In early May 2026 the story broke that an AI coding agent had wiped the entire production database of a US SaaS provider, including every backup, in nine seconds. Most reporting on the incident focuses on the agent's behaviour and the question of whether AI tools are reliable enough for production use. Look closer and the story is something else: a failure across three independent architectural layers that the speed of the agent merely made visible. The lessons apply to anyone connecting AI tools with write access to production systems, regardless of which vendor is on the label.