The continuous execution modes announced in the period change the nature of interaction: instead of evaluating each answer, the person sets an objective and the system works until it gets there.
That transfer of decision requires a counterpart that rarely ships with the feature: an explicit list of what the system can't do without confirmation.
The list needn't be long and usually fits in a few items: deleting files, changing production configuration, publishing changes, sending data outside, and spending above a defined ceiling.
Without that prior definition, the decision about what counts as irreversible ends up being made by the system itself, on criteria nobody wrote and that appear nowhere when something goes wrong.
It's the same recommendation that ran through the year's agent incidents, applied now to the most common case: it isn't an external attack, it's an authorised system doing more than someone would have authorised if asked.
