Security & AI

Prompt injection is not ordinary input validation: a business guide

Prompt injection can cause an AI system to treat untrusted content as instructions. The NCSC warns that it is not simply SQL injection with a new name and may not have a complete technical fix.

Source links included
Editorial image accompanying Prompt injection is not ordinary input validation: a business guide

Context

What happened, and why it matters

An indirect attack can be hidden in a document, web page or message that an AI system later reads. If the system also has tools, the model may be persuaded to reveal information or request an unwanted action.

Filtering suspicious phrases is not a sufficient security boundary because natural language has too many equivalent forms and legitimate instructions can conflict. The architecture must assume some attacks will reach the model.

Impact reduction is therefore central: restrict data, restrict tools, separate trust zones, require confirmation and make actions observable. If the remaining risk is unacceptable, the use case may not be suitable for an LLM.

Separate the announcement from the outcome

The named source explains what its publisher announced or recommended. It does not guarantee availability, suitability or results for every organisation.

Details

A useful way to read the update

RiskArchitectural response
Hostile user promptTreat model output as untrusted
Hostile retrieved contentSeparate sources and minimise privileges
Unwanted tool callAllow-list actions and validate parameters
Sensitive outputRestrict context and apply access checks outside the model
Hidden failureLog, monitor and provide a human route

Work through the guide

Signal board

Choose a lens to make the information easier to scan.

01Source

NCSC prompt injection article

02Check

Identify every untrusted input source.

03Record

Keep authorisation outside the language model.

Decision check

Put the update in your own context

Decision path

Move from news to a controlled change.

  1. 1ReadPrimary source
  2. 2CheckYour context
  3. 3TestLimited scope
  4. 4ReviewUseful evidence
  5. 5RecordDecision & owner

Practical response

What to do next

  1. 01

    Identify every untrusted input source.

  2. 02

    Keep authorisation outside the language model.

  3. 03

    Limit tools to the narrow task.

  4. 04

    Add human approval before consequential actions.

  5. 05

    Run adversarial tests and review logs.

Work through the guide

A controlled route forward

Step 1 of 4
  1. Treat model output as untrusted

  2. Identify every untrusted input source.

  3. Keep authorisation outside the language model.

  4. Limit tools to the narrow task.

Questions

How to use this update responsibly

What period does this article cover?

NCSC guidance current in 2026. The article was published on 17 September 2026; check the linked source for changes made later.

Does the announcement mean every organisation should adopt it?

No. Availability, cost, risk and usefulness depend on the specific workflow. A limited test with an owner and measurable acceptance criteria is more informative than a provider demonstration.

How should unverified discussion be treated?

Forum posts, rumours and individual reviews can reveal questions worth testing, but they do not establish prevalence or fact. Confirm material decisions through primary documentation, direct testing and qualified advice where necessary.

Relevant service

Need help applying this to your own setup?

Our security, privacy & accessibility service can help you review the current position, decide what is proportionate and plan a clearly scoped next step.

Explore Security, privacy & accessibility

Sources

Read the original material

These sources support the factual description above. External pages can change after our publication date.

Cookie settings

Choose what this site may use

Optional categories are off by default. Change these choices at any time from the cookie button.

See the cookie policy for the current list and more information about each category.

Accessibility

Adjust your reading experience

These controls supplement the underlying website.

Text size

UserWay is an optional third-party accessibility tool. Loading it connects to UserWay; the built-in controls remain available without it.

Live chat

Start a conversation.

Privacy information

Google reCAPTCHA helps protect this form from spam. Google privacy · Google terms.

Open contact form

Prefer email? [email protected]