What prompt injection actually is
Your AI system reads a system prompt from you, a request from your user, and often a third document: an email, a webpage, a PDF someone uploaded. The model treats all three as one stream of text. It cannot reliably tell your instruction apart from an instruction hidden inside that third document.
An attacker exploits this by hiding text in something your AI will read. White text on a white background in a CV. A comment buried in a webpage your AI summarises. A line in an email your AI assistant processes. The model reads the hidden instruction and, in enough cases, follows it.
This is why prompt injection is not a bug in one product. It is a property of how every current large language model processes text. You cannot patch it away. You can only limit what an AI system is allowed to do once it has been fooled.

