When an autonomous agent gets an email address of its own, the first question your security team asks isn't "can it send mail?" It's "can you prove, six months from now, exactly what it said and to whom?"

That's a different problem from "does it work." A demo that fires off a few support replies...