A Real Prompt Injection Attempt Against a Live Australian System, and Why It Failed
In July 2026 an attendee tried to prompt inject a live Australian system. The exact payload, why it failed, and the design that would have fallen for it.
Contents
The Attack Arrived As One Sentence In A Reply
Prompt Injection Is Text Being Read As An Order
Three Architectural Reasons It Failed
The Capability Was There, The Instruction Channel Was Not
The Lethal Trifecta Makes This Architecture, Not A Bug
Real Attacks Look Nothing Like The Demos
Production Systems Have Already Fallen To This
Australia Is Adopting Agents Faster Than It Is Governing Them
Design For Blast Radius, Not For Prevention
Where Australian Regulators Now Stand
What We Are Not Claiming
Frequently Asked Questions
Worried about what your agent could be told to do?
We design and build AI automation for Australian businesses with the boundaries drawn first: separated read and act paths, scoped credentials, and human approval in front of anything irreversible.
See buildAgencyRelated Guides
Nobody owns it: the one question that predicts whether your automation survives its first year
Automations in small businesses die because no named person owns them. The three-question audit to run before any build, why 'the agency monitors it' is not...
Human Approval Before an Automated Send: The Legal and Engineering Case
Why anything your automation sends a customer needs a human checkpoint in Australia, the three approval patterns, and how to stop one becoming a rubber stamp.
How To See What Your AI Agent Is Doing Without Reading A Log File
Six things get sold as agent visibility and they answer different questions. What Zapier, Make and n8n actually show an owner, and where retention fails.
AI Evals: How to Know Your Output Is Actually Right
A demo proves an AI feature can work. Evals tell you how often it does: what to measure, how many cases to start with, and where LLM judges quietly lie.