Prompt injection

An input that alters a model's behaviour or output in ways its designers did not intend. It is direct when the user supplies it and indirect when it arrives inside content the model processes, such as a web page, file or tool result 1. Contained by guardrails, least-privilege tools and evals.

Developed in
ch. 04, Layer 04: Runtime Controls & Observability
Chapters
ch. 01, Definition · ch. 04, The Stack · ch. 17, Incidents · ch. 23, AI Agents
Contrast with
Jailbreak · Hidden Context Exposure
Source
1 numbered reference, listed below

Commonly confused

  • Prompt injection versus Jailbreak

    Prompt injection
    An input that alters a model's behaviour or output in ways its designers did not intend.
    Jailbreak
    A prompt crafted to make a model disregard its safety instructions entirely.

    The differenceAny input that alters behaviour in unintended ways, direct or hidden in processed content, against inputs aimed at dropping the safety rules.

    Why it mattersJailbreak evals test refusals; injection also needs least-privilege tools and isolation of untrusted content.

Where it is used

12 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Patterns that use this term

4 pattern pages use the term, most mentions first.

Sources

  1. [1] LLM01:2026 Prompt Injection (OWASP Top 10 for LLM Applications 2026; direct and indirect injection; jailbreaking as the subset of prompt injection that aims to make the model violate its safety protocols; entry text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Prompt injection. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/prompt-injection. CC BY 4.0

BibTeX

@misc{aige2026promptinjection,
  author  = {Jorge García Aibar},
  title   = {{Prompt injection}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/prompt-injection}
}