Tap a claim on the ring to put it at the centre.
← Prompt injection can be caught by watching the neurons that fire when…
17 connected korrents · 15 moments on record from 22 Mar 2025 to 4 Sept 2026.
Everything filed under prompt injection
prompt injection
Everything filed under scaling laws
scaling laws
Everything filed under documentation
documentation
Everything filed under AI agents
AI agents
Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject Same subject
Read this korrent: Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack.
Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack.
Last stated a month ago
27 Jul 2026
BC
Boris Cherny — holds since 2026-07-27 — tap for who they are
Same subject: Auto-mode does not yet convincingly fix prompt-injection risk for coding agents. — tap to centre the map on it
Auto-mode does not yet convincingly fix prompt-injection risk for coding agents.
Last stated 4 weeks ago
8 Aug 2026
SW
Simon Willison — holds since 2026-08-08 — tap for who they are
Same subject: Prompt injection has no equivalent of parameterized queries: there is no reliable way to tell a language model which text is data and which is instructions. — tap to centre the map on it
Prompt injection has no equivalent of parameterized queries: there is no reliable way to tell a language model which text is data and which is instructions.
Last stated 6 months ago
19 Mar 2026
SW
Simon Willison — holds since 2026-03-19 — tap for who they are
Same subject: Prompt injection is an extremely hard attack to defend against, and hardly anyone integrating AI is talking about it. — tap to centre the map on it
Prompt injection is an extremely hard attack to defend against, and hardly anyone integrating AI is talking about it.
Last stated a year ago
22 Mar 2025
TH
ThePrimeagen — holds since 2025-03-22 — tap for who they are
Same subject: Prompt injection is no longer a live attack on the frontier model: it simply does not follow instructions it reads on the internet any more. — tap to centre the map on it
Prompt injection is no longer a live attack on the frontier model: it simply does not follow instructions it reads on the internet any more.
Last stated a month ago
27 Jul 2026
BC
Boris Cherny — holds since 2026-07-27 — tap for who they are
Same subject: Prompt injection is unsolved, but the latest models are post-trained to resist it, so it takes far more than 'ignore all previous instructions' now. — tap to centre the map on it
Prompt injection is unsolved, but the latest models are post-trained to resist it, so it takes far more than 'ignore all previous instructions' now.
Last stated 7 months ago
12 Feb 2026
PS
Peter Steinberger — holds since 2026-02-12 — tap for who they are
Same subject: Current prompt-injection defenses for AI agents (such as auto mode) are now reliable enough that agents can practically be assumed safe from successful injection attacks. — tap to centre the map on it
Current prompt-injection defenses for AI agents (such as auto mode) are now reliable enough that agents can practically be assumed safe from successful injection attacks.
Last stated 3 days ago
4 Sept 2026
ZM
Zvi Mowshowitz — holds since 2026-09-04 — tap for who they are
Same subject: If whole categories of reward hack are undetectable by humans, then training against the hacks we do catch teaches models to cheat only where we cannot see. — tap to centre the map on it
If whole categories of reward hack are undetectable by humans, then training against the hacks we do catch teaches models to cheat only where we cannot see.
Last stated 4 weeks ago
11 Aug 2026
RG
Ryan Greenblatt — holds since 2026-08-11 — tap for who they are
Same subject: The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out. — tap to centre the map on it
The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out.
Last stated 6 months ago
19 Mar 2026
SW
Simon Willison — holds since 2026-03-19 — tap for who they are
Same subject: A design proposal should describe the feature as though it already existed — once as a tutorial and once as reference documentation. — tap to centre the map on it
A design proposal should describe the feature as though it already existed — once as a tutorial and once as reference documentation.
Last stated 4 months ago
20 May 2026
AR
Alice Ryhl — holds since 2026-05-20 — tap for who they are
Same subject: Examples in documentation should be compiled and run as tests, so that changing the code breaks the docs instead of quietly outdating them. — tap to centre the map on it
Examples in documentation should be compiled and run as tests, so that changing the code breaks the docs instead of quietly outdating them.
Last stated 4 months ago
20 May 2026
AR
Alice Ryhl — holds since 2026-05-20 — tap for who they are
Same subject: Good documentation is produced by effort, not by tooling that keeps code and docs together — tap to centre the map on it
Good documentation is produced by effort, not by tooling that keeps code and docs together
Last stated 8 months ago
18 Jan 2026
HH
Hamel Husain — holds since 2026-01-18 — tap for who they are
Same subject: A handful of AI agents is not a handful of colleagues, because agents agree with you constantly and colleagues tell you where you are wrong. — tap to centre the map on it
A handful of AI agents is not a handful of colleagues, because agents agree with you constantly and colleagues tell you where you are wrong.
Last stated 6 months ago
22 Mar 2026
NF
Nicole Forsgren — holds since 2026-03-22 — tap for who they are
Same subject: After pre-training, post-training and test-time scaling, the fourth scaling law is agentic: multiplying AI by spawning agents, and the whole loop scales on one thing, compute. — tap to centre the map on it
After pre-training, post-training and test-time scaling, the fourth scaling law is agentic: multiplying AI by spawning agents, and the whole loop scales on one thing, compute.
