In software security, a classic defense against injection is to prevent untrusted data from changing the syntax or meaning of an instruction executed by an interpreter. That boundary does not solve every attack class, but it does stop that data from becoming control through the same channel. In LLM systems, that separation is no longer sufficient because the system itself consumes instructions and data through the same medium: natural language.
That changes the risk surface structurally. A document retrieved by RAG, an observation written by another agent, a tool result or a note stored in memory can influence the model as if it were an instruction. Separating privileges, context and execution does not eliminate that influence; it limits which data and actions it can reach if the model follows it.
This series is not a catalogue of new AI security scares. Its goal is to separate mechanisms that are often conflated: which controls reduce the chance that untrusted content changes model behavior, and which controls limit the consequences—accessible data, tools and actions—even when that influence occurs.
Series map · one path, two outcomes
Injection changes a proposal; architecture decides whether it becomes an effect
Follow the same hostile content to an authorization decision outside the model. Change only the control and observe where the outcome diverges.
Compare
1Hostile contentemail · web · document · memory
2Enters the systemretrieval · reading · tool result
3Influences contextcompetes with legitimate instructions
4Changes the proposaltext · plan · tool call
5Authorization boundaryintent · scope · parameters · approvalcontrol outside the model