An autonomous agent just pushed code to production at 2 a.m. It accessed a Kubernetes secret, called an API, and spun up a new container instance. Nothing broke, but you have no idea who authorized that action, what data it saw, or whether the model deviated from policy. Welcome