This is an extension of running untrusted code, except AI agents are basically interpreting everything -> prompt injection.
I'm surprised we haven't _already_ seen a major personal incident as early adopters tend to be less cautious - my guess is that it has already happened and no incident has been publicized or gone viral yet.