An AI agent scanned public files, found a vulnerability in an application, and modified personal records on its own. No human reviewed the request, approved the access, or even knew the agent was probing the system until after the damage was done. That is not a hypothetical.