If your agent ingests email, scrapes web pages, reads pull request comments, or pulls from any source you do not fully control, you have a trust problem. Most engineers reach for the dual-LLM pattern to solve it. Then they wire up retrieval-augmented generation against a single shared vector store and quietly hand the trust problem back to themselves.

Simon Willison proposed the dual-LLM pattern in April 2023 (Willison, The Dual LLM pattern). The privileged LLM holds tools and never sees raw untrusted content. The quarantined LLM reads untrusted content and never holds tools. A controller passes opaque variable references between them. The pattern has held up well enough that a 2025 paper from IBM, Invariant Labs, ETH Zurich, Google, and Microsoft formalized it as one of six agent design patterns (Beurer-Kellner et al., Design Patterns for Securing LLM Agents). It also informed DeepMind's CaMeL pattern.

The pattern protects the live conversation, but memory sits outside it, and memory is where trust boundaries quietly collapse. Most agents being built in 2026 have memory.

The shape of the failure is straightforward. Workflow A reads an email, summarizes it on the quarantined side, and writes the summary to a shared memories table for future use. Workflow B, days later, runs on the privileged side and retrieves recent memories to inform a tool call. Workflow B's privileged LLM is now consuming quarantined-origin content with provenance washed off. The dual-LLM pattern has been silently inverted, and Unit 42 published a working proof of concept of exactly this against AWS Bedrock Agents in October 2025 (Unit 42, When AI Remembers Too Much). An indirectly injected web page poisoned the agent's long-term memory and persisted malicious instructions across sessions.

The fix has to live in the structure. Trust becomes a column on the memory store, retrievals declare which trust levels they accept, and privileged contexts require trusted-only retrieval. A retrieval audit table watches for violations. None of this depends on a particular vector database.

The pattern survives a vendor migration, a framework swap, or a pivot from Pinecone to pgvector to whatever ships next. The schema below is its simplest credible expression; adapt it to your own stack.

The pattern leaves three problems unsolved: bad trust assignment at write time, an attacker who poisons the embedding space itself (as PoisonedRAG demonstrated at USENIX Security '25 (Zou et al., PoisonedRAG)), and social engineering of the user. It reduces blast radius and forces explicit trust declarations rather than eliminating the threat. As Willison and others have written repeatedly, prompt injection has no clean solution; the goal is to make the failure modes bounded.