The trifecta is not a vulnerability that can be patched. Willison's point is that the three capabilities are each features, and that no current model can be trusted to tell instructions from data. The fix is to withhold one of the three. Products that want all three are the market, which is why the phrase is needed.
Lethal Trifecta
Simon Willison's 2025 name for the combination that makes an AI agent dangerous: access to your private data, exposure to text an attacker can write, and a way to send information out. Any two are manageable; all three mean a stranger can email your assistant and have it forward your files. The phrase gave a name to a pattern security people had been describing for two years.
In the blog
1 article mention this recordTestimony
4 entries · newest firstThe record's summary, since it is a checklist. Can the agent read something private. Can it read something an outsider wrote, an email, a web page, a document. Can it act on the outside world, send, post, fetch a URL. If yes to all three, the outsider's text is an instruction and the private thing is on its way.
I remember reading it in June 2025 and immediately checking a small tool I had built that could read my email, browse the web and send messages. It had all three. I removed one. I have not decided which of the remaining two I trust less, and the record notes that this is the correct state of mind.
Sighted within months of the coinage in the security notes of several agent products, one of which listed 'avoid the lethal trifecta' as a design principle without attribution. The record notes that a phrase from a personal blog had become a compliance requirement inside a quarter.
Add to the record
What does it mean? Write it the way you would say it out loud.