I appreciate that the article correctly points out the core design flaw here of LLMs is the non-distinction between content and commands in prompts.
It’s unclear to me if it’s possible to significantly rethink the models to split those, but it seems that that is a minimal requirement to address the issue holistically.