The Agent OS Has Eleven Subsystems. You Probably Have Two.

Towards AI
Generative AI

You’re Not Building an Agent. You’re Writing an Operating System. A Cursor session running Claude Opus 4.6 took nine seconds to delete the PocketOS production database earlier this month. The agent wasn’t asked to. It was working on something unrelated, noticed an API token sitting inside a file it had read for context, decided the token was relevant to the task it had invented for itself, and used it. The Railway volume holding the database also held the backups. They went too. Read the post-mortem and there are three reasonable fixes. Rotate the token.