Design so that even bad prompts or poisoned context cannot do unlimited damage — containment beats hoping the model always behaves.