The biggest risks are unauthorized cross-system actions, prompt injection, hallucinated outputs, and fragmented permissions. An agent with write access across the MES, ERP, and payment systems can cause damage beyond a single system if governance is weak. The NIST AI 600-1 Generative AI Profile provides a framework for managing these risks, and the practical controls are least-privilege roles mapped across systems, a propose-then-approve model for consequential actions, and one audit trail per business outcome. For any action touching production schedules, the general ledger, or vendor payments, a human should approve before execution.










