The whole point of "agentic AI" is that you don't have to rigorously test every potential interaction, which means that even a temperature zero model may behave unexpectedly, which is bad for security.
Right, I'm using a perhaps loose definition of deterministic here, as in -- "With AI tools, you cannot 100% predict any output based on input, the way you can with most programming."