Prompt injection is an attack where malicious instructions sneak into the data an AI system is processing. The AI can’t tell the difference between what it’s supposed to do and what an attacker wants it to do. The result: the AI does something it shouldn’t.
If you’ve heard of SQL injection, you already understand the core idea. In SQL injection, a hacker types malicious database commands into a form field. The database treats it as legitimate SQL and executes it. Prompt injection works the same way—except instead of SQL commands, the attacker injects instructions into text that an AI will read.



