For example in years gone by, the ME may have requested data and would have been provided a weekly SQL dump of relevant data in CSV format. No harm if that data is becomes corrupted as it will be replaced in a couple days time.
But now, the ME can prompt the LLM. The LLM may search the company wiki, emails, Sharepoint servers, discover some AWS credentials, and directly access whatever environments those credentials allow, perhaps the production systems. The ME didn't know to tell the LLM to not do this. The ME asked for "n", and the LLM went off and did a bunch of stuff to accomplish "n". Huge harm if production data becomes corrupted, tables modified, etc.