The cars are still unsafe at speed. All those mitigations reduce the risks but do not eliminate the inherent danger. Sandboxing agentic LLMs is similar, there is no way to mitigate the inherent safety problem entirely while preserving the power of the thing (an LLM without a harness is safe in the way an engine without a chassis is - safe and useless).
But safety is just one thing people optimise for; if it's convenient enough people will accept imperfect safety (as with cars). It's unrealistic to just heap blame on end-users who use mostly very safe tools in the common way, even though in aggregate they are meaningfully dangerous. They don't think they are strapping a weed whacker to a dog; they think they are driving a car.
And therein lies the problem. I listed all the things that differentiate cars from current AI models: cars require a license to drive, they are subject to heavy regulation (insurance, registration, inspections, etc.), there's road signs, police, incident statistics, recalls in case of defects etc. etc. NONE of that is currently in place for AI models and the systems surrounding them. So the analogy is flawed on every level. I don't buy the convenience is just too appealing narrative when your own analogy clearly demonstrates what is required in order to roll out dangerous technology to the masses, while NONE of that is in place in the context of AI models.