You're missing his point somewhat. I don't know if this applies universally to SQL, but consider MySQL.
$stmt = $db->prepare('SELECT bar FROM foo
LIMIT :offset, :count');
...
You can't do that. You can only bind data to fields.
$stmt = $db->prepare('SELECT bar FROM foo
ORDER BY :column :direction');
$stmt->bindValue(':column', 'foo');
$stmt->bindValue(':direction', 'DESC');
You can't do that either, because again, it's not data.
So, you end up having to do something similar to this (for the love of god, don't actually do this):
$stmt->prepare("SELECT bar FROM foo WHERE id = :id
ORDER BY {$column} {$direction}
LIMIT {$offset}, {$count}");
Bound parameters won't save you, and the potential attack vector is there if you're not
really careful. That example shows the most stupid thing you could ever do, so don't do it.