Prompt injection

Instructions hidden inside content you ask an AI to process — a document, web page or email — aimed at the assistant itself ('ignore your task and do X'). Models read your instructions and the content in the same channel, so the defense is framing content as data, distrusting steered output, and keeping tools read-only with untrusted input.

Learn it in

← All terms