They still haven't found any viable solution to prompt injection. Every time they put an AI agent in charge of anything important, that's a huge security risk.
The AIs are very stupid, and it's trivially easy to trick them into violating security protocols.