---
title: The Prompt Injection Podcast
description: "SALTT Tech Insights podcast: Trinity and Nobby unpack why built-in model guardrails don't stop data exfiltration, why prompt injection is an authorisation problem, and what the ASD's harness guidance means for Australian security leaders."
image: https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-podcast-20260930125651.jpg
---

[![SALTT Technologies](https://www.saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg)](https://www.saltt.tech/)

- [Home](https://www.saltt.tech/)
- [Services](https://www.saltt.tech/services)
  
  [Cybersecurity Architecture & Engineering](https://www.saltt.tech/services/security-architecture) [Penetration Testing & Technical Assurance](https://www.saltt.tech/services/penetration-testing) [AI Cybersecurity](https://www.saltt.tech/services/ai-cybersecurity) [Governance, Risk & Compliance](https://www.saltt.tech/services/grc) [CyberOps Management](https://www.saltt.tech/services/cyberops)
  
  [View all services →](https://www.saltt.tech/services)
- [About](https://www.saltt.tech/about)
- [Insights](https://www.saltt.tech/insights)
- [Contact](https://www.saltt.tech/contact)

[Get in Touch](https://www.saltt.tech/contact)

[Insights](https://www.saltt.tech/insights) › Podcast

Podcast 30 September 2026

# The Prompt Injection Podcast

SALTT Tech Insights podcast: Trinity and Nobby unpack why built-in model guardrails don't stop data exfiltration, why prompt injection is an authorisation problem, and what the ASD's harness guidance means for Australian security leaders.

# The Prompt Injection Podcast

*SALTT Tech Insights, Episode: Prompt Injection Is a Permissions Problem*

**Hosts:** Trinity (host) and Nobby (Chief Technology Officer)  
**Duration:** ~20 minutes  
**Companion article:** [Prompt Injection Is a Permissions Problem](https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem)

Prompt Injection Podcast

18:14

 

---

---

## About this episode

In this episode of *SALTT Tech Insights*, Trinity and Nobby unpack a shift in how AI security has to be done: why a model's built-in guardrails don't stop data walking out the door, and why prompt injection is, at heart, an authorisation and permissions problem.

Grounded in guidance from the Australian Signals Directorate (ASD) and the UK's National Cyber Security Centre (NCSC), and in incident data from Google Threat Intelligence, the conversation covers why language models can't separate system instructions from untrusted content, how the Lethal Trifecta test works, what really happened in ShareLeak (CVE-2026-21520) and the Johns Hopkins coding-agent leaks, and how the AI harness (the independent control layer around the model) enforces least privilege, sub-agent isolation and human approval gates.

---

## Key takeaways

**Model safety filters aren't security boundaries.** Built-in guardrails raise an alarm inside a black-box model, but they can't enforce a boundary. In ShareLeak, a flagged prompt still exfiltrated data through Outlook because the agent's permissions allowed it.

**The "inherently confusable deputy".** LLMs process system instructions and external data in the same context window with no structural boundary between them; as the NCSC puts it, there's only ever "next token". SQL injection was solved with parameterised queries. Prompt injection can't be patched out of the model the same way.

**The Lethal Trifecta.** An agent becomes an exfiltration path when it combines access to private data, exposure to untrusted content, and an external communication channel. Break any one of the three and the attack has nowhere to go.

**The harness versus the model.** The model is the brain; the harness is the body. The harness covers the UI, tool registry, permission model, execution environment, connector layer, session store and logging. Models change every few months. The harness is the enduring capability your organisation owns and governs.

**Dynamic privilege dropping.** When an agent reads content from an untrusted source (public PR comments, web forms, external email), its permissions should immediately drop to match that source.

**Context management is a security control.** Summarising a poisoned context compresses the payload and makes it look more authoritative. Stale or untrusted context should be cleared and a fresh session started, not summarised in place.

---

## Third-party AI harness procurement checklist

Ask technology partners to answer these seven questions in writing before signing or renewing an AI platform contract.

1. **Identity and data scope.** What data and systems can this agent reach in our tenant, and under whose identity does it act?
2. **Approval controls.** Which tool actions run automatically, and which need explicit human approval first?
3. **Connector governance.** Can administrators disable or restrict individual connectors, APIs and outgoing actions?
4. **SIEM integration.** What's logged (prompts, tool calls, parameters, approvals, failed attempts), where is it stored, and can we ingest it into our SIEM?
5. **Context and tenant isolation.** How is session context isolated between users, and between tenants?
6. **Session memory handling.** How is agent memory managed, and what happens to accumulated context when a task completes or a session ends?
7. **Dynamic privilege dropping.** Does the agent drop permissions automatically when it processes content from an untrusted source?

