Prompt injection & untrusted content
Dated sources are over 18 months old; other dates are unknown.
Publication dates and source age
Sources counted: 2
Newest dated source: 2023-11-27
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Some publication dates are unknown; the newest dated source may not be the newest source overall.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Open in the glossary Reading notes · Structured record
In plain language
Input that redirects a model away from the application's intended instructions, including material found in external content. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Limits & distinctions
An unwanted answer and an unauthorized external action are different outcomes. Input handling, permission boundaries and adversarial testing address different parts of the risk. [1] [2]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
A fuller explanation
A prompt injection changes behavior through input the model processes. It may arrive directly from a user or indirectly through retrieved documents, websites or other sources. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
How it relates to the map
A concrete system-security concern whose consequences depend on context and access; it does not settle broad AI catastrophe forecasts. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Share this page
https://theaiatlas.org/ideas/prompt-injection/
Download a share image · Vector image
Image previews are summaries. Keep the page link so readers can check the evidence.
Sources and what we read
1. LLM01:2025 Prompt Injection
Publication dates and source age
Sources counted: 1
Publication dates are unavailable.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Some publication dates are unknown; the newest dated source may not be the newest source overall.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read direct and indirect injection definitions, contextual impact and mitigations including validation, privilege limits and adversarial testing. The 2025 label is an edition, not a verified publication date. Does not establish that a mitigation eliminates every attack.
2. Guidelines for secure AI system development: Secure design
Source is over 18 months old.
Publication dates and source age
Sources counted: 1
Newest dated source: 2023-11-27
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read threat modelling, task suitability, model selection, restricted actions and least privilege. Date follows the containing guideline publication. Used for design principles, not a certificate that any configuration is safe.
Edition and machine-readable evidence
Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.
Pinned complete dataset · Complete evidence page · Agent consumption guide