---
title: "Prompt injection"
description: "An input that alters a model's behaviour or output in ways its designers did not intend."
canonical: https://aigovernanceengineer.com/glossary/prompt-injection
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Prompt injection

An input that alters a model's behaviour or output in ways its designers did not intend. It is direct when the user supplies it and indirect when it arrives inside content the model processes, such as a web page, file or tool result [1]. Contained by guardrails, least-privilege tools and evals.

- Developed in: [ch. 04, Layer 04: Runtime Controls & Observability](https://aigovernanceengineer.com/bok/the-stack#layer-04-runtime-controls--observability)
- Chapters: [ch. 01, Definition](https://aigovernanceengineer.com/bok/definition) · [ch. 04, The Stack](https://aigovernanceengineer.com/bok/the-stack) · [ch. 17, Incidents](https://aigovernanceengineer.com/bok/incidents) · [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Jailbreak](https://aigovernanceengineer.com/glossary/jailbreak) · [Hidden Context Exposure](https://aigovernanceengineer.com/glossary/hidden-context-exposure)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-prompt-injection

## Commonly confused

- **Prompt injection** vs **Jailbreak**: Any input that alters behaviour in unintended ways, direct or hidden in processed content, against inputs aimed at dropping the safety rules Jailbreak evals test refusals; injection also needs least-privilege tools and isolation of untrusted content

## Sources

[1] LLM01:2026 Prompt Injection (OWASP Top 10 for LLM Applications 2026; direct and indirect injection; jailbreaking as the subset of prompt injection that aims to make the model violate its safety protocols; entry text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
