AI agents are easiest to oversell right before they touch something expensive.
I do not want an agent sending money, touching credentials, or posting from my account without stopping me first. Drafting is cheap. A bad public action is not.
So the boundary I would actually trust is boring in the right places: gather the inputs, show the draft, point out the conflict, keep a log, then pause before the action can damage money, access, or reputation.
That is slower than the autonomy pitch, but probably closer to how serious users will adopt agents. Let the machine remove the repetitive work. Keep the human at the expensive edge until the system has earned more room.