Here's a rule I use that sounds paranoid until you watch it work: when my AI agent changes one of its own safety gates, the change gets reviewed by a panel of four rival AI models from four different labs — and one dissent kills the change. Not a vote. If one reviewer says "risky," it's risky, even when the other two say ship it.

One detail before the story, because the numbers below say three, not four: during these rounds one of the four reviewers was down. The system doesn't quietly run smaller when that happens; it stamps the missing seat onto every verdict it issues. So these rounds ran three-of-four, with the absence on the record.

This week that rule earned its keep.

The bug that took four rounds to die

The change under review was a safety gate — the thing that stops my agent from "freezing" a test harness that's secretly blind to some of its inputs. I'd hit that failure before, thought I'd fixed the gate, and sent the fix to the panel.