Control AI agent egress with verified identities, scoped destinations and data safeguards, while accounting for trusted-service and DNS bypass risks.