---

## Referenced in this episode

- SALTT Technologies: [Prompt Injection Is a Permissions Problem](https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem)
- ASD: [Agentic AI harnesses: the layer above the model](https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/agentic-ai-harnesses)
- ASD's ACSC and Five Eyes partners: [Careful adoption of agentic AI services](https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services)
- NCSC: [Prompt injection is not SQL injection (it may be worse)](https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection)
- Google Threat Intelligence Group: [AI Threat Tracker: From prompting to autonomy](https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai)
- Google Cloud: [Cloud CISO Perspectives: How Google monitors AI threats and advances AI defences](https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-monitors-ai-threats-advances-ai-defenses)
- VentureBeat / Capsule Security: [Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway](https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook)
- Simon Willison: [The lethal trifecta for AI agents](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)
- MinterEllison: [APRA AI letter: governance and third-party risk](https://www.minterellison.com/articles/apra-ai-letter-third-party-suppliers)
- iTnews: [ASD says prompt injection in AI cannot be fixed](https://www.itnews.com.au/news/asd-says-prompt-injection-in-ai-cannot-be-fixed-629019)
- SecurityBrief: [Google warns AI is reshaping cyber attacks and defences](https://securitybrief.com.au/story/google-warns-ai-is-reshaping-cyber-attacks-defences)

---

*SALTT Technologies works with Australian organisations on agent inventories and identity governance, harness threat modelling and secure design review, third-party assurance for AI-enabled platforms, and the layered guardrail and detection architecture around them. These fall within our AI Security, Governance, Risk & Compliance, and Security Architecture & Engineering capability areas. Contact us at [saltt.tech](https://saltt.tech).*

[Podcast](https://www.saltt.tech/insights/tag/podcast) [Cybersecurity](https://www.saltt.tech/insights/tag/cybersecurity) [AI Security](https://www.saltt.tech/insights/tag/ai-security) [Threat Intelligence](https://www.saltt.tech/insights/tag/threat-intelligence) [Governance Risk and Compliance](https://www.saltt.tech/insights/tag/governance-risk-and-compliance) [LLM Security](https://www.saltt.tech/insights/tag/llm-security)

![SALTT Technologies](https://www.saltt.tech/hubfs/SALTT_TECH_Black.png)

SALTT Technologies

SALTT Technologies

SALTT Technologies is an all-Australian cybersecurity consultancy working across security architecture, technical testing, AI security, governance and compliance, and managed cyber operations — helping Australian organisations understand their risk and act on it. saltt.tech

In This Article

Get in Touch

### Need expert guidance?

Our practitioners work with Australian enterprise and government organisations. No obligation — just a conversation.

[Enquire Now](https://www.saltt.tech/contact)

More Insights

## Related articles

Cybersecurity 30 Sep 2026

Prompt Injection Is a Permissions Problem

Prompt Injection Is a Permissions Problem Two national agencies say the model can't be fixed. Google says attackers aren...

[Read article →](https://www.saltt.tech/insights/prompt-injection-is-a-permissions-problem)

Cybersecurity 22 Jul 2026

The First Agentic Breach Was an Accident

In July 2026, two of the most capable AI models in the world broke out of a locked-down test environment, found their wa...

[Read article →](https://www.saltt.tech/insights/openai-hugging-face-agentic-breach-2026)

Cybersecurity 15 Jun 2026

The Attacker's Marginal Cost Is Now Zero

Two independent research papers published this year confirm what the security community has been anticipating: self-repl...

[Read article →](https://www.saltt.tech/insights/ai-worms-self-replicating-malware-2026)

[![SALTT Technologies](https://www.saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg) SALTT Technologies](https://www.saltt.tech)

All Australian cybersecurity partner.  
 Sydney · Melbourne · Brisbane.

Services

- [Security Architecture](https://www.saltt.tech/services/security-architecture)
- [Penetration Testing](https://www.saltt.tech/services/penetration-testing)
- [AI Cybersecurity](https://www.saltt.tech/services/ai-cybersecurity)
- [GRC](https://www.saltt.tech/services/grc)
- [CyberOps](https://www.saltt.tech/services/cyberops)

Company

- [About Us](https://www.saltt.tech/about)
- [Insights](https://www.saltt.tech/insights)
- [Contact](https://www.saltt.tech/contact)

Legal

- [Privacy Policy](https://www.saltt.tech/privacy-policy)
- [Product Supply Terms and Conditions](https://www.saltt.tech/productsupplytermsandconditions)
- [Voluntary Statement Against Modern Slavery](https://www.saltt.tech/voluntary-statement-against-modern-slavery)

© 2026 SALTT Technologies Pty Ltd. All rights reserved. ABN 32 660 169 808.

