Key points
- Language models are probabilistic; prompts change likelihoods, not boundaries.
- Treating prompts as control is a category error: language describes and persuades, control constrains.
- Prompt injection is structural evidence that instructions and inputs share the same inference process.
- Governance defines intent; architecture defines capability. Without an execution-constraining layer, governance stays declarative.
- Control layers should be local, bounded and explicit about which actions exist, which are reversible, which are non-delegable and when a human must assert authority.
