This is a fascinating low-level trick. Feels like there’s a pattern here that can be used to regulate AIs at natural language level too (in this form it might not work depending on what permissions the agent has over the linked source of uncertainty).