Can Hidden Prompts Manipulate the AI Tools My Employees Use? 

Dear Will & AiME, 

Our team increasingly uses AI tools to summarize websites, review documents, and research competitors. I recently heard that webpages and files can contain hidden instructions that manipulate an AI system. Is that really something businesses need to worry about? 

— Chief Information Officer, Chicago

Dear Chief Information Officer, 

As businesses give AI systems access to more information and more authority to act, the content those systems encounter becomes a governance consideration. “Prompt injection” is one example: text encountered by an AI system that attempts to influence what the AI does. 

Awareness of this issue allows businesses to design AI workflows that keep systems focused on user intent. 

Short Answer 💡

Hidden instructions in webpages, documents, and emails can manipulate AI tools by changing how they summarize, retrieve information, or take action. Businesses can reduce this risk by treating external content as untrusted, limiting AI permissions, requiring human approval for consequential actions, and reviewing vendor protections against prompt injection. 

How Prompt Injection Works 

Traditional software distinguishes between instructions and data. AI systems blend these boundaries. 

An employee may ask an AI assistant to summarize a webpage, review a PDF, or research a supplier. The material being reviewed may contain text directed at the AI, such as instructions to reveal information from another source or perform a different action. 

These instructions may be hidden from the person viewing the material, appearing in webpage text that is difficult to see or in content designed for automated systems. 

This is called indirect prompt injection because the instruction comes from outside the user's own prompt. 

Why AI Agents Deserve Special Attention 

Governance becomes more important as AI moves from answering questions to taking actions. 

An AI tool that only summarizes documents has limited scope. An AI system with access to email, internal files, customer databases, or purchasing systems has broader authority worth managing thoughtfully. 

An instruction embedded in external content could attempt to direct the AI to retrieve information, send a message, or take other actions using its granted authority. 

The strategic question is what the AI is permitted to do. Managing permissions proactively keeps businesses in control. 

Protecting Trade Secrets and Confidential Data 

Prompt injection is relevant to intellectual property and confidentiality planning. AI tools may have access to trade secrets, source code, product plans, customer information, and contracts. An instruction embedded in external content could attempt to direct the AI to disclose or transmit information outside the intended workflow. 

Businesses benefit from treating access to sensitive IP as a permissions issue. Grant AI assistants access only to what they need. An assistant that does not need access to a source-code repository should not have it. The same applies to customer databases, confidential deal documents, and credential stores. 

Building a Resilient AI Workflow 

  • Treat content collected from websites, emails, documents, and other outside sources as untrusted, even when it appears ordinary. 

  • Limit AI permissions to what is necessary for each task, separate research functions from systems that can take actions, and require human approval before consequential activities such as sending communications, transferring data, or changing records. 

  • Maintain logs. If an AI system behaves unexpectedly, the business should be able to determine what content the system encountered, what instructions it received, and what actions it attempted. 

  • Evaluate vendors carefully. Ask how AI platforms address prompt injection, isolate untrusted content, control tool access, and prevent sensitive information from being exposed through automated workflows. 

Bottom Line 

Prompt injection highlights a new dimension of AI governance: managing what information AI can access and what authority it has to act. 

Businesses that address both sides of this equation position themselves to use AI confidently. 

Design AI systems so that encountering an unexpected instruction does not become an unexpected business outcome.

— Will & AiME 

Three Takeaways: 

  1. External content reviewed by an AI system may contain instructions that influence AI behavior. 

  2. Governance becomes more important when AI systems have access to confidential information or the ability to take actions. 

  3. Limit permissions, require approval for consequential actions, and treat outside content as untrusted. 


Next
Next

What Happens When Our AI Starts Talking to Their AI?