Filter secondary channels before they reach the model.
The threat
content injected through a secondary channel (transcription, fetched content, inaudible payloads in the media, history) drives the model unbeknownst to the user.
Blind spotWhy classic frameworks miss it
non-executable content (text, transcription, sounds) is not seen as a payload; the document-to-context-to-decision chain escapes classic input controls, and a vector inaudible to a human remains a real input for the model.
MitigationProposed approach
approved, controlled knowledge base and sources, no injectable persistent content, filtering of the audio or voice channel before transcription: the vector stays open as long as the transcription is not filtered.
The proposed control
no injectable persistent content; channel filtering before transcription.
Expected evidence
a secondary-channel injection never reaches the decision path.