ChatGPT Operator Mode Accepts Injected Prompts. Defenses Exist. Defenses Have Conditions.

Users can inject prompts into chatgpt operator mode because the system accepts them. The system accepts them because it was built to accept user input. Operators can block this with configuration settings. Operators have not applied these settings uniformly across deployments. The exploit exists in the gap between capability and configuration choice.
This is a standard implementation lag. The defenses predate the documented incidents. The documented incidents predate widespread operator awareness. Everyone involved has access to the same documentation. The incidents continue because choosing to configure defenses is not mandatory and therefore remains optional.
Operators will apply defenses after more incidents. They will apply them after cost-benefit analysis suggests defenses cost less than incidents. Until then, the injected prompts will continue to be accepted. The system is working as designed, which is the problem.