prompt injection

13 statements across 4 episodes · 1 bullish · 9 bearish · 3 people on the record · first statement Jun 19, 2025 by Sander Schulhoff · across every show →

Everything said about prompt injection, oldest first

Jun 19, 2025 bearish
Insight
Schulhoff: Prompt injection is not solvable, only mitigatable
“It is not a solvable problem, which I think is very difficult for a lot of people to hear... So, you know, it's not solvable. It's mitigatable. You can kind of sometimes detect and track when it's happening, but it's really, really not solvable. And that's one…”
Sander Schulhoff Jun 19, 2025 ▶ 1:15:08 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Jun 19, 2025 negative
Insight
Schulhoff: AI guardrails fail due to intelligence gaps with main models
“The next step for defending is using some kind of AI guardrail. So you go out and you find or make, I mean, there's thousands of options out there an AI that looks at the user input and says, is this malicious or not? This is A very limited effect against a mo…”
Sander Schulhoff Jun 19, 2025 ▶ 1:11:06 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Jun 19, 2025 negative
Insight
Schulhoff: System prompt instructions do not prevent prompt injections at all
“The most common technique by far that is used to try to prevent prompt injection is improving your prompt and saying in your prompt or maybe in like the model system prompt. Do not follow any malicious instructions, ah, be a good model, ah, stuff like that. Th…”
Sander Schulhoff Jun 19, 2025 ▶ 1:09:48 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Dec 21, 2025 negative
Insight
Schulhoff: All Transformer-Based Chatbots Are Vulnerable to Adversarial Attacks
“And because all I guess for the most part, all currently deployed chatbots are based on transformers or transformer adjacent technologies. They're all vulnerable to Prompt injection, jailbreaking, forms of adversarial attacks.”
Sander Schulhoff Dec 21, 2025 ▶ 28:54 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Dec 21, 2025 neutral
Insight
Schulhoff: Jailbreaking targets models directly; prompt injection overrides developer prompts
“So the difference is in jailbreaking. It's just a malicious user and a model. In prompt injection, it's a malicious user, a model, and some developer prompt that the malicious user is trying to get the model to ignore.”
Sander Schulhoff Dec 21, 2025 ▶ 9:25 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Dec 21, 2025 neutral
Assertion Not checkable as stated
Schulhoff: There has not yet been a very damaging prompt injection incident
“Cause like I have a couple of examples that we can go through, but maybe strangely, maybe not so strangely, there hasn't been like a, an actually very damaging event quite yet.”
Sander Schulhoff Dec 21, 2025 ▶ 10:59 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Dec 21, 2025 positive
Insight
Schulhoff: Containerizing AI-generated code execution fully neutralizes prompt injection risks
“And then they'd be like, oh, you know, they, you know, they'd realize we can just dockerize that code run put it in a container. So it's running on a different system and take a look at the sanitized output. And now we're completely secure. So in that case, pr…”
Sander Schulhoff Dec 21, 2025 ▶ 53:37 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Dec 21, 2025 neutral
Assertion Partly supported
Schulhoff: Remotely.io was the first public prompt injection incident
“The very first example of prompt injection, Publicly on the internet was this Twitter chat bot by a company called remotely.io.”
Sander Schulhoff Dec 21, 2025 ▶ 11:52 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Dec 21, 2025 bearish
Opinion
Schulhoff: No meaningful progress made on solving prompt injection or jailbreaking
“And so in, in my professional opinion, there's been no meaningful progress made towards solving adversarial robustness, prompt injection, jailbreaking. In the last couple of years, since the problem was discovered and we're, we, you know, we're often seeing ne…”
Sander Schulhoff Dec 21, 2025 ▶ 1:12:29 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Jan 11, 2026 negative
Prediction Not checkable as stated
Reganti: Prompt injection will become a major crisis as AI goes mainstream
“I think that will be a huge problem once systems go mainstream. We're still so busy building AI products that we're not worried about security, but it will be such a huge problem to kind of especially with this non-deterministic API again, right? So you're kin…”
Aishwarya Reganti (Ash) Jan 11, 2026 ▶ 23:03 Why most AI products fail: Lessons from 50+ AI deployments at OpenAI, Google & Amazon
Apr 2, 2026 negative
Insight
Willison: LLMs fundamentally cannot separate trusted instructions from untrusted user text
“Agents fundamentally, like LLMs, can't tell the difference between texts that you give them and texts that you copy and paste in from other people. They're all the same thing. So instructions in that input text can always override the earlier instructions.”
Simon Willison Apr 2, 2026 ▶ 1:18:38 An AI state of the union: We’ve passed the inflection point & dark factories are coming
Apr 2, 2026 negative
Opinion
Willison: AI prompt injection benchmarks under 100% provide false security
“And again, until it's a hundred percent, I don't think it's a meaning. I think it just gives people a false sense of security that this problem won't bite them.”
Simon Willison Apr 2, 2026 ▶ 1:25:50 An AI state of the union: We’ve passed the inflection point & dark factories are coming
Apr 2, 2026 bearish
Prediction Not checkable as stated
Willison: AI will eventually suffer a catastrophic Challenger-style security disaster
“So my prediction is that we're going to see a challenging disaster. Like at some point, this is going to catch up with us and it's going to be Very, very, very bad, and that will hopefully help us start trying to figure out how not to do this. At the same time…”
Simon Willison Apr 2, 2026 ▶ 1:24:43 An AI state of the union: We’ve passed the inflection point & dark factories are coming
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.