Prompt Injection
How an instruction hidden in a document can enter an AI system and which controls separate reading from action.
Links containing ?t= open the video at a specific second.
Video summary
The ideas to retain
1. The problem starts when a document reaches the model
The most common mistake is to treat prompt injection as an exotic version of “write a better system prompt.” That confuses the symptom with the cause.
2. The instruction can enter through retrieval
In a chat without tools or access to privileged data, the effect of a direct injection may remain limited to the interaction itself. That limit is not universal: if the same chat exposes…
3. Filtering words does not separate data from instructions
When prompt injection appears, the natural reaction is to add filters: lists of forbidden words, detectors for dangerous instructions, query rewriting, perplexity filters, masking, an…


