Agentic AI security has spent the last year stuck in an awkward phase: everyone agrees prompt injection is real, but too many defenses still look like chat-app bandages wrapped around systems that now browse, write code, invoke tools, remember state, delegate work, and ask humans to approve things they barely