, external communications, or ticket closures. Drawing parallels with alert fatigue in security operations and consent fatigue in cookie banners, the discussion argues that repetitive, low-variation requests encourage people to adopt “approve” as a default heuristic rather than carefully assessing each action, while noting that recent healthcare research does not support a broad theory that judgment simply deteriorates after many decisions. The issue has become an intentional attack vector, with adversaries reportedly using benign framing, urgency, repeated prompts, and batches of routine actions to conceal risky requests and exploit human trust. Uniform approval gates can worsen the problem by treating low- and high-consequence actions alike, creating queues that exhaust attention without providing meaningful oversight. More effective governance would place controls outside the model’s influence, assess actions according to consequence and reversibility, treat manipulative wording as a risk signal, route only meaningful exceptions to humans, and monitor approval rates, response times, and overrides for evidence that review processes are becoming performative.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 4 | 1,180 | 266 | 113 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.