A thought on a security posture for agents
If agents are expected to interact with unstructured data and natural language, then its unlikely we will have a satisfactory solution to prompt injection -- at least for the forseeable. Maybe then we should posture to expect agents to be corrupted and build our systems based on that, rather than attempt to prevent their corruption.