That's not the point. Let's put aside that an LLM driven agent is not deterministic ie, not always doing what the user intended, just like regular text autocomplete messes up as well regularly. The point is that like with e-mails when spam became so easy to generate that it flooded the system, now more sophisticated actions on the internet get easier to do (that said, most of it was possible already before, just required more skill), at least as long as LLMs are not charged at real costs but highly subsidised.
At some point something has to give. Either tools will be developed to somewhat reliably classify the nature of the traffic or things will start to be priced out as everyone will have to pay the bill for this new kind of spam (ie low value high volume traffic, or ill intended traffic)