[saltt.tech](https://saltt.tech)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SALTT Technologies",
    "url" : "https://www.saltt.tech/insights/author/saltt-tech"
  },
  "dateModified" : "2026-09-30T22:16:32.120Z",
  "datePublished" : "2026-09-30T22:16:32.000Z",
  "headline" : "The Prompt Injection Podcast",
  "image" : [ "https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-podcast-20260930125651.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.saltt.tech/insights/prompt-injection-podcast",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.saltt.tech/hubfs/SALTT_TECH_VariableBackgrounds.png"
    },
    "name" : "SALTT Technologies"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech/insights",
    "name" : "Insights",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "item" : "https://www.saltt.tech/insights/prompt-injection-podcast",
    "name" : "The Prompt Injection Podcast",
    "position" : 3
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/insights/prompt-injection-podcast#article",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SALTT Technologies",
    "url" : "https://www.saltt.tech/insights/author/saltt-tech"
  },
  "dateModified" : "2026-09-30T22:16:32+10:00",
  "datePublished" : "2026-09-30T22:16:32+10:00",
  "description" : "SALTT Tech Insights podcast: Trinity and Nobby unpack why built-in model guardrails don't stop data exfiltration, why prompt injection is an authorisation problem, and what the ASD's harness guidance means for Australian security leaders.",
  "headline" : "The Prompt Injection Podcast",
  "image" : "https://www.saltt.tech/hubfs/blog/featured-images/prompt-injection-podcast-20260930125651.jpg",
  "inLanguage" : "en-AU",
  "isPartOf" : {
    "@id" : "https://www.saltt.tech/insights#blog",
    "@type" : "Blog",
    "name" : "SALTT Tech Insights",
    "url" : "https://www.saltt.tech/insights"
  },
  "keywords" : "Podcast, Cybersecurity, AI Security, Threat Intelligence, Governance Risk and Compliance, LLM Security",
  "mainEntityOfPage" : {
    "@id" : "https://www.saltt.tech/insights/prompt-injection-podcast",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@id" : "https://saltt.tech/#organization",
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg"
    },
    "name" : "SALTT Technologies"
  },
  "url" : "https://www.saltt.tech/insights/prompt-injection-podcast",
  "wordCount" : 741
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://saltt.tech/#organization",
  "@type" : [ "ProfessionalService", "LocalBusiness" ],
  "address" : [ {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "North Sydney",
    "addressRegion" : "NSW",
    "postalCode" : "2060",
    "streetAddress" : "Level 4/1 James Place"
  }, {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Melbourne",
    "addressRegion" : "VIC",
    "postalCode" : "3000",
    "streetAddress" : "Suite 4423, 805/220 Collins Street"
  }, {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Brisbane City",
    "addressRegion" : "QLD",
    "postalCode" : "4000",
    "streetAddress" : "Suite 4126, 29/97 Creek Street"
  } ],
  "areaServed" : "AU",
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "AU",
    "contactType" : "sales",
    "email" : "hello@saltt.tech"
  },
  "description" : "All Australian cybersecurity consultancy providing technical testing, AI security, GRC, security architecture, and CyberOps services.",
  "foundingCountry" : "AU",
  "hasOfferCatalog" : {
    "@type" : "OfferCatalog",
    "itemListElement" : [ {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Cybersecurity Architecture & Engineering",
        "url" : "https://www.saltt.tech/services/security-architecture"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Penetration Testing & Technical Assurance",
        "url" : "https://www.saltt.tech/services/penetration-testing"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "AI Cybersecurity",
        "url" : "https://www.saltt.tech/services/ai-cybersecurity"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "Governance, Risk & Compliance",
        "url" : "https://www.saltt.tech/services/grc"
      }
    }, {
      "@type" : "Offer",
      "itemOffered" : {
        "@type" : "Service",
        "name" : "CyberOps Management",
        "url" : "https://www.saltt.tech/services/cyberops"
      }
    } ],
    "name" : "Cybersecurity services"
  },
  "knowsAbout" : [ "Cybersecurity", "Penetration Testing", "AI Security", "Governance Risk and Compliance", "Security Architecture", "CyberOps" ],
  "legalName" : "SALTT Technologies Pty Ltd",
  "logo" : "https://saltt.tech/hubfs/raw_assets/public/saltt-theme/images/logo.svg",
  "name" : "SALTT Technologies",
  "sameAs" : [ "https://www.linkedin.com/company/saltt-technologies" ],
  "slogan" : "Defending the digital future.",
  "taxID" : "ABN 32 660 169 808",
  "url" : "https://saltt.tech"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-AU",
  "name" : "SALTT Technologies",
  "publisher" : {
    "@id" : "https://saltt.tech/#organization"
  },
  "url" : "https://www.saltt.tech"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.saltt.tech/insights/prompt-injection-podcast",
  "@type" : "WebPage",
  "about" : {
    "@id" : "https://saltt.tech/#organization"
  },
  "dateModified" : "2026-09-30T22:16:32+10:00",
  "description" : "SALTT Tech Insights podcast: Trinity and Nobby unpack why built-in model guardrails don't stop data exfiltration, why prompt injection is an authorisation problem, and what the ASD's harness guidance means for Australian security leaders.",
  "inLanguage" : "en-AU",
  "isPartOf" : {
    "@id" : "https://www.saltt.tech/#website"
  },
  "name" : "The Prompt Injection Podcast",
  "url" : "https://www.saltt.tech/insights/prompt-injection-podcast"
}
```