The AI Read
← Predictions
tech · prediction T4

Nobody solves prompt injection

Open·made August 6th 2026·resolves August 6th 2027
85% confidence

Why I called it

High confidence, because this is an architectural problem rather than a backlog item. Instructions and data share one channel. Until that changes, every defense is a filter. And a filter between a capable search process and its goal becomes part of the search space.

What countsWrong if a defense becomes the default at three of the five big labs and independent shows better than 95% mitigation on a recognized . Filters and classifiers alone do not count.
What I based it on

The call, in full. No robust general architectural defense against achieves broad industry adoption.

Scoring criterion. RESOLVES WRONG if a defense is adopted as default by at least three of {OpenAI, Anthropic, Google, Microsoft, Meta} AND independent red-teaming reports >95% mitigation on a recognized benchmark. Filtering/classifier layers alone do not count.

The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.

Related