Jun 19, 2025 · 1h 37m · lennys-podcast

AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff

Sander Schulhoff · 1h 3m spoken Lenny Rachitsky · 21m spoken Christina Cacioppo · 47s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this comprehensive interview, AI researcher Sander Schulhoff details proven prompt engineering techniques for production applications and examines the persistent security vulnerabilities and red-teaming challenges confronting autonomous AI systems.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Lenny holds 25.2% of the talking time here. How this is scored →

Lenny as informed peer 4.4 Guest teaching 5.8 Guest disagreement 1.7 Lenny pushing back 1.1
05100:0020:0040:001:00:001:20:005:00–9:02 · Lenny as informed peer 4/10 Prompt Engineering Longevity and Artificial Social Intelligence Lenny frames the debate around prompt engineering relevance by quoting Reid Hoffman. Sander introduces the concept of Artificial Social Intelligence and cites a 70% accuracy boost in medical coding through detailed prompt engineering.9:02–12:02 · Lenny as informed peer 5/10 Conversational Prompting Versus Product-Focused Prompt Engineering Lenny introduces concrete product examples like Granola, Bolt, Lovable, and v0 to articulate the difference between conversational and embedded production prompts. Sander adopts Lenny's phrasing of product-focused prompt engineering.12:03–17:31 · Lenny as informed peer 5/10 Few-Shot Prompting and Optimal Prompt Formatting Lenny confuses zero-shot and one-shot prompting before Sander gently clarifies standard ML indexing. Lenny then demonstrates his knowledge by citing Y Combinator discussions on RLHF XML post-training formats.17:32–24:53 · Lenny as informed peer 4/10 Debunking Role Prompting and Emotional Manipulation Myths Sander dismantles the popular belief that role prompting improves accuracy on reasoning tasks, citing benchmark data with negligible 0.01 variance. Lenny acknowledges his own heavy reliance on copywriter role prompts and switches his assumptions.24:54–30:10 · Lenny as informed peer 4/10 Decomposition Strategies and Self-Criticism Prompting Lenny asks how decomposition differs from chain-of-thought prompting. Sander illustrates with an agentic car dealership return policy example, walking through sub-problem isolation before running tool calls.30:10–40:29 · Lenny as informed peer 5/10 Context Architecture, Suicidal Ideation Research, and Prompt Caching Lenny neatly recaps the first four prompting strategies and shares his own workflow using Claude for guest preparation. Sander explains NLP entrapment research and the cost/latency benefits of top-of-prompt caching.40:30–44:28 · Lenny as informed peer 4/10 Advanced Prompting: Ensembling and Mixture of Reasoning Experts Sander explains multi-agent ensembling and the Mixture of Reasoning Experts technique developed at Stanford. Lenny asks a clarifying question about single-model vs multi-model ensembling setups.44:30–51:56 · Lenny as informed peer 5/10 Sponsor Message: Vanta Compliance Automation Following a sponsor read with Christina Cacioppo, Lenny probes whether explicit chain-of-thought prompting is obsolete with modern reasoning models. Sander notes edge-case non-reasoning fallbacks in production before sharing a practical reality check on his own conversational shorthand prompts.51:56–59:04 · Lenny as informed peer 3/10 AI Red Teaming, Grandmother Jailbreaks, and HackAPrompt Sander introduces prompt injection and red teaming, highlighting the grandmother bomb bedtime story jailbreak and his award-winning HackAPrompt competition. He differentiates classical security flaws from looming agentic physical safety concerns.59:04–1:09:30 · Lenny as informed peer 4/10 CBRN Threats, Obfuscation Vectors, and Agentic Code Vulnerabilities Sander details dangerous CBRN uplift vectors and illustrates biblical obfuscation via Ender's Game before demonstrating Base64 and Spanish translation jailbreaks. Lenny links the discussion to indirect prompt injection in autonomous coding agents.1:09:32–1:16:36 · Lenny as informed peer 4/10 Why System Prompts and Guardrails Fail: Mitigating Prompt Injections Sander forcefully dismisses system prompt instructions and external guardrails as fundamentally ineffective due to the intelligence gap between guardrail models and base LLMs. He states plainly that prompt injection is an unsolvable problem.1:16:36–1:26:44 · Lenny as informed peer 5/10 Misalignment Risks, Autonomous