Eh. You're moving the goalposts here. You're describing a credential theft problem and then slapping "agentic swarm" on it. It doesn't rewrite what TCP/IP does.
An agent doesn't "pivot to an account that has egress." It assumes the identity that you already gave it. If that identity can assume another user’s creds, brute employee logins, or walk past MFA, you didn’t get beaten by AI. Malware, cron jobs, and a bored intern do the same thing.
Also, a swarm hammering every employee account isn't some kind of new threat class here. It's actually probably one of the louder attacks you can do and lockouts, rate limits, idp risk signals, etc exist so that this gets detected if someone just starts hammering away like this.
MFA bypass also isn't some special agent feature. Session theft and prompt bombing already worked with humans, so the model isn't getting some secret sauce attack to use.
Also, no one claimed that "basic firewall == security is done." The point you keep dodging is simpler: Agents open sockets like everything else does. Default-deny egress, allow only the destinations the workload needs, and inspect the path you permitted is part of security.
As far as "AI isn't bound to guardrails" - That's a dumb slogan AI doomers keep repeating. If your model is "what if it already has every account and MFA is broken," then you've defined a company that already was owned.