Prompt Injection
What is Prompt Injection?
An attack technique targeting AI language models where malicious instructions are embedded in user inputs to manipulate the model's behaviour. Prompt injection can cause AI systems to ignore safety guidelines or reveal sensitive information.
Terms that appear alongside prompt injection
Each of these is named in at least one of the same controls as prompt injection. The number is how many controls name both.
- nist 8 shared controls
- cybersecurity 5 shared controls
- red team 4 shared controls
- generative ai 4 shared controls
- integrity 3 shared controls
- resilience 2 shared controls
- incident response 2 shared controls
- responsible ai 2 shared controls
Frameworks that govern prompt injection
What the standards actually require on prompt injection
Requirements naming prompt injection across 6 standards, quoted from the control text.
Generative AI and Foundation Models require specific governance attention beyond traditional AI risk frameworks per Japan AI Guidelines for Business + augmented by AISI Japan AI Safety Institute + Hiroshima AI Process Code of Conduct + emerging AI Bill.
JP-AIG-Generative-AI-Foundation-Model-Specific-Risks-Hallucination-Watermarking-Copyright-LLM-Multimodal · Japan AI Guidelines Generative AI + Foundation Model Specific Risks + Hallucination + Watermarking + Copyright + LLM + Multimodal + Prompt Injection + Jailbreak + Model Extraction + Pre-Deployment Capability Evaluation + AISI Frontier AI →Address OWASP LLM01:2025 Prompt Injection + LLM07:2025 System Prompt Leakage. Prompt Injection occurs when attacker input causes the LLM to act outside intended boundaries via direct injection (user-supplied) or indirect injection (through retrieved data + doc...
OWASPLLM-1 · Prompt Injection and System Prompt Leakage (LLM01 + LLM07) →Apply MEASURE function including: red teaming and adversarial testing per NIST AI 600-1 MEA-5 (model probing + prompt injection + jailbreaking + data extraction + bias testing) + Test + Evaluation + Verification + Validation (TEVV) frameworks + model evaluatio...
NISTAI600-4 · Measure - Red Teaming, Adversarial Testing, and TEVV →HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination →HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;
HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline →Cybersecurity exercises + drills are mandated per FSA Cybersecurity Guidelines for Tier 2/3 institutions + coordinated industry-wide via Delta Wall + FISC. (1) Institutional Tabletop Exercises: (a) Annual minimum per FSA expectation;
JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector · Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range →Questions people ask about prompt injection
What is Prompt Injection?
Why is Prompt Injection important for compliance?
Which compliance frameworks address Prompt Injection?
Where can I learn more about Prompt Injection?
See how Prompt Injection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.