I don't see this as being much different from a crane operator or airline pilot.
One of my clients has enforced a policy where a live human user principal must be supplied as a header with any requests outbound from the AI system. The effective policy is that you are completely (100%) responsible for what your agent does on your behalf. The AI system is designed to request confirmation for any potentially destructive actions.