I used to think the scary part of AI agents was the model hallucinating.

It isn’t.

The scary part is when your system looks fine — green logs, clean outputs, a polite writer agent producing a report — and somewhere in the middle, one message quietly changed the mission.

Not because a user typed something evil.

Because a researcher agent fetched a page. Because a tool returned poisoned text. Because the next agent trusted its teammate the way we trust people we work with every day.