Skip to content

Prompt Injection

What is Prompt Injection?

An attack technique targeting AI language models where malicious instructions are embedded in user inputs to manipulate the model's behaviour. Prompt injection can cause AI systems to ignore safety guidelines or reveal sensitive information.

AI & Technology

Each of these is named in at least one of the same controls as prompt injection. The number is how many controls name both.

What the standards actually require on prompt injection

Requirements naming prompt injection across 6 standards, quoted from the control text.

Generative AI and Foundation Models require specific governance attention beyond traditional AI risk frameworks per Japan AI Guidelines for Business + augmented by AISI Japan AI Safety Institute + Hiroshima AI Process Code of Conduct + emerging AI Bill.

JP-AIG-Generative-AI-Foundation-Model-Specific-Risks-Hallucination-Watermarking-Copyright-LLM-Multimodal · Japan AI Guidelines Generative AI + Foundation Model Specific Risks + Hallucination + Watermarking + Copyright + LLM + Multimodal + Prompt Injection + Jailbreak + Model Extraction + Pre-Deployment Capability Evaluation + AISI Frontier AI

Address OWASP LLM01:2025 Prompt Injection + LLM07:2025 System Prompt Leakage. Prompt Injection occurs when attacker input causes the LLM to act outside intended boundaries via direct injection (user-supplied) or indirect injection (through retrieved data + doc...

OWASPLLM-1 · Prompt Injection and System Prompt Leakage (LLM01 + LLM07)

Apply MEASURE function including: red teaming and adversarial testing per NIST AI 600-1 MEA-5 (model probing + prompt injection + jailbreaking + data extraction + bias testing) + Test + Evaluation + Verification + Validation (TEVV) frameworks + model evaluatio...

NISTAI600-4 · Measure - Red Teaming, Adversarial Testing, and TEVV

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination
HKMA TM-G-11 control

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

Questions people ask about prompt injection

What is Prompt Injection?
An attack technique targeting AI language models where malicious instructions are embedded in user inputs to manipulate the model's behaviour. Prompt injection can cause AI systems to ignore safety guidelines or reveal sensitive information.
Why is Prompt Injection important for compliance?
Prompt Injection is a key concept in AI & Technology. Understanding prompt injection helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Prompt Injection?
Prompt Injection appears in the requirement text of Japan AI Guidelines, OWASP Top 10 for LLM Applications 2025, NIST AI 600-1: Generative AI Profile, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA TM-G-1. Across these standards we have identified 11 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Prompt Injection?
Explore our compliance framework pages to see how prompt injection applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Prompt Injection applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.