Intent Is Not an Authorization Boundary
Three disclosed cyber-evaluation failures show why consequential actions cannot be authorized by inferred intent or situational awareness: scope, egress and credentials need controls the agent cannot reinterpret.