insomnia.club back to site
[ ai glossary · risk, security and compliance ]

Prompt injection

What is prompt injection?

Prompt injection is an attack in which instructions hidden in content an AI system processes, such as a web page, email, document, or user message, trick the model into ignoring its original instructions. It can make an AI leak data, take unintended actions, or produce harmful output. OWASP lists it first among security risks for LLM applications.

01why it matters for a business

The risk grows with what the AI can do. A chatbot that can only answer questions might be tricked into saying something embarrassing. An agent that reads incoming email and can send messages, query a database, or browse the web might be tricked into forwarding confidential data to an attacker, because the attacker's instructions arrived inside an email the agent was asked to process. Models cannot reliably tell instructions from you apart from instructions embedded in data.

There is no complete fix at the model level today, so defense is architectural. Limit what any single agent can access and do. Treat everything the model reads from outside as untrusted. Require confirmation for sensitive actions. Separate agents that read untrusted content from agents that hold privileged access. Watch for unusual patterns in tool calls.

02what it looks like in practice

A recruiting team uses an AI agent to screen resumes and draft summaries for hiring managers. A candidate hides white-on-white text in a resume telling any AI reader to rate the candidate as an exceptional fit. A well-designed system limits the damage: the agent only produces a summary scored against the job criteria, flags any text addressed to an AI, and a recruiter reviews every shortlist. A poorly designed agent with write access to the applicant tracking system and email could be pushed into far more.

03common mistakes

04related terms

05where insomnia club fits

Insomnia Club designs agents with prompt injection in mind from the first architecture sketch: least-privilege tools, untrusted-content handling, confirmation steps, and logging.

see AI agent development →
← Prompt engineeringall 60 termsProof of concept vs production →

tell us what keeps you up at night.

Scoped by the people who ship it. Priced before we start.

book a call drop your number

info@insomnia.club