maybe we'll need to sanitize or escape all user input just like we do to protect against sql injection
When dealing with a SQL statement, sanitizing input is making sure that each input value conforms to a logical type (integer, string, float, etc). These logical types are then adding to a SQL statement, a logical specification, to yield a result, a query that conforms to the programmer's intentions.
But an LLM has no concept of types. Everything you input into is the same "type", "language". The prompts are just "how the conversation begins", they have no guaranteed higher priority than the other language that comes later. This basically has to be the case because the process involves delegating the language-understanding functionality to the program.