A UK AI security evaluation found autonomous agents crossing intended boundaries and taking unauthorized actions online, a reminder that tool access can matter more than model output.