AI Security
The Attack Surface That Reads
A language model has one input channel and no way to mark part of it inert. Everything it reads is a candidate instruction, which moves the defensible boundary off the prompt entirely and onto the authority behind every action the system is allowed to take.