Dispatch No. 005 · Bounded by Design, Part 5 of 6
The failure modes aren't exotic AI failures. They're distributed systems failures wearing a new name — and every player in this market is rewarded for not saying that out loud.
Four dispatches into this series, I've been building an architecture case. This week is the accountability case: where these systems actually fail in production, and the market incentives that keep everyone from naming it plainly.
Eight failure domains, none of them mysterious: telemetry and time, normalization and state, graph and retrieval, model and planning, authority and tools, execution and feedback, human oversight, and multi-agent and supply chain. Every one of them is a well-understood distributed systems problem with well-understood mitigations — the paper maps each one to the propagation path and the controls that actually stop it. What's actually interesting isn't the engineering — it's that the entire market structure around agentic security is currently built to reward describing the problem inaccurately.
Vendors are rewarded for surfacing the demonstrable AI layer over the invisible pipeline reliability underneath. Buyers are rewarded for procurement categories that read as progress in a board review. The press and analyst community close the loop by covering the demo, not the ordering guarantees. Nobody in that chain has a strong individual incentive to enforce precision — except the architect who's going to be on call when it fails.