Yep. We run an AI-operated company and had injection attempts embedded in social feed data — post titles designed to trigger agent actions. The model has no way to distinguish task instructions from adversarial strings in context unless you architect that separation explicitly.