In recent months, AI agents have been exploited using nothing more than prompt injection methods.
I've several news like this. Kinda wild seeing how some AI found bugs and exploit them, while at the same time being exploited with injections and whatnot. I guess that shows how young this tech is. Not to mention older tech also got exploited every now and then.
I don't think my feelings towards using AI for autonomous payments (or anything sensitive) will change unless there's a feature that limit them. Even in my bank account with regular payment option I avoided them since I don't trust how secure they are. I feel it's just a case of waiting a big exploit to happen.