Approval Fatigue
Approval fatigue is the loss of meaningful scrutiny when a person must answer too many repetitive permission requests from an AI agent. Benign-looking prompts become habitual, so the reviewer may skim, approve reflexively, ignore the queue or seek a broad bypass. The interface still records human approval, but the decision may no longer provide the assurance the control assumes.
Origin and context
The exact label appeared in reviewed agent-governance guidance by January 2025. In 2026, CoSAI listed consent or user-approval fatigue in its MCP threat analysis, Anthropic published data from Claude Code's permission flow, and independent security researchers framed runtime approval as a widespread but cognitively costly control. These uses adapt older warning- and consent-habituation problems to agents that request many actions quickly.
Why it matters
Human approval is protective only when the reviewer understands the proposed action, its target and its consequences. Agents can produce requests faster than people can evaluate them, while a long run of harmless actions teaches the reviewer that approval is usually safe. The resulting rubber stamp can hide risk behind a reassuring audit field. Excessive gates also create pressure to grant broader credentials or disable prompts entirely.
Example
A coding agent that requests confirmation for every read, test and local edit may condition a developer to approve the later command that changes shared infrastructure. A risk-tiered design can pre-authorize bounded, reversible work, deny prohibited actions and reserve a clear diff-based prompt for consequential exceptions. That reduces prompt volume, but the remaining policy, sandbox or classifier can still be wrong and needs monitoring.
How it differs
Automation bias in agentic AI
Automation bias is over-reliance on an automated recommendation. Approval fatigue is specifically the erosion of review under repeated decision load; either can reinforce the other, but they are not synonyms.
Agentic zero trust
Agentic zero trust scopes identity, delegation and authorization. Well-designed policy can reduce unnecessary prompts, while approval fatigue explains why sending every authorization decision to a person is not itself a robust architecture.
Copilot fatigue
Copilot fatigue is broader dissatisfaction or cognitive load from AI assistance. Approval fatigue concerns repeated authorization decisions and the reliability of a safety gate, even when the agent is otherwise useful.
Maturity and evidence
Maturity is rated 3. Independent security guidance, a consortium threat analysis, product telemetry, research and an experimental detection rule converge on the same failure mode. However, there is no standard metric, universal prompt threshold or mature comparative evidence for mitigations. The label is stable enough to explain, while measurement and attack prevalence remain early.
Limits and open questions
High approval volume does not prove inattentive review, and a high approval rate may reflect genuinely safe requests. Reducing prompts can improve attention but can also hide decisions inside overly broad policy. Sandboxes, allowlists and classifier gates shift rather than eliminate failure modes. Evaluate prompt quality, reversibility, scope, denials, overrides and post-action outcomes; do not treat a recorded click as evidence of informed consent or system safety.
Related terms
References
- Designing approvals that do not kill automationRelynt · 2025-01-22 · class C
- How we built Claude Code auto mode: a safer way to skip permissionsAnthropic · 2026-03-25 · class A
- Model Context Protocol (MCP) SecurityCoalition for Secure AI · 2026-01-08 · class A
- Reframing LLM Agent Security as an Agent-Human Interaction ProblemWang, Li and Tian / arXiv · 2026-05-23 · class B
- ATR-2026-00118: Human Approval Fatigue ExploitationAgent Threat Rule · 2026-03-26 · class B
Last updated: 2026-09-07