Detecting and blocking the specific failure where retrieved, untrusted data is used to hijack the LLM's behaviour against the requesting user's actual intent — OWASP's ASI01 confused-deputy pattern — distinct from moderating the content of the prompt itself. The mechanism that failed in the documented Copilot Studio and Agentforce incidents.