Australian EnterpriseAI Index
GlossaryTechnical

Prompt Injection

Prompt injection is the AI-era equivalent of SQL injection: an attacker embeds hidden instructions in text the model will process — a document, a webpage, an email — to override the system's intended behaviour, exfiltrate data, or bypass safety controls. It is the leading technical incident class in AI red-teaming exercises and a required control area under most enterprise AI security frameworks.

Primarily affects

The Incidents dimension of the Australian Enterprise AI Index.

See where this shows up in the Index

The open methodology explains exactly how each dimension is scored and weighted.

Read the methodology

Related terms

Definitions are written for enterprise AI governance context, not a formal legal standard. Suggest a correction →