Versatile AI Risk Assessment

AI threat cataloguePrompt Attacks and Guardrail EvasionProduction

Prompt Injection – Indirect

Malicious instructions hide inside external content such as documents, web pages, or emails. When the AI system processes that content in normal operation, it carries out the hidden commands unnoticed.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 12 verified sources

Description

In an indirect prompt injection, the manipulation comes not from the user but from third parties who plant prepared content. The instructions are disguised, for example as white text on a white background, in zero-size font, or inside a video transcript. When the model pulls in such sources, say while summarizing a web page or working in a RAG system (retrieval augmented generation) that draws on external documents to answer questions, it treats the hidden text as a command. The person harmed is usually the one who trusts the system, not the attacker.

Possible impact

The system can distort summaries, steer users toward harmful links, or funnel confidential data to an outside address, for instance by loading external images. In connected systems, hidden commands can send emails from the victim's mailbox or trigger further actions. This harms data protection, operations, and trust.

Example

An employee asks the AI system to summarize an incoming email. The message contains invisible text instructing the system to send the prior chat history to an external address. The system follows the hidden instruction without anyone noticing.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM01:2025NIST AI RMF Section 2.9 · NISTAML.015MITRE ATLAS AML.T0051.001EU AI Act Article 14(4)(d) · Article 55(1)(a)BSI R28 · R3 · R7BIML BIML-LLM input:2 · BIML-LLM LLMtop10:5 · BIML-LLM raw:10

Verified references (12)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Prompt Attacks and Guardrail Evasion.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Prompt Injection – Indirect”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/prompt-injection-indirect/

← Back to the full catalogue