Even your discussion makes it "sanitized input" simply doesn't exist in relation to an LLM. At best it seems like one can prefix and filter input as much as possible, monitor the results but never assume that you are done.
If that's the case then user-facing products that can take any useful action are strictly off the table.
If that's the case then user-facing products that can take any useful action are strictly off the table.