As enterprises give AI agents more autonomy — the ability to plan, decide, and act across systems without a human approving each step — a hard question moves to the center of every architecture review: When an agent tries to complete an action that it was never authorized to do, what actually stops it?

We want to give agents enough authority to be useful but with strong guardrails to curb the damage they can do. New financial limits from AWS are a good start.

An AI agent can now read a repository, modify code, run tests, prepare a release, update a ticket,...