Agents moved from suggesting to acting.
A year ago the risk was a bad answer. Now the risk is a real command, a real file, a real commit, a real API call, often with nobody watching. The incidents in the field were rarely agents going rogue. They were agents doing exactly what they were told, against systems nobody meant to expose.