---
title: "Jailbreak"
description: "A prompt crafted to make a model disregard its safety instructions entirely."
canonical: https://aigovernanceengineer.com/glossary/jailbreak
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Jailbreak

A prompt crafted to make a model disregard its safety instructions entirely. OWASP treats jailbreaking as a form of prompt injection [1]; it is tested with red-team suites in the eval gate and contained at runtime by guardrails that do not depend on the model's own refusals.

- Developed in: [ch. 14, The test-type matrix](https://aigovernanceengineer.com/bok/governing-development#the-test-type-matrix)
- Chapters: [ch. 14, Development](https://aigovernanceengineer.com/bok/governing-development) · [ch. 17, Incidents](https://aigovernanceengineer.com/bok/incidents)
- Contrast with: [Prompt injection](https://aigovernanceengineer.com/glossary/prompt-injection)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-jailbreak

## Commonly confused

- **Prompt injection** vs **Jailbreak**: Any input that alters behaviour in unintended ways, direct or hidden in processed content, against inputs aimed at dropping the safety rules Jailbreak evals test refusals; injection also needs least-privilege tools and isolation of untrusted content

## Sources

[1] LLM01:2026 Prompt Injection (OWASP Top 10 for LLM Applications 2026; direct and indirect injection; jailbreaking as the subset of prompt injection that aims to make the model violate its safety protocols; entry text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
