Enterprise AI agents can become a security problem long before they become a breach: once they are given broad access to records, systems, and tools, the real danger is uncontrolled context, not model “intelligence.”