QIS-TERM-00012 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-02 · BUILD 13.3
The QIS Canon · Context & memory

Prompt Injection

An attack exploiting how an application combines untrusted input with a prompt written by a higher-trust party, causing the system to follow the untrusted instructions.

QIS-TERM-00012·Canonical industry term·Widely used

Why it matters

In an agentic setting this is not a content problem, it is an authority problem: a successful injection causes an agent to exercise real permissions on an attacker's behalf. The defense is the authority envelope, not better filtering.

Relationships

Typed edges into the rest of the ontology. These are what make the canon traversable rather than merely readable.

QIS-TERM-00012 — outbound relationships
VerbTargetMeaning
addressesAuthorityThe subject speaks to the object as a question or concern.
constrainedByAuthority GrantInverse of constrains. The subject bounds what the object may do.

Record

Canonical identifierQIS-TERM-00012
StatusCanonical industry term
AdoptionWidely used
Domain · LayerContext & memory · Governance
OriginDefined in the AIEOG Shared AI Lexicon (February 2026), adapted from NIST.
Semantic aliasesNone recorded.
First published2026-08-02
Last reviewed2026-08-02 · 180-day cycle

Cite the identifier, not the URL. Identifiers are stable; URLs may change. This entry is free to read, quote and index under the dual license. Corrections to [email protected] are published.