Imagine your AI assistant pushes code to production at 2 a.m., queries a production database, or sends logs to a third-party API. It’s not malicious, just overeager. But in the age of autonomous agents and copilots, that single action could expose secrets, violate compliance policies, or trigger an