---
term: "Prompt injection"
category: "AI risks and safety"
url: https://agenticopenfinance.com/glossary/prompt-injection
source: AgenticOpenFinance glossary
---

# Prompt injection

> An attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.

Prompt injection is an attack in which input to a generative AI system is crafted or modified so that the system behaves in ways its operator or user did not intend, such as ignoring its instructions, revealing data or calling tools. NIST's Generative AI Profile distinguishes direct prompt injection, typed by the attacker, from indirect prompt injection, hidden in content the system retrieves. For agents with tools, a successful injection can turn into an unauthorised action, so the defences belong outside the model as well as inside it.

Related terms: [Indirect prompt injection](https://agenticopenfinance.com/glossary/indirect-prompt-injection.md), [Jailbreak](https://agenticopenfinance.com/glossary/jailbreak.md), [Excessive agency](https://agenticopenfinance.com/glossary/excessive-agency.md), [System prompt](https://agenticopenfinance.com/glossary/system-prompt.md)