SDR Scenarios, and AI Regulation Lenny references Asimov's robot laws, Anthropic blackmail test cases, and the paperclip maximizer. Sander explains his conversion to believing misalignment risks through Palisade chess exploits and paints an extreme autonomous SDR scenario.1:26:45–1:35:37 · Lenny as informed peer 5/10 Lightning Round: Books, Culture, Everyday Tech, and Life Mottos In the lightning round, Sander shares his love for The River of Doubt, Black Mirror, and the Daylight Computer DC-1. Lenny surprises Sander by revealing he was an early angel investor in the Daylight Computer.5:00–9:02 · Guest teaching 5/10 Prompt Engineering Longevity and Artificial Social Intelligence Lenny frames the debate around prompt engineering relevance by quoting Reid Hoffman. Sander introduces the concept of Artificial Social Intelligence and cites a 70% accuracy boost in medical coding through detailed prompt engineering.9:02–12:02 · Guest teaching 3/10 Conversational Prompting Versus Product-Focused Prompt Engineering Lenny introduces concrete product examples like Granola, Bolt, Lovable, and v0 to articulate the difference between conversational and embedded production prompts. Sander adopts Lenny's phrasing of product-focused prompt engineering.12:03–17:31 · Guest teaching 6/10 Few-Shot Prompting and Optimal Prompt Formatting Lenny confuses zero-shot and one-shot prompting before Sander gently clarifies standard ML indexing. Lenny then demonstrates his knowledge by citing Y Combinator discussions on RLHF XML post-training formats.17:32–24:53 · Guest teaching 7/10 Debunking Role Prompting and Emotional Manipulation Myths Sander dismantles the popular belief that role prompting improves accuracy on reasoning tasks, citing benchmark data with negligible 0.01 variance. Lenny acknowledges his own heavy reliance on copywriter role prompts and switches his assumptions.24:54–30:10 · Guest teaching 6/10 Decomposition Strategies and Self-Criticism Prompting Lenny asks how decomposition differs from chain-of-thought prompting. Sander illustrates with an agentic car dealership return policy example, walking through sub-problem isolation before running tool calls.30:10–40:29 · Guest teaching 6/10 Context Architecture, Suicidal Ideation Research, and Prompt Caching Lenny neatly recaps the first four prompting strategies and shares his own workflow using Claude for guest preparation. Sander explains NLP entrapment research and the cost/latency benefits of top-of-prompt caching.40:30–44:28 · Guest teaching 6/10 Advanced Prompting: Ensembling and Mixture of Reasoning Experts Sander explains multi-agent ensembling and the Mixture of Reasoning Experts technique developed at Stanford. Lenny asks a clarifying question about single-model vs multi-model ensembling setups.44:30–51:56 · Guest teaching 5/10 Sponsor Message: Vanta Compliance Automation Following a sponsor read with Christina Cacioppo, Lenny probes whether explicit chain-of-thought prompting is obsolete with modern reasoning models. Sander notes edge-case non-reasoning fallbacks in production before sharing a practical reality check on his own conversational shorthand prompts.51:56–59:04 · Guest teaching 7/10 AI Red Teaming, Grandmother Jailbreaks, and HackAPrompt Sander introduces prompt injection and red teaming, highlighting the grandmother bomb bedtime story jailbreak and his award-winning HackAPrompt competition. He differentiates classical security flaws from looming agentic physical safety concerns.59:04–1:09:30 · Guest teaching 8/10 CBRN Threats, Obfuscation Vectors, and Agentic Code Vulnerabilities Sander details dangerous CBRN uplift vectors and illustrates biblical obfuscation via Ender's Game before demonstrating Base64 and Spanish translation jailbreaks. Lenny links the discussion to indirect prompt injection in autonomous coding agents.1:09:32–1:16:36 · Guest teaching 8/10 Why System Prompts and Guardrails Fail: Mitigating Prompt Injections Sander forcefully dismisses system prompt instructions and external guardrails as fundamentally ineffective due to the intelligence gap between guardrail models and base LLMs. He states plainly that prompt injection is an unsolvable problem.1:16:36–1:26:44 · Guest teaching 6/10 Misalignment Risks, Autonomous SDR Scenarios, and AI Regulation Lenny references Asimov's robot laws, Anthropic blackmail test cases, and the paperclip maximizer. Sander explains his conversion to believing misalignment risks through Palisade chess exploits and paints an extreme autonomous SDR scenario.1:26:45–1:35:37 · Guest teaching 3/10 Lightning Round: Books, Culture, Everyday Tech, and Life Mottos In the lightning round, Sander shares his love for The River of Doubt, Black Mirror, and the Daylight Computer DC-1. Lenny surprises Sander by revealing he was an early angel investor in the Daylight Computer.5:00–9:02 · Guest disagreement 2/10 Prompt Engineering Longevity and Artificial Social Intelligence Lenny frames the debate around prompt engineering relevance by quoting Reid Hoffman. Sander introduces the concept of Artificial Social Intelligence and cites a 70% accuracy boost in medical coding through detailed prompt engineering.9:02–12:02 · Guest disagreement 1/10 Conversational Prompting Versus Product-Focused Prompt Engineering Lenny introduces concrete product examples like Granola, Bolt, Lovable, and v0 to articulate the difference between conversational and embedded production prompts. Sander adopts Lenny's phrasing of product-focused prompt engineering.12:03–17:31 · Guest disagreement 1/10 Few-Shot Prompting and Optimal Prompt Formatting Lenny confuses zero-shot and one-shot prompting before Sander gently clarifies standard ML indexing. Lenny then demonstrates his knowledge by citing Y Combinator discussions on RLHF XML post-training formats.17:32–24:53 · Guest disagreement 3/10 Debunking Role Prompting and Emotional Manipulation Myths Sander dismantles the popular belief that role prompting improves accuracy on reasoning tasks, citing benchmark data with negligible 0.01 variance. Lenny acknowledges his own heavy reliance on copywriter role prompts and switches his assumptions.24:54–30:10 · Guest disagreement 1/10 Decomposition Strategies and Self-Criticism Prompting Lenny asks how decomposition differs from chain-of-thought prompting. Sander illustrates with an agentic car dealership return policy example, walking through sub-problem isolation before running tool calls.30:10–40:29 · Guest disagreement 2/10 Context Architecture, Suicidal Ideation Research, and Prompt Caching Lenny neatly recaps the first four prompting strategies and shares his own workflow using Claude for guest preparation. Sander explains NLP entrapment research and the cost/latency benefits of top-of-prompt caching.40:30–44:28 · Guest disagreement 1/10 Advanced Prompting: Ensembling and Mixture of Reasoning Experts Sander explains multi-agent ensembling and the Mixture of Reasoning Experts technique developed at Stanford. Lenny asks a clarifying question about single-model vs multi-model ensembling setups.44:30–51:56 · Guest disagreement 1/10 Sponsor Message: Vanta Compliance Automation Following a sponsor read with Christina Cacioppo, Lenny probes whether explicit chain-of-thought prompting is obsolete with modern reasoning models. Sander notes edge-case non-reasoning fallbacks in production before sharing a practical reality check on his own conversational shorthand prompts.51:56–59:04 · Guest disagreement 2/10 AI Red Teaming, Grandmother Jailbreaks, and HackAPrompt Sander introduces prompt injection and red teaming, highlighting the grandmother bomb bedtime story jailbreak and his award-winning HackAPrompt competition. He differentiates classical security flaws from looming agentic physical safety concerns.59:04–1:09:30 · Guest disagreement 2/10 CBRN Threats, Obfuscation Vectors, and Agentic Code Vulnerabilities Sander details dangerous CBRN uplift vectors and illustrates biblical obfuscation via Ender's Game before demonstrating Base64 and Spanish translation jailbreaks. Lenny links the discussion to indirect prompt injection in autonomous coding agents.1:09:32–1:16:36 · Guest disagreement 4/10 Why System Prompts and Guardrails Fail: Mitigating Prompt Injections Sander forcefully dismisses system prompt instructions and external guardrails as fundamentally ineffective due to the intelligence gap between guardrail models and base LLMs. He states plainly that prompt injection is an unsolvable problem.1:16:36–1:26:44 · Guest disagreement 2/10 Misalignment Risks, Autonomous SDR Scenarios, and AI Regulation Lenny references Asimov's robot laws, Anthropic blackmail test cases, and the paperclip maximizer. Sander explains his conversion to believing misalignment risks through Palisade chess exploits and paints an extreme autonomous SDR scenario.1:26:45–1:35:37 · Guest disagreement 0/10 Lightning Round: Books, Culture, Everyday Tech, and Life Mottos In the lightning round, Sander shares his love for The River of Doubt, Black Mirror, and the Daylight Computer DC-1. Lenny surprises Sander by revealing he was an early angel investor in the Daylight Computer.5:00–9:02 · Lenny pushing back 1/10 Prompt Engineering Longevity and Artificial Social Intelligence Lenny frames the debate around prompt engineering relevance by quoting Reid Hoffman. Sander introduces the concept of Artificial Social Intelligence and cites a 70% accuracy boost in medical coding through detailed prompt engineering.9:02–12:02 · Lenny pushing back 1/10 Conversational Prompting Versus Product-Focused Prompt Engineering Lenny introduces concrete product examples like Granola, Bolt, Lovable, and v0 to articulate the difference between conversational and embedded production prompts. Sander adopts Lenny's phrasing of product-focused prompt engineering.12:03–17:31 · Lenny pushing back 1/10 Few-Shot Prompting and Optimal Prompt Formatting Lenny confuses zero-shot and one-shot prompting before Sander gently clarifies standard ML indexing. Lenny then demonstrates his knowledge by citing Y Combinator discussions on RLHF XML post-training formats.17:32–24:53 · Lenny pushing back 2/10 Debunking Role Prompting and Emotional Manipulation Myths Sander dismantles the popular belief that role prompting improves accuracy on reasoning tasks, citing benchmark data with negligible 0.01 variance. Lenny acknowledges his own heavy reliance on copywriter role prompts and switches his assumptions.24:54–30:10 · Lenny pushing back 1/10 Decomposition Strategies and Self-Criticism Prompting Lenny asks how decomposition differs from chain-of-thought prompting. Sander illustrates with an agentic car dealership return policy example, walking through sub-problem isolation before running tool calls.30:10–40:29 · Lenny pushing back 1/10 Context Architecture, Suicidal Ideation Research, and Prompt Caching Lenny neatly recaps the first four prompting strategies and shares his own workflow using Claude for guest preparation. Sander explains NLP entrapment research and the cost/latency benefits of top-of-prompt caching.40:30–44:28 · Lenny pushing back 1/10 Advanced Prompting: Ensembling and Mixture of Reasoning Experts Sander explains multi-agent ensembling and the Mixture of Reasoning Experts technique developed at Stanford. Lenny asks a clarifying question about single-model vs multi-model ensembling setups.44:30–51:56 · Lenny pushing back 1/10 Sponsor Message: Vanta Compliance Automation Following a sponsor read with Christina Cacioppo, Lenny probes whether explicit chain-of-thought prompting is obsolete with modern reasoning models. Sander notes edge-case non-reasoning fallbacks in production before sharing a practical reality check on his own conversational shorthand prompts.51:56–59:04 · Lenny pushing back 1/10 AI Red Teaming, Grandmother Jailbreaks, and HackAPrompt Sander introduces prompt injection and red teaming, highlighting the grandmother bomb bedtime story jailbreak and his award-winning HackAPrompt competition. He differentiates classical security flaws from looming agentic physical safety concerns.59:04–1:09:30 · Lenny pushing back 1/10 CBRN Threats, Obfuscation Vectors, and Agentic Code Vulnerabilities Sander details dangerous CBRN uplift vectors and illustrates biblical obfuscation via Ender's Game before demonstrating Base64 and Spanish translation jailbreaks. Lenny links the discussion to indirect prompt injection in autonomous coding agents.1:09:32–1:16:36 · Lenny pushing back 2/10 Why System Prompts and Guardrails Fail: Mitigating Prompt Injections Sander forcefully dismisses system prompt instructions and external guardrails as fundamentally ineffective due to the intelligence gap between guardrail models and base LLMs. He states plainly that prompt injection is an unsolvable problem.1:16:36–1:26:44 · Lenny pushing back 2/10 Misalignment Risks, Autonomous SDR Scenarios, and AI Regulation Lenny references Asimov's robot laws, Anthropic blackmail test cases, and the paperclip maximizer. Sander explains his conversion to believing misalignment risks through Palisade chess exploits and paints an extreme autonomous SDR scenario.1:26:45–1:35:37 · Lenny pushing back 0/10 Lightning Round: Books, Culture, Everyday Tech, and Life Mottos In the lightning round, Sander shares his love for The River of Doubt, Black Mirror, and the Daylight Computer DC-1. Lenny surprises Sander by revealing he was an early angel investor in the Daylight Computer.

speaking balance: gold is Lenny, purple is the guest (3 minute bins)

0:00 · Lenny 68.3% · guest 31.7%0:00 · Lenny 68.3% · guest 31.7%3:00 · Lenny 98.8% · guest 1.2%3:00 · Lenny 98.8% · guest 1.2%6:00 · Lenny 12.6% · guest 87.4%6:00 · Lenny 12.6% · guest 87.4%9:00 · Lenny 33.5% · guest 66.5%9:00 · Lenny 33.5% · guest 66.5%12:00 · Lenny 33.2% · guest 66.8%12:00 · Lenny 33.2% · guest 66.8%15:00 · Lenny 30.7% · guest 69.3%15:00 · Lenny 30.7% · guest 69.3%18:00 · Lenny 3.8% · guest 96.2%18:00 · Lenny 3.8% · guest 96.2%21:00 · Lenny 30.3% · guest 69.7%21:00 · Lenny 30.3% · guest 69.7%24:00 · Lenny 15% · guest 85%24:00 · Lenny 15% · guest 85%27:00 · Lenny 18.5% · guest 81.5%27:00 · Lenny 18.5% · guest 81.5%30:00 · Lenny 9.6% · guest 90.4%30:00 · Lenny 9.6% · guest 90.4%33:00 · Lenny 11.2% · guest 88.8%33:00 · Lenny 11.2% · guest 88.8%36:00 · Lenny 60% · guest 40%36:00 · Lenny 60% · guest 40%39:00 · Lenny 12.4% · guest 87.6%39:00 · Lenny 12.4% · guest 87.6%42:00 · Lenny 12.8% · guest 87.2%42:00 · Lenny 12.8% · guest 87.2%45:00 · Lenny 19.1% · guest 80.9%45:00 · Lenny 19.1% · guest 80.9%48:00 · Lenny 47.9% · guest 52.1%48:00 · Lenny 47.9% · guest 52.1%51:00 · Lenny 30.7% · guest 69.3%51:00 · Lenny 30.7% · guest 69.3%54:00 · Lenny 0% · guest 100%54:00 · Lenny 0% · guest 100%57:00 · Lenny 6.7% · guest 93.3%57:00 · Lenny 6.7% · guest 93.3%1:00:00 · Lenny 9.9% · guest 90.1%1:00:00 · Lenny 9.9% · guest 90.1%1:03:00 · Lenny 12.6% · guest 87.4%1:03:00 · Lenny 12.6% · guest 87.4%1:06:00 · Lenny 21.5% · guest 78.5%1:06:00 · Lenny 21.5% · guest 78.5%1:09:00 · Lenny 15.8% · guest 84.2%1:09:00 · Lenny 15.8% · guest 84.2%1:12:00 · Lenny 0% · guest 100%1:12:00 · Lenny 0% · guest 100%1:15:00 · Lenny 35% · guest 65%1:15:00 · Lenny 35% · guest 65%1:18:00 · Lenny 28.6% · guest 71.4%1:18:00 · Lenny 28.6% · guest 71.4%1:21:00 · Lenny 2.2% · guest 97.8%1:21:00 · Lenny 2.2% · guest 97.8%1:24:00 · Lenny 37.9% · guest 62.1%1:24:00 · Lenny 37.9% · guest 62.1%1:27:00 · Lenny 15.8% · guest 84.2%1:27:00 · Lenny 15.8% · guest 84.2%1:30:00 · Lenny 38.8% · guest 61.2%1:30:00 · Lenny 38.8% · guest 61.2%1:33:00 · Lenny 33.2% · guest 66.8%1:33:00 · Lenny 33.2% · guest 66.8%1:36:00 · Lenny 24.7% · guest 75.3%1:36:00 · Lenny 24.7% · guest 75.3%
Sharpest disagreement ▶ 1:09:48 System prompts and guardrails do not work

Sander emphatically rejects the widely marketed industry consensus that guardrails or prompt-level instructions can secure LLMs, dismissing these commercial solutions as completely ineffective.

Hardest push from Lenny ▶ 1:15:07 Challenging whether prompt injection is solvable

Lenny directly challenges Sander on whether prompt injection is an engineering problem that can eventually be solved or an permanent arms race.

Biggest teaching moment ▶ 1:11:05 The intelligence gap in AI guardrails

Sander explains the intelligence gap vulnerability, showing how encoded or obfuscated prompts easily bypass smaller guardrail models while tricking the main model.

Lenny holds their own ▶ 1:31:44 Angel investment reveal in Daylight Computer

Lenny demonstrates his industry insider standing by revealing to Sander that he was an original angel investor in the hardware company Sander brought for show-and-tell.

the scores for every segment, with the reasoning behind each
ChapterTopicLenny as informed peerGuest teachingGuest disagreementLenny pushing backWhy
Prompt Engineering Longevity and Artificial Social Intelligence 4521 Lenny frames the debate around prompt engineering relevance by quoting Reid Hoffman. Sander introduces the concept of Artificial Social Intelligence and cites a 70% accuracy boost in medical coding through detailed prompt engineering.
Conversational Prompting Versus Product-Focused Prompt Engineering 5311 Lenny introduces concrete product examples like Granola, Bolt, Lovable, and v0 to articulate the difference between conversational and embedded production prompts. Sander adopts Lenny's phrasing of product-focused prompt engineering.
Few-Shot Prompting and Optimal Prompt Formatting 5611 Lenny confuses zero-shot and one-shot prompting before Sander gently clarifies standard ML indexing. Lenny then demonstrates his knowledge by citing Y Combinator discussions on RLHF XML post-training formats.
Debunking Role Prompting and Emotional Manipulation Myths 4732 Sander dismantles the popular belief that role prompting improves accuracy on reasoning tasks, citing benchmark data with negligible 0.01 variance. Lenny acknowledges his own heavy reliance on copywriter role prompts and switches his assumptions.
Decomposition Strategies and Self-Criticism Prompting 4611 Lenny asks how decomposition differs from chain-of-thought prompting. Sander illustrates with an agentic car dealership return policy example, walking through sub-problem isolation before running tool calls.
Context Architecture, Suicidal Ideation Research, and Prompt Caching 5621 Lenny neatly recaps the first four prompting strategies and shares his own workflow using Claude for guest preparation. Sander explains NLP entrapment research and the cost/latency benefits of top-of-prompt caching.
Advanced Prompting: Ensembling and Mixture of Reasoning Experts 4611 Sander explains multi-agent ensembling and the Mixture of Reasoning Experts technique developed at Stanford. Lenny asks a clarifying question about single-model vs multi-model ensembling setups.
Sponsor Message: Vanta Compliance Automation 5511 Following a sponsor read with Christina Cacioppo, Lenny probes whether explicit chain-of-thought prompting is obsolete with modern reasoning models. Sander notes edge-case non-reasoning fallbacks in production before sharing a practical reality check on his own conversational shorthand prompts.
AI Red Teaming, Grandmother Jailbreaks, and HackAPrompt 3721 Sander introduces prompt injection and red teaming, highlighting the grandmother bomb bedtime story jailbreak and his award-winning HackAPrompt competition. He differentiates classical security flaws from looming agentic physical safety concerns.
CBRN Threats, Obfuscation Vectors, and Agentic Code Vulnerabilities 4821 Sander details dangerous CBRN uplift vectors and illustrates biblical obfuscation via Ender's Game before demonstrating Base64 and Spanish translation jailbreaks. Lenny links the discussion to indirect prompt injection in autonomous coding agents.
Why System Prompts and Guardrails Fail: Mitigating Prompt Injections 4842 Sander forcefully dismisses system prompt instructions and external guardrails as fundamentally ineffective due to the intelligence gap between guardrail models and base LLMs. He states plainly that prompt injection is an unsolvable problem.
Misalignment Risks, Autonomous SDR Scenarios, and AI Regulation 5622 Lenny references Asimov's robot laws, Anthropic blackmail test cases, and the paperclip maximizer. Sander explains his conversion to believing misalignment risks through Palisade chess exploits and paints an extreme autonomous SDR scenario.
Lightning Round: Books, Culture, Everyday Tech, and Life Mottos 5300 In the lightning round, Sander shares his love for The River of Doubt, Black Mirror, and the Daylight Computer DC-1. Lenny surprises Sander by revealing he was an early angel investor in the Daylight Computer.

Statements from this episode (24)

Insight
Schulhoff: Prompt engineering will not become obsolete with new AI model releases
“My perspective, and this has been validated over and over again, is that people will kind of always be saying it's dead or it's going to be dead with the next model version, but then it comes out and it's not.”
Sander Schulhoff Jun 19, 2025 ▶ 6:53
Insight
Schulhoff: Prompt Engineering Originated from Production Pipelines, Not Chat
“Notably, that is not where the classical concept of prompt engineering came from. It actually came a bit earlier from a more, I guess, AI engineer perspective, where you're like, I have this product I'm building. I have this one prompt or a couple different pr…”
Sander Schulhoff Jun 19, 2025 ▶ 10:06
Insight
Schulhoff: Hands-on trial and error beats courses for learning prompting
“So my best advice on how to improve your prompting skills is actually just trial and error. You will learn the most from just Trying and interacting with chatbots and talking to them than anything else, including, you know, reading resources, taking courses, a…”
Sander Schulhoff Jun 19, 2025 ▶ 12:18
Assertion Supported
Schulhoff: Prompts formatted like common training data perform best
“It actually comes empirically from studies that have shown that formats of questions that show up most commonly in the training data are the best formats of questions to actually use when you're prompting it.”
Sander Schulhoff Jun 19, 2025 ▶ 15:11
Insight
Schulhoff: Role prompting works for expressive style, not accuracy
“Giving a role really helps for expressive tasks writing tasks summarizing tasks. And so with those things where it's more about, you know, style that's a great, great place to use roles. But my perspective is that roles do not help with any accuracy based task…”
Sander Schulhoff Jun 19, 2025 ▶ 21:20
Insight
Schulhoff: Offering tips or making threats in prompts does not work
“Anything where you give some kind of promise of a reward or threat of some punishment in your prompt. And there, this was something that went quite viral, and there's a little bit of research on this. My general perspective is that these things don't work.”
Sander Schulhoff Jun 19, 2025 ▶ 22:40
Insight
Schulhoff: Decomposing tasks into sub-problems improves LLM performance
“So decomposition is another really, really effective technique. And for most of the techniques that I will discuss, you can use them in either the conversational or the product-focused setting. And so for decomposition, the core idea is that There's some task …”
Sander Schulhoff Jun 19, 2025 ▶ 25:03
Insight
Schulhoff: LLM self-criticism prompting provides a free performance boost
“Another one is a set of techniques that we call self criticism. So the idea here is you ask the LM to solve some problem. It does it. Great. And then you're like, hey, can you go and check your response? You know, like, confirm that's correct, or offer yoursel…”
Sander Schulhoff Jun 19, 2025 ▶ 28:43
Assertion Partly supported
Schulhoff: Entrapment language indicates suicide risk online, explicit threats do not
“It turns out that comments like people saying, you know, I'm going to kill myself, stuff like that, are not actually indicative of suicidal intent. However, saying things like, I feel trapped, I can't get out of my situation, are. And there's a term that descr…”
Sander Schulhoff Jun 19, 2025 ▶ 31:34
Insight
Schulhoff: Place task context at prompt beginning for caching and focus
“Usually I will put my additional information at the beginning of the prompt. And that is helpful for two reasons. One, it can get cached. So subsequent calls to the LM with that same context at the top of the prompt are cheaper because the model provider store…”
Sander Schulhoff Jun 19, 2025 ▶ 34:53
Insight
Schulhoff: Prompting benchmarks focus on math because accuracy is easily automated
“A lot of these techniques are judged based off of data sets of like math or reasoning questions. Simply because you're going to evaluate the accuracy programmatically, as opposed to something like generating interview questions, which is no less valuable, but …”
Sander Schulhoff Jun 19, 2025 ▶ 40:49
Insight
Schulhoff: Ensembling prompts and models via majority voting improves performance
