The AGPL is about the operator of software not being legally allowed to hide nefarious code on their servers that harms users.
The problem is that if you're a big enough monopolist prooviding some online service that people have to use, you can do that in the open. You just comply with the AGPL and reveal all the code that tracks users or discriminates or whatever Bad Stuff. At the end of the day, the code is still running, and vast numbers of users are still logging in.
Basically, the AGPL has no real teeth; it gives the users no real control over the program they are using, only some visibility into it.
Nefarious behavior can be hidden in configurations, not just code. And in other services. Like suppose a server program, at some point in its execution, makes a HTTPS request to another server. The URL, including parameters and an POST data, are driven by data from a configuration database. Oops! Who knows what the heck that is doing? But, hey, if you want to run such a thing on your own machine, here is the source code.