An agent that reads an inbound email or a shared document can be made to obey instructions hidden inside it, because the model treats trusted commands and untrusted data as one stream. Here is why the failure is architectural, and the containment that holds.