The brain-versus-body split between the model and the harness is a useful line to draw, because most "rogue AI" stories are really the harness handing the model capabilities nobody scoped. The zero-vectors-into-training-cache detail is the interesting one, since it's an attack on the pipeline, not the weights. Do you think harness-level constraints are where the real safety work has to happen?