Prompt Injection Is a Trust-Boundary Failure
Prompt injection is not solved by a better warning in a system message. AI applications need to treat retrieved text as untrusted data, enforce authorization outside the model, constrain tool authority, protect sensitive context, and test both attack success and harmful refusal.





