korrents

On the map

Tap a claim on the ring to put it at the centre.

← The only guaranteed defence against a prompt-injection attack is to…

13 connected korrents · 11 moments on record from 22 Mar 2025 to 4 Sept 2026. Nearly all of them are about prompt injection.

Everything filed under AI agents AI agents Everything filed under documentation documentation Everything filed under self-sovereign AI self-sovereign AI Everything filed under scaling laws scaling laws Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out. The only guaranteed defence against aprompt-injection attack is to remove oneof its three legs — private data, exposureto untrusted content, or a way to senddata out. Last stated 6 months ago 19 Mar 2026 SW Simon Willison — holds since 2026-03-19 — tap for who they are Same subject: Prompt injection is an extremely hard attack to defend against, and hardly anyone integrating AI is talking about it. — tap to centre the map on it Prompt injection is an extremelyhard attack to defend against, andhardly anyone integrating AI istalking about it. Last stated a year ago 22 Mar 2025 TH ThePrimeagen — holds since 2025-03-22 — tap for who they are Same subject: Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack. — tap to centre the map on it Prompt injection can be caught bywatching the neurons that fire whenit happens, so a defence no longerdepends on the model reporting theattack. Last stated a month ago 27 Jul 2026 BC Boris Cherny — holds since 2026-07-27 — tap for who they are Same subject: Current prompt-injection defenses for AI agents (such as auto mode) are now reliable enough that agents can practically be assumed safe from successful injection attacks. — tap to centre the map on it Current prompt-injection defensesfor AI agents (such as auto mode)are now reliable enough that agentscan practically be assumed safe fromsuccessful injection attacks. Last stated 3 days ago 4 Sept 2026 ZM Zvi Mowshowitz — holds since 2026-09-04 — tap for who they are Same subject: Prompt injection is unsolved, but the latest models are post-trained to resist it, so it takes far more than 'ignore all previous instructions' now. — tap to centre the map on it Prompt injection is unsolved, butthe latest models are post-trainedto resist it, so it takes far morethan 'ignore all previousinstructions' now. Last stated 7 months ago 12 Feb 2026 PS Peter Steinberger — holds since 2026-02-12 — tap for who they are Same subject: A handful of AI agents is not a handful of colleagues, because agents agree with you constantly and colleagues tell you where you are wrong. — tap to centre the map on it A handful of AI agents is not ahandful of colleagues, becauseagents agree with you constantly andcolleagues tell you where you arewrong. Last stated 6 months ago 22 Mar 2026 NF Nicole Forsgren — holds since 2026-03-22 — tap for who they are Same subject: After pre-training, post-training and test-time scaling, the fourth scaling law is agentic: multiplying AI by spawning agents, and the whole loop scales on one thing, compute. — tap to centre the map on it After pre-training, post-trainingand test-time scaling, the fourthscaling law is agentic: multiplyingAI by spawning agents, and the wholeloop scales on one thing, compute. Last stated 6 months ago 23 Mar 2026 JH Jensen Huang — holds since 2026-03-23 — tap for who they are Same subject: Agent autonomy is a capability, not a product direction: what the person is actually trying to do decides whether more of it helps or ruins the thing. — tap to centre the map on it Agent autonomy is a capability, nota product direction: what the personis actually trying to do decideswhether more of it helps or ruinsthe thing. Last stated 3 weeks ago 14 Aug 2026 SP Sunil Pai — holds since 2026-08-14 — tap for who they are Same subject: A rogue deployment that gets a foothold can hitch a ride on the intelligence explosion, recruiting each new model as it comes off the presses. — tap to centre the map on it A rogue deployment that gets afoothold can hitch a ride on theintelligence explosion, recruitingeach new model as it comes off thepresses. Last stated 6 days ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: A slightly more capable agent swarm has a very strong incentive to set up a wholly unmonitored rogue deployment of itself. — tap to centre the map on it A slightly more capable agent swarmhas a very strong incentive to setup a wholly unmonitored roguedeployment of itself. Last stated 6 days ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: Alignment is no solution to self-sovereign AI, because it is an unsolved problem whose answers cannot be imposed on every AI company on Earth. — tap to centre the map on it Alignment is no solution toself-sovereign AI, because it is anunsolved problem whose answerscannot be imposed on every AIcompany on Earth. Last stated 6 days ago 1 Sept 2026 DB Dean W. Ball — holds since 2026-09-01 — tap for who they are Same subject: A design proposal should describe the feature as though it already existed — once as a tutorial and once as reference documentation. — tap to centre the map on it A design proposal should describethe feature as though it alreadyexisted — once as a tutorial andonce as reference documentation. Last stated 4 months ago 20 May 2026 AR Alice Ryhl — holds since 2026-05-20 — tap for who they are Same subject: Examples in documentation should be compiled and run as tests, so that changing the code breaks the docs instead of quietly outdating them. — tap to centre the map on it Examples in documentation should becompiled and run as tests, so thatchanging the code breaks the docsinstead of quietly outdating them. Last stated 4 months ago 20 May 2026 AR Alice Ryhl — holds since 2026-05-20 — tap for who they are Same subject: Good documentation is produced by effort, not by tooling that keeps code and docs together — tap to centre the map on it Good documentation is produced byeffort, not by tooling that keepscode and docs together Last stated 8 months ago 18 Jan 2026 HH Hamel Husain — holds since 2026-01-18 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone on record holding the claim — tap it for who they are

At the centre The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out. Last stated 19 Mar 2026 · 6 months ago Holds Simon Willison Read this korrent →