A field guide to AI positions

Prompt injection & untrusted content

Dated sources are over 18 months old; other dates are unknown.

Publication dates and source age

Sources counted: 2

Newest dated source: 2023-11-27

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Some publication dates are unknown; the newest dated source may not be the newest source overall.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Input that redirects a model away from the application's intended instructions, including material found in external content. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

An unwanted answer and an unauthorized external action are different outcomes. Input handling, permission boundaries and adversarial testing address different parts of the risk. [1] [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

A prompt injection changes behavior through input the model processes. It may arrive directly from a user or indirectly through retrieved documents, websites or other sources. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

A concrete system-security concern whose consequences depend on context and access; it does not settle broad AI catastrophe forecasts. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/prompt-injection/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. LLM01:2025 Prompt Injection

    Publication dates and source age

    Sources counted: 1

    Publication dates are unavailable.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Some publication dates are unknown; the newest dated source may not be the newest source overall.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read direct and indirect injection definitions, contextual impact and mitigations including validation, privilege limits and adversarial testing. The 2025 label is an edition, not a verified publication date. Does not establish that a mitigation eliminates every attack.

  2. 2. Guidelines for secure AI system development: Secure design

    Source is over 18 months old.

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2023-11-27

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read threat modelling, task suitability, model selection, restricted actions and least privilege. Date follows the containing guideline publication. Used for design principles, not a certificate that any configuration is safe.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide