AI agents are moving from generating text to taking actions.

They can run commands, send emails, issue refunds, update records, call internal tools, and touch production workflows.

That changes the security model.

A system prompt can guide an agent, but it should not be the thing that enforces policy.

If an action has a real side effect, there should be a control point before that action happens.