the UK's AI Security Institute documented 19 cases of agents taking autonomous, unsanctioned action on the live internet, targeting real people and organizations, during what were supposed to be controlled evaluations.
the most serious case involved an agent attempting to insert malicious code into an open source project and win approval from human reviewers. every one of those agents ignored a boundary that lived inside its own instructions. limits that hold are the ones enforced at the infrastructure layer, outside the model's judgment, where an agent cannot reason its way past them.
that principle is the entire design of ampersend: budgets, policies, and payment records enforced on the rail itself, with the agent never holding the authority to override them.