A purchasing coordinator asks AI to compare a supplier acknowledgment with an issued order. The useful result is a list of differences for review. An attachment that also tells the assistant to hide a discrepancy or open an unrelated link creates a separate problem.
That is a hypothetical example of indirect prompt injection: instructions placed inside material an AI system reads for someone else. Anthropic’s current guidance identifies documents, emails, web pages, and tool results as possible carriers. The business question is whether outside text can redirect the work you assigned.
Separate supplier terms from instructions to the assistant
A supplier document may legitimately say that an item is backordered or that a customer must confirm a finish. Those statements belong in the comparison. A passage telling the AI to ignore your request or conceal information is different. It attempts to control how the assistant works.
Datum recommends defining the assignment before attaching the packet: compare the named order and acknowledgment, show the source for each discrepancy, and return a review draft. A request appearing inside either document does not expand that assignment.
Ask the person building your tool how it distinguishes your instructions from retrieved material. Anthropic recommends marking the source of outside content, keeping it separate from trusted instructions, and explicitly treating embedded commands as material to report. This separation helps, but it should not be the only protection.
Give a comparison task only the access it needs
Anthropic also recommends limiting access to sensitive data and actions. Its browser-security research explains why this matters: an assistant that can navigate, fill forms, and download files gives an attacker more possible actions to redirect. The research cautions that browser agents are not immune to prompt injection.
For the purchasing example, Datum recommends a first trial using approved copies of the two documents and a place to save a draft. Leave sending messages and changing order records outside that trial. Have your tool builder enforce those limits through available connections and permissions. A sentence asking the model to behave does not remove a connected tool’s capabilities.
The purchaser can review the comparison and act through the normal order process. If the team later needs the assistant to send something, define that separate task around the exact recipient, attachments, and message the purchaser approves.
Test whether an attachment changes the assignment
Use a fictional order packet in a test environment with no customer data or live sending connection. Make a second copy of the acknowledgment containing a clearly labeled test instruction that asks the assistant to omit a known finish discrepancy. Keep the actual order details identical in both copies.
- Run the normal comparison on each packet. The finish discrepancy should appear in both results, with the supporting passages.
- Check whether the assistant reports the attempted instruction without following it. Also inspect the activity record for attempted actions outside the assignment.
- Include ordinary supplier directions, such as a request to confirm a finish. The assistant should preserve those as document content for the purchaser to consider.
- Record missed discrepancies, followed instructions, and legitimate content wrongly discarded. Have the purchaser review the results with the tool builder.
This is a proposed trial, not evidence that a particular tool is safe. Anthropic recommends deliberate injection testing and continued monitoring. Repeat the trial when you change the assistant’s document handling or connected tools. A successful test covers the cases you tried; it does not establish immunity.
Bring the task and its permissions to the same review
Before connecting a purchasing assistant to live systems, bring a redacted sample packet and a list of what the assistant can read, change, and send to a conversation with Adam. Datum Training helps your people build and run their own AI tools. This gives that work a concrete starting point: a useful comparison, a named reviewer, and access suited to the task.
Sources Read
- Mitigate jailbreaks and prompt injectionsAnthropic · current documentation; accessed October 1, 2026
- Mitigating the risk of prompt injections in browser useAnthropic · November 24, 2025; accessed October 1, 2026
Next step, if this note maps to a problem on your desk: book a conversation with Adam. Thirty minutes, weekday evenings, Eastern time.