Scope: what this does not show
A design position that several parties converge on. It trades away capability and is not a measurement.
Corroborated: Supported by at least two independent sources.
Evidence
Jun 10, 2025
Jun 16, 2025
Oct 31, 2025
Jan 28, 2026
Feb 13, 2026
How it relates to other findings
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- This finding supports Separating an agent's control flow from untrusted data can give provable protection against control-flow hijacking at a modest utility cost.CaMeL is one implementation of this principle.
Key questions that rely on this finding
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Status history
- 2025-06-10ReportedDesign patterns paper argues for constraining agents. · record
- 2025-06-16CorroboratedIndependent framing of the same principle as the lethal trifecta. · record
- 2026-09-25CorroboratedcorrectionWillison's post quotes and builds on the design patterns paper, so it is not independent of it. Corroboration rests on separate organizations adopting the position, such as OpenAI's deterministic Lockdown Mode. · record