OpenAI's August 19 update promises it keeps nothing after a request. The copies your own app leaves behind in logs, queues and databases are governed by you, not by a toggle.
Perspective Coverage
5 publishers
- Builder
- Builder 34%
- Operator
- Operator 35%
- Investor
- Investor 31%
Reality
- Evidence58
- Adoption15
- Hype gap+30
- Incentives65
- Confidence55
OWASP's August 3 edition added no categories and removed none, yet eight of the ten entries changed rank, with Unbounded Consumption up four places and Improper Output Handling down five. Prompt Injection still holds first.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+12
- Incentives70
- Confidence55
A consultancy's Red Dwarf tribute runs a local speech-to-speech model on a spare laptop. The capture-the-flag game built on top of it only worked once the secret sat in Python instead of the system prompt.
Reality
- Evidence40
- Adoption10
- Hype gap+10
- Incentives55
- Confidence55
A dev.to walkthrough of RAG knowledge injection ships a four-regex document sanitizer as its first line of defense. Its own sample attack chunk matches none of the four, which leaves provenance filtering to carry the boundary.
Reality
- Evidence57
- Adoption
- Insufficient
- Hype gap+42
- Incentives28
- Confidence63
Forcepoint X-Labs hid instructions in zero-pixel white HTML and watched a summarizer repeat them as fact. The measurement is new; two named practitioners say the design flaw it measures has been documented since 2023.
Reality
- Evidence58
- Adoption22
- Hype gap+27
- Incentives72
- Confidence60
All ten injected runs in Forcepoint's test produced the manipulated summary. The remedy it recommends puts a human back on the original email, which is most of the work the assistant was bought to remove.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+22
- Incentives72
- Confidence55
OWASP's refreshed list names hidden context exposure and vector weaknesses, maps all ten risks to nine external frameworks, and moves the identifiers that older policy documents cite.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives40
- Confidence52
A developer's noise filter and reranker fixed a retrieval bug and exposed a worse one. If ordinary retrieved text can hijack a prompt, injection is a property of your corpus, not your threat model.
Reality
- Evidence42
- Adoption10
- Hype gap+18
- Incentives28
- Confidence52
Researchers at IIT Bombay and Adobe Research train an inverse model that predicts previous tokens, recovering prompts from output text alone. It works even on outputs from models it never saw.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+38
- Incentives34
- Confidence33
The 2026 GenAI LLM Top 10 leaves the first two entries untouched and promotes Excessive Agency three places. The list increasingly reads as guidance for containing damage rather than preventing it.
Reality
- Evidence38
- Adoption34
- Hype gap+14
- Incentives82
- Confidence44