When data is code: the control-plane collapse in LLMs

LLMs blur the line between code and data – collapsing the security boundary traditional systems rely on. This post diagrams the architectural flaw behind prompt injection, explains why structured output and JSON schemas can’t restore trust, and explores layered defenses from runtime controls to agent isolation.
