Methodology · long-form
planned
~4,500 words
How to detect indirect prompt injection on the public web: a consolidated methodology
Consolidated long-form successor to the three live posts above. Multi-agent fetch, isolated browser contexts, baseline diffing, LLM-judged severity, attack-class taxonomy. Reproducible test cases against the EverHarden test corpus, with open-source detector components. Cites OWASP LLM Top 10, EchoLeak CVE, Forcepoint April 2026 research, Kai Greshake’s original IPI paper.
Findings & landscape · May 2026
planned
in-the-wild study
The state of indirect prompt injection on the [category] web, May 2026
First public sweep against a single content category. Prevalence by attack class, severity distribution, anonymized case studies, disclosure-and-remediation timeline. Raw anonymized data published alongside.
Regulator interpretation · auf Deutsch
planned
EU AI Act
Indirect Prompt Injection und der EU AI Act: Was Hochrisiko-Anbieter zu Art. 15 wissen müssen
Welche Systeme als Hochrisiko gelten, was der EU AI Act (Art. 15 Robustheit/Cybersicherheit) zu Prompt Injection sagt, Pflichten für Anbieter, Nachweis und Dokumentation, Checkliste zur IPI-Risikobewertung. Hinweis: Die Hochrisiko-Pflichten wurden per Digital Omnibus von August 2026 auf Dezember 2027 verschoben — die Robustheits-Pflicht selbst bleibt. Für deutsche Compliance-Verantwortliche.