" Agentic AI " possesses the autonomy to perform actions within a system. In a cybersecurity context, an agent might autonomously block an IP or shut down a database if it detects a threat. The most significant risk is that a " False Positive " could trigger an automated response that causes a massive service disruption. Auditors must validate the existence of " Guardrails, " " Human-in-the-loop " approval for high-impact actions, and " Kill Switches " to halt the agent if it behaves erratically. While reduced intervention (Option B) is a benefit, it is also the primary driver of this operational risk.