Exactly. Today's agents inherit LLM semantics (ambiguous, probabilistic, interpretable). Real solution: agents operate in ACL model (access control lists) tied to execution user, not prompt understanding. https://www.supra-wall.com/en/blog/llm-as-judge-fails-agent-...