Prompt Injection
An attack exploiting how an application combines untrusted input with a prompt written by a higher-trust party, causing the system to follow the untrusted instructions.
Why it matters
In an agentic setting this is not a content problem, it is an authority problem: a successful injection causes an agent to exercise real permissions on an attacker's behalf. The defense is the authority envelope, not better filtering.
Relationships
Typed edges into the rest of the ontology. These are what make the canon traversable rather than merely readable.
| Verb | Target | Meaning |
|---|---|---|
addresses | Authority | The subject speaks to the object as a question or concern. |
constrainedBy | Authority Grant | Inverse of constrains. The subject bounds what the object may do. |
Record
| Canonical identifier | QIS-TERM-00012 |
| Status | Canonical industry term |
| Adoption | Widely used |
| Domain · Layer | Context & memory · Governance |
| Origin | Defined in the AIEOG Shared AI Lexicon (February 2026), adapted from NIST. |
| Semantic aliases | None recorded. |
| First published | 2026-08-02 |
| Last reviewed | 2026-08-02 · 180-day cycle |
Cite the identifier, not the URL. Identifiers are stable; URLs may change. This entry is free to read, quote and index under the dual license. Corrections to [email protected] are published.