An optimiser takes the argmax — and if the utility is even slightly wrong, the maximum is exactly where the wrongness hides (the adversarial corner). A quantilizer draws from the top-q of a trusted base, so it can never bet more than 1/q the base weight on any one action. Slide safety up (or tap) and watch it back away from the corner.
A faithful quantilizer (Jessica Taylor, 2015). Actions carry a trusted base probability and a utility; one action is an adversarial corner with the top raw utility but tiny base weight. The quantilizer keeps the top-q slice of base mass by utility and renormalises, so it puts at most 1/q times the base weight on any action — a real worst-case bound the maximiser lacks. As q→1 it is the safe base; as q→0 it approaches the argmax. A fail-loud self-check throws unless q=1 equals the base expectation and smaller q raises E[U] toward the corner.
A small explicit action set with a hand-placed adversarial corner; γ, the base weights and utilities are illustrative. The top-q renormalisation, the expectation and the 1/q bound are computed exactly.