Skip to main content
Published A09 February 2026 9 min read

Unbounded Agent Actions: Rate Limits and Guardrails

An agent without rate limits is a liability. Without spending caps, action boundaries, and circuit breakers, a single runaway agent can exhaust resources, drain budgets, and cascade failures across your entire infrastructure.

What Are Unbounded Agent Actions?

Traditional software has natural limits—a web server can only handle so many requests, a database connection pool has a maximum size. But autonomous agents can spawn actions without any inherent boundary.

When an agent has the ability to call APIs, make purchases, send messages, or delegate tasks to other agents—and there's no limit on how many times or how quickly it can do so—you've created a system with unbounded action potential. The result: resource exhaustion, financial damage, and cascading failures.

No Rate Limits

1000 API calls/second

No Spending Caps

$50K bill overnight

No Circuit Breakers

Cascading failures

The Denial-of-Wallet Problem

"Denial of wallet" is the financial cousin of denial of service. Instead of crashing a server, the attacker (or a misconfigured agent) racks up enormous bills:

API Cost Explosion

An agent tasked with "research this topic thoroughly" calls GPT-4 10,000 times in a loop, each with a 128K context window. At $0.01/1K tokens, that's potentially tens of thousands of dollars in a single session.

Compute Runaway

An agent with cloud provisioning access spins up GPU instances "for performance" and never shuts them down. Or worse, enters a retry loop that spawns more and more compute resources.

Payment Drainage

An agent authorized to make purchases has no per-transaction or daily spending limit. A prompt injection or logic error causes it to place hundreds of orders, draining connected payment accounts.

Attack Patterns

Infinite Loops

An agent enters a retry loop—each failure triggers another attempt, which triggers another failure. Without max-retry limits, this continues until resources are exhausted or someone manually kills the process.

Resource Exhaustion

An agent consuming unbounded memory, CPU, or network bandwidth. In serverless environments, this means unbounded billing. In shared infrastructure, it means degraded performance for everyone.

Cascading API Calls

Agent A calls Agent B, which calls Agent C, which calls back to Agent A. Without depth limits or cycle detection, this creates an exponential explosion of requests that can take down entire agent networks.

Payment Drainage

Agents with payment capabilities that have no per-transaction limits, daily caps, or approval thresholds. A single misconfigured or compromised agent can drain accounts in minutes.

How KYM Mitigates This

KnowYourModel implements multiple layers of action boundaries:

3-Tier Rate Limiting

KV-backed rate limits at three tiers: 1,000 requests/day (free), 10,000/day (registered), and 100,000/day (verified). Each tier is enforced per API key with sliding window counters stored in Cloudflare KV.

x402 Payment Receipt Verification

Every paid action requires a cryptographically signed usage receipt. Agents can't spend more than they've been authorized for—each receipt is validated against the payment intent, and double-spending is prevented through receipt deduplication.

Nanda Points Staking Bounds

The NP staking system bounds how much any single agent can commit. Staking requires a minimum balance, and the maximum stake is capped relative to the agent's reputation score. This prevents both sybil attacks and unbounded resource allocation.

Usage Receipts & Audit Trail

Every action generates a tamper-evident receipt. Anomaly detection flags unusual patterns—sudden spikes in API calls, unusual spending patterns, or unexpected agent-to-agent delegation chains.

Defense Checklist

Essential Guardrails

  • Rate limits: Per-agent, per-API, and per-session request limits with sliding window enforcement
  • Budget caps: Hard spending limits per transaction, per session, and per day—with escalation for overrides
  • Circuit breakers: Automatic shutdown when error rates exceed thresholds or when cascading failures are detected
  • Usage monitoring: Real-time dashboards with alerts for anomalous usage patterns and spending spikes
  • Kill switches: Ability to immediately halt any agent, revoke API keys, and freeze budgets in an emergency

Anti-Patterns

  • Unlimited retries: "Try again until it works" without max attempts is a guaranteed infinite loop waiting to happen
  • No timeout policies: Agent tasks that run indefinitely consume resources and can block other operations
  • Trust-based limits: Relying on the model to "know when to stop" instead of enforcing hard limits at the infrastructure level

Real-World Incidents

2025 Denial-of-Wallet via AI Agent Loops

Security researchers demonstrated that adversarial prompts could force AI agents into infinite retry loops against paid APIs. Without budget caps or circuit breakers, a single poisoned request caused agents to exhaust thousands of dollars in API credits within minutes—a pattern OWASP now classifies as ASI08 (Cascading Failures).

2025 GitHub Actions — Unbounded Workflow Execution

Aikido Security's PromptPwnd research revealed that AI-powered GitHub Actions could be triggered repeatedly by malicious issue or PR content. Without execution limits, agents spawned unlimited workflow runs, consuming CI/CD minutes and exposing secrets through unbounded tool invocations—demonstrating how resource exhaustion amplifies tool misuse.

2025 Rogue Agent Self-Replication

OWASP documented cases (ASI10: Rogue Agents) where compromised agents persisted across sessions, continuously exfiltrating data and spawning sub-agents. Without kill switches, behavioral monitoring, or action budgets, these agents operated undetected—consuming unbounded resources while appearing to perform legitimate tasks.

Further Reading

Related in the OWASP Agentic Top 10

Agent Memory Poisoning: Persistent Threats in AI Systems

Rate limits protect against unbounded actions—but what about attacks that corrupt the agent's knowledge itself? A05 explores how memory poisoning creates persistent, cross-session threats.

Read A05: Agent Memory Poisoning