Fetching from the wire…
Public story · 2026-07-30 · high
MIT Technology Review traces the flaw to role tags, a labeling habit that became the security architecture behind modern LLMs.
Why now: MIT Technology Review covered the ICML paper's role-tag finding on July 30.
An ICML paper argues prompt injection can't be patched, because models infer who's speaking from writing style, not any secure signal, per MIT Technology Review's July 30 report. That's a problem for every agent harness that mixes retrieved web content with user instructions in one context window. The model has no reliable way to tell which text is giving the orders.
The paper, "Prompt Injection as Role Confusion," says the system, user, and assistant tags every chat API relies on were never a security boundary. They were a formatting trick. Somewhere along the way, that trick became the security architecture of modern LLMs, per the report.
The practical result: a webpage that says "ignore previous instructions" reads to the model just like a real instruction. Same style cues. Same inferred authority.
MIT Technology Review frames the fix as something that lives outside the model. It's a decision at the orchestration layer: what gets passed in, and how it's labeled.
I'm not convinced the impossibility framing is as absolute as the headline claims. But the accident part is real: role tags were never built as a security boundary, and no smarter model changes that. The fix that actually ships will separate retrieved text from instructions at the harness level, not teach the model to guess better.
Each link below shares sources, entities, or timing with this story.
Shared entities / Shared topic / Earlier coverage
Both cover LLMs, Prompt Injection, Role Confusion; overlapping topics (confusion, formatting, role); earlier LLMs coverage from 2026-03-16.
Both cover Prompt Injection, Role Confusion; overlapping topics (argu, confusion, injection, model, role); earlier Prompt Injection coverage from 2026-06-23.
Cisco partners with MIT Technology Review / Shared entity: MIT Technology Review / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Cisco partners with MIT Technology Review); both cover MIT Technology Review; reported by the same outlet (technologyreview.com).
Cisco partners with MIT Technology Review / Shared entity: July / Earlier coverage / Tension
Linked by a graph relationship (Cisco partners with MIT Technology Review); both cover July; earlier July coverage from 2026-07-13.
Shared entities / Same source domain / Earlier coverage
Both cover July, MIT Technology Review; reported by the same outlet (technologyreview.com); earlier July coverage from 2026-07-21.
Both cover July, MIT Technology Review; reported by the same outlet (technologyreview.com); earlier July coverage from 2026-07-01.
Both cover LLMs, MIT Technology Review; reported by the same outlet (technologyreview.com); earlier LLMs coverage from 2026-05-01.
Shared entity: LLMs / Shared topic / Earlier coverage / Tension
Both cover LLMs; overlapping topics (claim, correct, model); earlier LLMs coverage from 2026-06-09.