LLMs are not agentic, they are the brain behind the agent.
A harness is what is used to make an agent, the LLM is simply the stateless engine that responds to queries. The harness is what creates the queries, makes decisions and takes actions. This is agentic AI in a nutshell.
Try it yourself, go to any of the LLMs and ask it to hack something, it has no ability to do that because it has no ability to take action. It only has the ability to respond to queries. With some clever prompting you could probably get it to build a hacking tool for you. But something has to run the tool, that is the harness.
The harness can be pointed at any LLM, whether in the cloud or run locally. The LLM is not aware that it is being run by an agent so regulating Anthropic, OpenAI, etc regarding agents doesn't make much sense. The agents can simply be pointed at DeepSeek, a Chinese model.
But you could hold users liable for the actions of their agents. This is where the pet tiger analogy makes sense. Now, you could say that the more advanced LLM models are what turn the pet into a tiger instead of a housecat. But that's also what turns an annoying chihuahua into a useful German shepherd.
Beware of AI Agent.