An agent can receive an objective, retrieve untrusted content, select a tool, delegate work and mutate an external system during one task. Each step may look ordinary to a separate gateway, IAM platform or log stream while the combined sequence exceeds the original purpose.
This does not make existing security controls obsolete. It creates a correlation problem between them: which agent was operating, on whose authority, toward which declared task, and with what outcome?