The Lethal Trifecta for AI Agents Private Data, Untrusted Content, and External Communication
Source: simonwillison.net
Plenty of vendors will sell you โguardrailโ products that claim to be able to detect and prevent these attacks. I am deeply suspicious of these: If you look closely theyโll almost always carry confident claims that they capture โ95% of attacksโ or similar... but in web application security 95% is very much a failing grade.
Read The Lethal Trifecta for AI Agents Private Data, Untrusted Content, and External Communication