version 26.6.4 · Self-Help · Printing~3 min read

Hidden instructions: when a document tries to boss your AI around

Emails, documents and web pages can contain instructions aimed at the AI reading them — sometimes invisible to you. It’s called prompt injection.

  1. Be careful asking AI to summarise and act on content from outside your business — emails, attachments, websites.
  2. Don’t let an AI tool send, reply, share or buy anything based on outside content without you checking first.
  3. If an AI summary suddenly tells you to click a link, reset a password or contact someone, treat it like a phishing email.
  4. Watch for answers that go off topic, push you to act urgently, or ignore what you asked.
  5. Report odd AI behaviour to IT, with the document or email that caused it.

Based on: OWASP — LLM01:2025 Prompt injection · ASD’s ACSC — Engaging with artificial intelligence

Still stuck after those?

You’ve done the right thing by trying. Send whedo.it a quick note — what you tried, what you saw — and a senior pair of eyes will be on it the same business day.

+61 421 346 887
5.0
★★★★★ on Google · loading…
Read all on Google →