I remember back in the 2010s the debates between "oracle" and "agent" AGIs, and the arguments that AGIs that only answer questions would be safe and certainly nobody would ever be stupid enough to just let an AGI out of a sandbox, never mind to the greater internet, and give it tools to do whatever it thinks is needed to reach a goal.
Us circa 2026: "Hold my beer"
Yeah, I really miss the "nobody would ever be stupid enough to [_____]" days of AGI safety discourse.