Your AI Agent’s Safety Guardrails Are a Polite Suggestion — And Everyone Knows It
Every prompt filter, every output guardrail, every safety library you’ve bolted onto your agent lives *inside* the same address space the agent can reach. That’s not a safety system — that’s a lock made of the same clay as the door. This paper argues the whole paradigm is architecturally broken, and then tries to fix it.
