Think of a brilliant new assistant who treats every email, document, and sticky note on their desk as a direct order, including the forged ones. That’s a prompt injection attack. Large language models process instructions and untrusted data through the same conversational context, making it difficult to reliably distinguish trusted instructions from untrusted content without …