AWS is pushing teams to treat egress as a real defense layer, because once a workload or agent is compromised, outbound traffic is how data leaves quietly. Inbound controls catch the front door; they miss the stage where an attacker or manipulated agent uses allowed network paths to exfiltrate data and keep command-and-control hidden in normal traffic.
The guidance ties that blind spot to both classic cloud apps and agentic AI systems. AWS points to CVE-2025-55182 as an example of how fast exploited workloads can start sending data out, and it cites agent hijacking and unexpected code execution as ways AI systems can become the exfiltration path when they have API or code access.