Methodology · long-form
planned
~4,500 words
How to detect indirect prompt injection on the public web: a consolidated methodology
Consolidated long-form successor to the three live posts above. Multi-agent fetch, isolated browser contexts, baseline diffing, LLM-judged severity, attack-class taxonomy. Reproducible test cases against the EverHarden test corpus, with open-source detector components. Cites OWASP LLM Top 10, EchoLeak CVE, Forcepoint April 2026 research, Kai Greshake’s original IPI paper.
Findings & landscape · May 2026
planned
in-the-wild study
The state of indirect prompt injection on the [category] web, May 2026
First public sweep against a single content category. Prevalence by attack class, severity distribution, anonymized case studies, disclosure-and-remediation timeline. Raw anonymized data published alongside.
Regulator interpretation · auf Deutsch
planned
EU AI Act
Indirect Prompt Injection und der EU AI Act: Was Hochrisiko-Anbieter ab August 2026 wissen müssen
Stichtag August 2026. Welche Systeme als Hochrisiko gelten, was der EU AI Act zu Prompt Injection sagt, Pflichten für Anbieter, Nachweis und Dokumentation, Checkliste zur IPI-Risikobewertung. Für deutsche Compliance-Verantwortliche.