A system prompt telling your AI agent to show users only the data they’re cleared to see is not a security control. It’s a suggestion, written in English, sitting in the same context window as every other piece of text the agent processes, and suggestions get bypassed. That is not a provocative claim anymore.