Fetching from the wire…
Skills2026-06-07 · source-backed
Run a Privileged LLM that controls tools and a separate Quarantined LLM that processes untrusted content with no tool access and no persistent state, returning only typed, labeled data over an inspectable channel. A capability-based interpreter enforces policy outside the model. On AgentDojo this structural separation mitigated 67% of prompt-injection attacks, far better than instruction-based defenses any clever payload overrides. Source: SSOJet
Each link below shares sources, entities, or timing with this story.
Simon Willison released LLM / Shared entity: LLM / What happened next / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-08-16.
LLM uses OpenAI / Shared entity: LLM / What happened next / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; picks up the LLM thread on 2026-07-27.
LLM uses OpenAI / Shared topic / Tension
Linked by a graph relationship (LLM uses OpenAI); overlapping topics (access, attack, data, tool); pushes against this story (against).
Simon Willison released LLM / Shared entity: LLM / What happened next / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-06-18.
LLM uses OpenAI / Shared entity: LLM / What happened next
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; picks up the LLM thread on 2026-08-21.
Simon Willison released LLM / Shared entity: LLM / What happened next
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-08-17.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-08-12.