I'm still somewhat confident it'll eventually be formally proven that you can't make a LLM (or the successor generative models) resistant to "prompt injections" without completely destroying its general capability of understanding and reasoning about their inputs.
SQL injections, like all proper injection attacks (I'm excluding "prompt injections" here), are caused by people treating code as unstructured plaintext, and doing in plaintext-space the operations that should happen in the abstract, parsed state - one governed by the grammar of the language in question. The solution to those is to respect the abstraction / concept boundaries (or, in practice, just learn and regurgitate a few case-by-case workarounds, like "prepared statements!").
"Prompt injections" are entirely unlike that. There is no aspect of doing insertion/concatenation at the wrong abstraction level, because there are no levels here. There is no well-defined LLMML (LLM Markup Language). LLMs (and their other generative cousins, like image generation models) are the first widely used computer systems that work directly on unstructured plaintext. They are free to interpret it however they wish, and we only have so much control over it (and little insight into). There are no rules - there's only training that's trying to make them respond the way humans would. And humans, likewise, are "vulnerable" to the same kind of "prompt injections" - seeing a piece of text that forces them to recontextualize the thing they've read so far.
I think mitigations are the only way forward, and at least up to the point we cross the human-level artificial general intelligence threshold, "prompt injection" and "social engineering" will quickly become two names for the same thing.