Most reviews of an AI agent focus on capability. Can it read the right records, does it hallucinate, is the output good enough to send to a customer. Sensible questions. They are also the wrong place to spend your caution.
An agent that is right 90% of the time and can be switched off in sixty seconds is safer to run than one that is right 99% of the time and takes a change-management window to stop. Accuracy degrades quietly. A missing off switch fails all at once, and always at the worst moment.
The blocker is rarely technical. It is that the agent borrowed a human's credential, and three other things quietly borrowed the same one. Nobody wrote that down.
So the question worth asking before deployment is not how good it is. It is: if this thing starts doing the wrong thing tonight, who can stop it, and what else goes dark when they do?
https://unlockedconsulting.ai/blog/ai-agent-identity-access-revocation