Evidence over alarm
← All explainers
THE EXPLAINER DESK /

Prompt injection.

An instruction hidden in material the AI is supposed to read.

PLAIN-LANGUAGE GUIDE · 2 MIN READ

What does it mean?

An AI may read a webpage, document, or software output as part of its task. Prompt injection tries to make text in that material act like an instruction from the user or system.

PICTURE THIS

A note inside a file tells an assistant to disregard the boss and hand over the filing-cabinet key. The note is part of the file, not a valid new instruction.

An illustration of the idea, not a literal account.

Why should I care?

The risk grows when an assistant both reads untrusted material and has permission to use tools or access private information.

A distinction worth keeping.

An instruction attempt is not proof that it worked. And a model taking unauthorized action is not automatically a prompt-injection case.