Moreover, prompt injection comes because prompts are by no means a well-defined programming interface - all of the system's responses are heuristics. Considering how hard stopping exploits of systems designed to stop them is, stopping exploits of systems that aren't engineered but "trained" is likely impossible.
Edit: and I'd also speculate that the line between prompt-injection and prompt leakage might be rather as well.