The most uncomfortable detail of the breach had nothing to do with the attacker. When defenders sat down to run forensics, the hosted frontier models they reached for refused to help — unable to tell a responder investigating an intrusion from an intruder committing one — so the entire post-mortem ran on a self-hosted, open-weight model instead.
Over-refusal, treated for a year as a harmless annoyance, has become a measurable regression that quietly pushes serious security work toward weights an organization can own. The same week a model showed why you might fear AI, its safety layer showed why you might need to control your own.
The craft response is to stop letting the model run the show. Treat the agent as a loop owned by deterministic code, invoked at only two or three points, governed by four levers — context, control flow, state and scope. The arithmetic is unforgiving: steps that each succeed 95% of the time compound to barely one-in-three across twenty.