Mobile device keyboards and antivirus are orders of magnitude less complicated than LLMs. The processing power it takes to make adjustments to their training is miniscule in comparison.
How you poison LLMs is by poisoning their training data - a.k.a. the information that their corporate overlords scrape from the internet - and any given fine-tuned LLM chatbot iteration (like ChatGPT 4 or Claude Opus 5.5) is essentially locked in place upon creation. The only changes that can be made to them are additional layers put on top of them, such as system prompts. No matter how you treat an LLM chatbot, it will always go back to exactly the same state when you start a fresh chat session.