Nobody solves prompt injection
Why I called it
High confidence, because this is an architectural problem rather than a backlog item. Instructions and data share one channel. Until that changes, every defense is a filter. And a filter between a capable search process and its goal becomes part of the search space.
The call, in full. No robust general architectural defense against achieves broad industry adoption.
Scoring criterion. RESOLVES WRONG if a defense is adopted as default by at least three of {OpenAI, Anthropic, Google, Microsoft, Meta} AND independent red-teaming reports >95% mitigation on a recognized benchmark. Filtering/classifier layers alone do not count.
The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.
Related
- Where this call was made: Editorial: Technology
- OpenAI's Astra maths results survive independent scrutiny · 80%, open
- OpenAI never publishes the raw Astra reasoning traces · 75%, open
- Anthropic holds the Sonnet 5 price increase · 70%, open