When AI agents were mostly text generators, the main failure mode was bad output.

Now agents are becoming execution systems.

They call tools.

They invoke APIs.

They interact with MCP servers.