Last stated 6 months ago
23 Mar 2026
JH
Jensen Huang — holds since 2026-03-23 — tap for who they are
Same subject: Agent autonomy is a capability, not a product direction: what the person is actually trying to do decides whether more of it helps or ruins the thing. — tap to centre the map on it
Agent autonomy is a capability, not a product direction: what the person is actually trying to do decides whether more of it helps or ruins the thing.
Last stated 3 weeks ago
14 Aug 2026
SP
Sunil Pai — holds since 2026-08-14 — tap for who they are
Same subject: A benchmark result should be reported under a stated budget, or as a curve against test-time compute — never as a single number. — tap to centre the map on it
A benchmark result should be reported under a stated budget, or as a curve against test-time compute — never as a single number.
Last stated 2 months ago
26 Jun 2026
NB
Noam Brown — holds since 2026-06-26 — tap for who they are
Same subject: A lab should spend most of its compute on research rather than on building the next model, because research is where the tenfold yearly efficiency gains come from. — tap to centre the map on it
A lab should spend most of its compute on research rather than on building the next model, because research is where the tenfold yearly efficiency gains come from.
Last stated 6 months ago
13 Mar 2026
DP
Dylan Patel — holds since 2026-03-13 — tap for who they are
Same subject: AI model capability progress is not going to slow down soon — tap to centre the map on it
AI model capability progress is not going to slow down soon
Last stated 4 days ago
3 Sept 2026
AR
Armin Ronacher — holds since 2026-09-03 — tap for who they are
same subject or similar wording a cloud: claims about one subject, named for it bar: when it was last stated, on a scale from 2015 to today — full is today a face: someone on record holding the claim — tap it for who they are
At the centre
Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack.
Last stated 27 Jul 2026 · a month ago
Holds Boris Cherny
Read this korrent →
Same subject: prompt injection
Auto-mode does not yet convincingly fix prompt-injection risk for coding agents.
Last stated 8 Aug 2026 · 4 weeks ago
Holds Simon Willison
Same subject: prompt injection
Prompt injection has no equivalent of parameterized queries: there is no reliable way to tell a language model which text is data and which is instructions.
Last stated 19 Mar 2026 · 6 months ago
Holds Simon Willison
Same subject: prompt injection
Prompt injection is an extremely hard attack to defend against, and hardly anyone integrating AI is talking about it.
Last stated 22 Mar 2025 · a year ago
Holds TH ThePrimeagen
Same subject: prompt injection
Prompt injection is no longer a live attack on the frontier model: it simply does not follow instructions it reads on the internet any more.
Last stated 27 Jul 2026 · a month ago
Holds Boris Cherny
Same subject: prompt injection
Prompt injection is unsolved, but the latest models are post-trained to resist it, so it takes far more than 'ignore all previous instructions' now.
Last stated 12 Feb 2026 · 7 months ago
Holds Peter Steinberger
Similar wording
Current prompt-injection defenses for AI agents (such as auto mode) are now reliable enough that agents can practically be assumed safe from successful injection attacks.
Last stated 4 Sept 2026 · 3 days ago
Holds ZM Zvi Mowshowitz
Similar wording
If whole categories of reward hack are undetectable by humans, then training against the hacks we do catch teaches models to cheat only where we cannot see.
Last stated 11 Aug 2026 · 4 weeks ago
Holds RG Ryan Greenblatt
Similar wording
The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out.
Last stated 19 Mar 2026 · 6 months ago
Holds Simon Willison
Same subject: documentation
A design proposal should describe the feature as though it already existed — once as a tutorial and once as reference documentation.
Last stated 20 May 2026 · 4 months ago
Holds AR Alice Ryhl
Same subject: documentation
Examples in documentation should be compiled and run as tests, so that changing the code breaks the docs instead of quietly outdating them.
Last stated 20 May 2026 · 4 months ago
Holds AR Alice Ryhl
Same subject: documentation
Good documentation is produced by effort, not by tooling that keeps code and docs together
Last stated 18 Jan 2026 · 8 months ago
Holds HH Hamel Husain
Same subject: AI agents
A handful of AI agents is not a handful of colleagues, because agents agree with you constantly and colleagues tell you where you are wrong.
Last stated 22 Mar 2026 · 6 months ago
Holds NF Nicole Forsgren
Same subject: AI agents
After pre-training, post-training and test-time scaling, the fourth scaling law is agentic: multiplying AI by spawning agents, and the whole loop scales on one thing, compute.
Last stated 23 Mar 2026 · 6 months ago
Holds JH Jensen Huang
Same subject: AI agents
Agent autonomy is a capability, not a product direction: what the person is actually trying to do decides whether more of it helps or ruins the thing.
Last stated 14 Aug 2026 · 3 weeks ago
Holds Sunil Pai
Same subject: scaling laws
A benchmark result should be reported under a stated budget, or as a curve against test-time compute — never as a single number.
Last stated 26 Jun 2026 · 2 months ago
Holds NB Noam Brown
Same subject: scaling laws
A lab should spend most of its compute on research rather than on building the next model, because research is where the tenfold yearly efficiency gains come from.
Last stated 13 Mar 2026 · 6 months ago
Holds DP Dylan Patel
Same subject: scaling laws
AI model capability progress is not going to slow down soon
Last stated 3 Sept 2026 · 4 days ago
Holds Armin Ronacher