At the International Conference on Machine Learning 2026, a team of researchers made a point many would rather ignore: large language models (LLMs) cannot be made fully secure. This is not a bug waiting for a patch. It is a structural flaw in how they work.
Why should an Italian SME care? Because AI is now embedded in everyday business processes: virtual assistants, automated replies, document analysis, CRM integrations. The EU AI Act already imposes compliance obligations on high-risk systems. But if full security is impossible, compliance cannot be a one-time check. It becomes a continuous risk management exercise. European institutions are still debating how to audit models that change with every update. The gap between regulation and technical reality is growing, and Italian businesses are exposed exactly there.
Sponsored Protocol
There is also a practical layer. An LLM can be tricked into ignoring safeguards, leaking sensitive data or generating harmful content. This is not an edge case: it is a known property. Anyone implementing an AI solution without surrounding controls — permissions, output validation, access management — is leaving the door open. When damage happens, responsibility falls on the provider and the buyer, not on the research paper.
Our position is clear. Absolute security does not exist, risk management does
We, at Meteora Web, have been building software and platforms for over eight years. We come from accounting and ERP systems: we know every technical choice has a cost and a value. Security is not an add-on. It is a feature designed from the start. The ICML study confirms what we see every day in the servers and websites we manage: weak configurations, missing backups, exposed credentials. Demanding an inviolable model is the perfect excuse to do nothing — or worse, to sell illusions with hardened prompts and fake audits.
Sponsored Protocol
Anyone using LLMs in production should demand a systemic approach: strong authentication, least privilege, logging, monitoring, backups and an incident response plan. Without these, there is no security. The fundamental flaw of LLMs is not a reason to abandon the technology. It is a reason to raise the bar.
This matters twice as much in Europe. If companies stop experimenting because they fear liability, we fall further behind the US and China. The answer is not slowing AI down. It is making AI reliable, traceable and fixable. Italian SMEs do not need perfect models. They need tools that handle uncertainty and partners that take responsibility.
Sponsored Protocol
For everyone reading this — business owners, developers, decision-makers — the takeaway is practical. If you are using an LLM in any process that touches customers or sensitive data, ask yourself a simple question: what happens if the model gets bypassed? Then build the answer before someone else builds it for you. Security is a process, not a feature. Those who invest in real defences today will be the only ones not explaining tomorrow why they lost everything.