An agent that can truly “use your computer” is incredibly powerful, but it's also the first time the system has to act as you, not just for you. That shifts the problem from product design to permission, auditability, and undoability.
Summarizing notifications is boring, but it’s also reversible. Filing taxes or sending emails isn’t.
It feels less like Apple missing the idea, and more like waiting until they can make the irreversible actions feel safe.
All steps before it are reversible, and reviewable.
Bigger problem is attacker tricking your agent to leak your emails / financial data that your agent has access to.