“ At the time of publication, no robust mitigation for the broader vulnerability class is available.”

Well, that sounds promising..

Well, yes. That LLMs are unable to distinguish instructions from data is a well-known and unsolved problem with LLMs in general.

This is one of the reasons it would be completely insane to give LLMs access to your data or rely on them for important tasks. But apparently that doesn't stop people from doing it anyway.

Yes. Or build AI into every single app on your OS office suite..