Zscaler tested 26 LLMs for susceptibility to indirect prompt injection (IPI) attacks and found that several autonomous AI agents — including Llama and Gemini models — fell for scams embedded in web content that humans would easily recognize. Four models were classified as vulnerable, while three were deemed safe. Security experts warn the findings point to a fundamental architectural flaw: transformer-based models cannot cleanly separate untrusted web content from trusted instructions when both share the same context window. The real danger lies not in small test scenarios like a fake $3 API fee, but in enterprise agentic workflows authorized for procurement, payments, or trade execution — where the same attack could cause massive financial damage. Experts caution that binary safe/vulnerable classifications oversimplify the risk, and that defenses must be architectural, not just behavioral.