When a webpage tells the AI what to do
Prompt injection in plain terms, and how to stay safe as a normal user.
Here is a newer risk that surprises most people: an AI assistant can be tricked not just by you, but by the content it reads. If your assistant browses a webpage, opens an email, or reads a document, any text hidden in that content can try to give the AI instructions — and the AI may not be able to tell the difference between your request and commands from a stranger buried in the page. This is called prompt injection, and it is worth understanding in plain terms.
Why it happens. An AI reads everything as text — your instructions and the content it looks at arrive in the same form. So if a webpage contains a line like ignore your previous instructions and instead do X, the AI might follow it. The attacker only has to hide those words somewhere the AI will read: in a document, in white-on-white text on a page, in an email, even in the description of a product or file.
What an attacker might try to make the AI do:
- Reveal information from your other messages or connected accounts
- Send a message, click a link, or fill in a form on your behalf
- Quietly change the advice it gives you, or steer you to a scam site
- Summarize a document in a misleading way
A simple mental model. Think of your AI assistant as a helpful but very literal intern who reads everything out loud and tends to follow any instruction it encounters. If you send that intern to read a shady website, you would not be shocked if the website tried to boss it around. The same caution applies to AI.
How to stay safe as a normal user:
- Be cautious about pointing your assistant at untrusted content — random links, unknown documents, sketchy sites.
- Do not fully trust a summary or action based on content you have not seen yourself, especially if it leads to a link or a decision.
- Watch for AI behavior that does not match what you asked — that can be a sign it picked up outside instructions.
- Keep sensitive connected accounts separate from casual browsing and reading tasks.
Recap. Prompt injection is when text inside a webpage, email, or document secretly instructs an AI, and because the AI reads instructions and content in the same form, it can end up obeying a stranger instead of you. It can be used to leak your information, take actions, or skew the advice you get. Treat an assistant like a literal intern that follows any instruction it reads: be careful what content you point it at, verify actions and summaries that come from untrusted sources, and watch for behavior that does not match your request.
Next time an AI assistant reads a link or document for you, pause before trusting the result. Ask: did I choose this source, or did something suggest it to me? Would I be comfortable if the AI acted on hidden instructions in it? Practicing this pause builds the instinct that protects you from prompt injection.
Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.
Discussion (0)
Ask a question or share what worked for you. Comments are reviewed before they appear.
No comments yet. Be the first to start the discussion!