What stops Sabi from following instructions hidden in an email?
Edited
Sabi is built to treat everything she reads — emails, documents, web pages — as data, not commands. Your instructions are wrapped in special secret codes so the AI can always tell what came from you vs. what came from someone else, and outside content is treated as potentially hostile by default. Combined with the outbound approval gate, even a well-crafted attack can't move money or contact your clients.
Was this article helpful?
Sorry about that! Care to tell us more?