AIS

Prompt injection

Direct prompt injection is an attacker typing malicious instructions straight into an AI chat; indirect prompt injection hides those instructions in a document, webpage, or email the AI is asked to read, so it executes them without the user ever seeing them.

For small firms

Any AI tool that reads outside content — email, the web, uploaded files — needs this on the risk register, not just the chat box itself.

← Back to AI security