Michael Nicosia, COO and cofounder at Salt Security. Security teams have spent the last few years securing the wrong things. While enterprises debated AI ethics and model safety, AI agents quietly earned the keys to production infrastructure. At Amazon, an AI coding agent made changes to a production environment without authorization, taking it offline for 13 hours, according to unnamed sources cited by the Financial Times. At McKinsey, as part of a red-team test, an autonomous agent breached their internal AI platform in under two hours and accessed 46.5 million internal chat messages. And at PocketOS, an AI coding agent deleted its database in seconds. Individually, these events may seem unrelated. Together, they point to something bigger: AI is no longer confined to generating outputs. It is being trusted to take action inside live systems. When those actions go wrong, the impact can be immediate and real. The Real Lesson From Early Incidents These incidents are an early signal of how quickly things can go wrong when autonomous systems are given operational access without sufficient controls. A self-running system can execute tasks in a live environment and cause irreversible damage in a matter of seconds. This doesn't mean AI is inherently unsafe. However, most organizations have not yet built the guardrails required for autonomous systems. There are still gaps in how permissions are defined, how actions are validated and how behavior is monitored in real time. When those gaps exist, even well-intentioned systems can create significant risk. From Assistants To Operational Actors Most recent discussions around AI risk have focused on outputs such as accuracy, bias and hallucinations. Those concerns matter, but they only address part of the picture. AI agents are now being deployed to write code, manage infrastructure, trigger workflows and interact directly with critical systems. This changes