This is true. However, if you simply forbid all “tools” or “actions” that are potentially harmful then there will be very little left the agent can actually do.
Every tool you give to an LLM agent might be used for “good” or “bad”. To filter malicious actions would need a way to classify the actions with confidence which imo would only work with human supervision.
However, I still think that the companies that develop such systems should still be responsible for what those systems do: They are the ones who pushed the “release” button on those systems.

















Yep. Pretty easy to find if the meeting is tomorrow or next week. But good luck finding the meeting you accepted yesterday that is in (maybe?) 3 months.
(I know again skill issue because the invite is conveniently stored in the deleted items)
Also god forbid if people want to have different work flows than Microsoft intended.