Safe, Untrusted, "Proof-Carrying" AI Agents: toward the agentic lakehouse