I want to walk through the public AI-agent incidents from the last sixteen months in chronological order. The headline framing on each of them, when they hit the press, was the AI did X. Read with a few months of distance, the structural cause in each case turns out to be something much more pedestrian: a permission scope nobody narrowed, a retry...