Skip to content
Beyond Prompt AI Studio
AI Security for Businesses

Approval Fatigue: Why "A Human Checks It" Isn't Enough

An approval gate for irreversible actions sounds like a solid solution – until you look at how people actually treat such approvals in practice. One number from vendor telemetry shows the problem in stark terms.

Four approval realities – worth remembering

Try it yourself: match the approval behaviour to its consequence

Approval behaviour

Consequence

93 percent: the number that devalues approval gates on their own

According to vendor telemetry, around 93% of all approval prompts for AI agents get confirmed without a real check. That matches a general pattern from security research: the more often a warning or confirmation prompt appears, the more it becomes a routine gesture instead of a deliberate decision. An approval gate that theoretically protects but gets reflexively clicked away in practice offers no real safety – only the feeling of it.

The second problem: over-privileged agents from the start

Approval fatigue is made worse by a structural problem: around 90% of deployed agents are over-privileged relative to their actual task – they're technically capable of more than their function requires. Combine over-privileged setup with an approval that's only formally confirmed anyway, and there's practically no effective control left. Around 88% of organisations reported at least one AI agent security incident in the same period – direct evidence that this combination actually goes wrong in practice.

Why step-by-step checking doesn't solve the problem

A single step an agent takes almost always looks harmless on its own – reading a file, setting a parameter, calling a tool. Only the chaining of several harmless individual steps adds up to a risky overall action. Anyone who only evaluates each step in isolation rarely sees the actual risk – which is exactly why leading providers now evaluate entire action chains instead of individual steps, to close precisely that gap.

The key points

  • Around 93% of all approval prompts for AI agents get confirmed without a real check, per vendor telemetry – an approval gate alone therefore guarantees no real safety.
  • Around 90% of deployed agents are over-privileged relative to their task – combined with reflexive confirmation, hardly any effective control remains.
  • Around 88% of organisations already reported at least one AI agent security incident – direct evidence of the consequences of this combination.
  • Step-by-step checking misses the actual risk: only the chaining of several harmless steps adds up to the risky overall action.
  • The effective consequence: ask for approval less often, but more meaningfully – on real action chains with genuinely irreversible consequences, not on every little thing.

The OpenAI incident: why your AI agent is not a new employee

Quick check: did it sink in?

1 / 3

What does the 93% figure in this module show?

Want to design your approval processes so they actually protect instead of just reassuring?