Risk & governance
Prompt injection
Instructions in untrusted content that attempt to redirect an AI system.
Definition
Prompt injection occurs when text from a user, document, webpage or tool output manipulates a model into ignoring intended instructions or controls.
Why it matters
Tool-using and RAG systems can turn a text-level attack into data leakage or unauthorised actions.
Related concepts
- Red teaming
Adversarial testing designed to uncover failures and unsafe behaviour.
- Guardrail
A technical or procedural control that constrains system behaviour.
- Entitlements
Rules defining which data and actions a user or system may access.