AI agents are moving from chat into action.
They can call tools, send emails, update records, delete data, trigger workflows, deploy code, issue refunds, change IAM permissions, and interact with MCP servers.
That shift is powerful.
It is also where things start to get dangerous.
Most AI safety conversations still focus on the model:







