
The AI XR Podcast. · 2026-06-19 · 59 min
Jonathan Rodriguez Cefalu built the hardware that Snap shipped on people's faces - first the camera-only Gen 1 Spectacles, then the Gen 4 display version. His path through Stanford CS, an honors thesis on varifocal display optics, and a startup called Vergence (named after the vergence-accommodation conflict in AR) led him to Snap, and then to the problem he is working on now. Preamble AI exists to prevent the worst possible AI outcomes - starting with a class of attack that Preamble was the first to publicly demonstrate: prompt injection. Ted Schilowitz hosted this episode solo. Together, he and Jonathan worked through the architecture problem sitting under every AI assistant being deployed at scale right now: large language models see one token stream. There is no separation between what the developer intended and what an untrusted email or web page is quietly instructing the model to do. With Gemini Spark about to give AI agents access to tens of thousands of emails per user, this is not a theoretical concern. Jonathan's team has a proposed fix - and they have already shaped federal law.