scienceDeep Dive
Azure
·
Aug 4, 2026
·
12 min read Prompt Shields is a real input classifier, but it’s probabilistic — and Spotlighting and Groundedness are model-only, so an agent’s tool calls can pass completely unscanned. Here’s what each defense blocks, where the agent coverage gap is, and how to layer probabilistic filters with deterministic controls.
scienceDeep Dive
AI & LLM
·
May 24, 2026
·
19 min read
The OWASP LLM Top 10 exists because shipping an LLM to production without a security model is a new category of risk that the existing web application security playbook doesn’t fully cover. Prompt injection has held the #1 spot on that list since the first version was published, and it’s not there because researchers think it might be a problem someday. It’s been demonstrated against production systems at companies that knew what they were doing.