Prompt injection
In more depth
Language models read their operating instructions and the content they are given as one stream of text, so a document, email, or web page an AI tool ingests can smuggle in wording the model treats as a command. Injected instructions can override the vendor's system prompt, pull information the session has access to, or misdirect an AI agent into unintended actions—and the indirect, hidden-in-content form is the harder problem, because the user never sees it. No complete technical fix exists today; practical mitigations include restricting what data and tools an assistant can reach, filtering untrusted content, and keeping human approval in front of consequential actions. For legal teams it is a vendor-diligence question: before pointing a tool at client matter data, ask how it defends against instructions embedded in the material it reads.
Further reading: Wikipedia.
Related terms
Educational information, not legal advice. AI terminology and tools change quickly; definitions reflect usage as of the last-updated date. For what bar associations and courts actually require of lawyers using AI, see legalaicompliance.help and consult a licensed attorney in your jurisdiction.