The trouble for AI vendors is that LLMs fundamentally cannot do anything but in-band signaling. There is simply no way to do anything *but* try and filter out bad words from the jumble of words that you call a "prompt."
Sometimes, attackers find a way to get your machine to confuse your out-of-band signaling and effectively make your system into one that uses in-band signalling; that's in essence what an *injection* attack is. But that's not how LLMs work! At all!