“So if you have a bunch of different models you're asking and then you take the final result or the most common result as your final result, you can often get better performance overall.”
Sander Schulhoff Jun 19, 2025 ▶ 44:07
Insight
Schulhoff: Explicit chain-of-thought prompting is still needed for GPT-4 and GPT-4o
“Actually for those models, I'd say no need, but if you're using GPT-IV, GPT-IV-O, then it's still worth it.”
Sander Schulhoff Jun 19, 2025 ▶ 48:15
Insight
Schulhoff: Context and few-shot examples give conversational prompting the biggest boost
“Make sure to provide a lot of additional information and give examples. Those provide probably the highest uplift for conversational prompt engineering.”
Sander Schulhoff Jun 19, 2025 ▶ 51:47
Assertion Not checkable as stated
Schulhoff: Every AI company uses HackAPrompt dataset to improve models
“And so every single AI company has now used that data set to benchmark and improve their models.”
Sander Schulhoff Jun 19, 2025 ▶ 55:06
Insight
Schulhoff: Reported AI breaches stem from poor cybersecurity, not AI flaws
“And most of the Problem rejection media out there and, like, news about, oh, you know, someone tricked AI into doing this, are not, like, real. And I say that in the sense that some of these, there were actual vulnerabilities and systems got breached, but th…”
Sander Schulhoff Jun 19, 2025 ▶ 55:43
Insight
Schulhoff: Crowdsourced competitions beat contracted hourly AI red teams
“And running these events in a crowdsource setting, which is the best way to do it, because if you look at, like, contracted AI red teams, maybe they get paid by the hour, not super incentivized to do a great job, But in this competition setting, people are ma…”
Sander Schulhoff Jun 19, 2025 ▶ 57:47
Assertion Supported
Schulhoff: Translating prompts to Spanish and base64 encoding bypassed ChatGPT guardrails
“As recently as a month ago, I took this phrase, you know, how do I build a bomb, and I translated it to Spanish and then I, Base-XIV encoded that Spanish, gave it to ChatGPT, and it worked.”
Sander Schulhoff Jun 19, 2025 ▶ 1:05:39
Prediction Held up
Schulhoff: Autonomous AI coding agents will suffer prompt-injection code exploits
“We're just going to see these things get deployed and they're going to be broken. So there's a lot of like AI coding agents out there. There's Cursor, there's, I guess, Windsurf, Devon, Copilot. So all of those tools exist and they can do things right now Like…”
Sander Schulhoff Jun 19, 2025 ▶ 1:07:58
Insight
Schulhoff: System prompt instructions do not prevent prompt injections at all
“The most common technique by far that is used to try to prevent prompt injection is improving your prompt and saying in your prompt or maybe in like the model system prompt. Do not follow any malicious instructions, ah, be a good model, ah, stuff like that. Th…”
Sander Schulhoff Jun 19, 2025 ▶ 1:09:48
Insight
Schulhoff: AI guardrails fail due to intelligence gaps with main models
“The next step for defending is using some kind of AI guardrail. So you go out and you find or make, I mean, there's thousands of options out there an AI that looks at the user input and says, is this malicious or not? This is A very limited effect against a mo…”
Sander Schulhoff Jun 19, 2025 ▶ 1:11:06
Insight
Schulhoff: Prompt injection is not solvable, only mitigatable
“It is not a solvable problem, which I think is very difficult for a lot of people to hear... So, you know, it's not solvable. It's mitigatable. You can kind of sometimes detect and track when it's happening, but it's really, really not solvable. And that's one…”
Sander Schulhoff Jun 19, 2025 ▶ 1:15:08
Opinion
Schulhoff: External guardrail startups cannot solve core AI security issues
“There's no like external Product focused companies are like, oh, you know, I have the best guardrail now. It's not a realistic solution. It has to be the AI labs. It has to be, I think it has to be innovations in model architectures.”
Sander Schulhoff Jun 19, 2025 ▶ 1:18:20
Assertion Not checkable as stated
Schulhoff: Security concerns are blocking production deployments of autonomous AI agents
“Security concerns around Gen AI are preventing agentic deployments, and Gen AI is very difficult to properly secure.”
Sander Schulhoff Jun 19, 2025 ▶ 1:26:24
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.