A fundamental flaw leaves LLMs strikingly vulnerable to attack

MIT Technology Review – AI(Global) 30 Jul 2026 68

A structural vulnerability in how all LLMs parse input roles undermines a core assumption behind current AI safety training - relevant to any agency deploying LLM-based tools.

  • LLMs identify text roles by style and content, not tags - making role-spoofing attacks structurally reliable.
  • Researchers argue this is a fundamental flaw, meaning training-based defences cannot fully eliminate the vulnerability.
  • Agencies deploying LLMs with agentic or tool-use features - including document ingestion - face elevated prompt-injection risk.
  • Consider Agencies using or procuring LLM tools that ingest external documents, web content, or multi-agent outputs could consider reassessing prompt-injection risk assumptions in their current risk assessments.
  • Monitor AI governance and security teams may want to monitor follow-on research and vendor responses to understand whether mitigations emerge or the vulnerability is confirmed at scale.

Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.

View original source