What needs a change?
The fix is pretty straightforward: treat comment content as untrusted data, not as potential instructions. Comments should be passed to the model with clear role boundaries that prevent them from being interpreted as system-level directives.
If only prompt injection were that easy to defeat! Then YouTube would have done it already, I'm sure, among many others.