As AI agents get access to customer records, RAG pipelines and persistent memory, I think one issue deserves more attention: authorization at the evidence layer.
It is not enough for an LLM to retrieve relevant information. It also needs to know whether that evidence is authorized for this specific requester, tenant and response.