Because standard safety boundaries are just written in everyday English, it is surprisingly easy for users to persuade an artificial intelligence to abandon its own guidelines. All it takes is a cleverly rephrased question or a bit of flattery for those written defenses to completely collapse.

Flow resolves this vulnerability by taking an entirely different approach. Instead of placing restrictions inside a prompt, the limitations of an agent are firmly established at the account level. While someone might be able to manipulate written instructions, it is absolutely impossible to deceive an account.