
If you're building or deploying AI agents — especially browser agents that read untrusted web content — this breaks down why off-the-shelf don't stop and what defense approaches actually hold up, from someone who ran the first large-scale prompt injection competition.
“You can patch a bug, but you can't patch a brain.”
Sander Schulhoff
“If someone is determined enough to trick GPT-5, they're gonna deal with that guardrail, no problem.”
Sander Schulhoff
“And we found that, first of all, humans break everything. 100% of the defenses in maybe like 10 to 30 attempts.”
Sander Schulhoff
“any data that AI has access to, the user can make it leak it. Any actions that it can possibly take, the user can make it take 'em.”
Sander Schulhoff
“the only reason there hasn't been a massive attack yet is how early the adoption is, not because it's secure.”
podcastThe 100-person AI lab that became Anthropic and Google's secret weapon | Edwin Chen (Surge AI)
podcastWhy humans are AI’s biggest bottleneck (and what’s coming in 2026) | Alexander Embiricos (OpenAI Codex Product Lead)
podcastWhy most AI products fail: Lessons from 50+ AI deployments at OpenAI, Google, and Amazon
podcastThe non-technical PM’s guide to building with Cursor | Zevi Arnovitz (Meta)
podcastAn AI state of the union: We’ve passed the inflection point, dark factories are coming, and automation timelines | Simon WillisonLenny Rachitsky
podcastThe 100-person AI lab that became Anthropic and Google's secret weapon | Edwin Chen (Surge AI)Lenny Rachitsky
podcast“Engineers are becoming sorcerers” | The future of software development with OpenAI’s Sherwin WuLenny RachitskyChecking sign-in…
Loading comments…