The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.