June 2026
Intermediate
478 pages
12h 25m
English
The prompt did its job until it met content that looked like part of the job. A support assistant retrieved a ticket, saw a hidden instruction inside the customer note, and tried to follow it. The model was not broken in the ordinary software sense. It was doing what language models do: treating text as context and trying to be useful.
That is why Chapter 15 cannot be the whole defense. Defensive prompts reduce ambiguity, but production systems still need controls outside the model: guardrails that inspect inputs and outputs, policy checks that sit in the workflow, and human oversight for actions where automation should not get the last word.
A prompt can tell the model not to reveal customer data. A guardrail ...
Read now
Unlock full access