An input that alters a model's behaviour or output in ways its designers did not intend. It is direct when the user supplies it and indirect when it arrives inside content the model processes, such as a web page, file or tool result 1. Contained by guardrails, least-privilege tools and evals.
- Developed in
- ch. 04, Layer 04: Runtime Controls & Observability
- Chapters
- ch. 01, Definition · ch. 04, The Stack · ch. 17, Incidents · ch. 23, AI Agents
- Contrast with
- Jailbreak · Hidden Context Exposure
- Source
- 1 numbered reference, listed below
Commonly confused
Prompt injection versus Jailbreak
- Prompt injection
- An input that alters a model's behaviour or output in ways its designers did not intend.
- Jailbreak
- A prompt crafted to make a model disregard its safety instructions entirely.
The differenceAny input that alters behaviour in unintended ways, direct or hidden in processed content, against inputs aimed at dropping the safety rules.
Why it mattersJailbreak evals test refusals; injection also needs least-privilege tools and isolation of untrusted content.
Where it is used
12 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 01 · Definition The disambiguation cluster 2 mentions
- 02 · Why Now The five problems, with the evidence 2 mentions
- 03 · Values & Principles The six principles 1 mention
- 04 · The Stack Layer 03: Evals & Red Teaming as Evidence 2 mentions
- 10 · Reading List Canonical papers: measurement, fairness and evaluation 1 mention
- 12 · Governance Program Updating the policies you already have 1 mention
- 13 · Risk Management Identifying risk: sources, factors and stakeholders 1 mention
- 14 · Development Testing and validation 1 mention
- 15 · Deployment Model types and deployment options 2 mentions
- 17 · Incidents Playbooks, RACI and drills 5 mentions
- 20 · Existing Law Product liability 1 mention
- 23 · AI Agents Threats mapped to controls 2 mentions
Patterns that use this term
4 pattern pages use the term, most mentions first.
- Runtime Guardrail 2 mentions
- Kill Switch / Circuit Breaker 1 mention
- Incident Pipeline 1 mention
- AI Threat Model 1 mention
Related terms
Sources
- [1] LLM01:2026 Prompt Injection (OWASP Top 10 for LLM Applications 2026; direct and indirect injection; jailbreaking as the subset of prompt injection that aims to make the model violate its safety protocols; entry text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .