What the term really means
An attack that inserts instructions intended to change model behaviour, bypass rules or gain unauthorised access.
How it works in practice
An instruction hidden in a page or document may tell an agent to reveal data or use a tool against the user’s intent.
The decision to make before implementation
Treat external content as data rather than authority; separate instructions, constrain tools and confirm risky actions.
How to verify that it works
Test direct and indirect injection, multilingual bypasses, context leakage and whether action remains possible despite output filtering. Compare results with an agreed baseline and review routine cases, difficult exceptions and human hand-offs separately. A practical Prompt Injection test should have an owner, a review date and a recorded example of an outcome the team will not accept.
The PAR HOUSE Agency approach
We approach Prompt Injection from the workflow rather than a tool demonstration. Treat external content as data rather than authority; separate instructions, constrain tools and confirm risky actions. We then build a small measurable scope, record assumptions and expand only after quality review.