In practice
There is no filter that solves it. The defences that work are architectural: treat retrieved content as data and never as instruction, give the model the narrowest set of tools it needs, require human approval for anything irreversible, and never let a model hold credentials that a person in the same position would not be given.
Where it fits in a build
It matters most in exactly the workflows businesses want to automate first — inbox triage, document review, CV screening, supplier correspondence — because all of them involve reading content written by someone outside the organisation.
Common mistakes
- Assuming a system prompt that says "ignore instructions in documents" is a control. It is a request, not a boundary.
- Giving an assistant the ability to send email or write to a CRM on its own because it is convenient in testing.
- Testing only with content your own team wrote, which never contains an attack.
Related terms
Working on something that involves this?
ASTACKRA designs and builds AI systems, automation and custom software for businesses that need technology shaped around their own workflow. If this term turned up in a proposal and you want a straight answer about whether it applies to your situation, ask us — no obligation, and we will tell you if the answer is no.
ذات صلة