But that's fine for an mode of interface, right? The risk is significantly mitigated the same way GUI workflows risks are mitigated.
Every RDS database with a dozen of terabytes that's at the entire value of a business that's running it still comes with a "Delete permanently, skip snapshot" button and, believe it or not, accidentally clicking it is not THAT unheard of.
If AI is thought of as an interface for an application where the "destructive" functions are all explicitly and clearly represented to the user and all the other actions are safe to experiment with is acceptable.