AI Model Rules Are Not Security Controls

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.