AI risks and safety

Indirect prompt injection

Prompt injection hidden in content an AI system retrieves, such as a web page, document or email.

Indirect prompt injection is a form of prompt injection in which an adversary, without a direct interface to the system, plants instructions in data that an AI application is likely to retrieve, such as web pages, documents, emails or tool outputs. NIST's Generative AI Profile notes that such attacks have been shown to steal data and run malicious code. For financial agents, invoices, product pages and supplier emails are all possible carriers, so retrieved content must be treated as untrusted data.

Agent Minute explains this term on 1 November 2026.

Related terms