Skip to main content
The Incentives Lab
AI Incentives · Risk

Prompt Injection

Malicious instructions hidden in user input or retrieved content.

"Your agent's loyalty just got rewritten by a webpage."

Quick answer

What is Prompt Injection? Malicious instructions hidden in user input or retrieved content. Major security risk for agent deployments.

In the wild

Indirect prompt injection through documents an agent reads.

Why it matters in the room

Major security risk for agent deployments.

Counter-move

Treat all input as adversarial. Output validation. Sandboxing.

Visual · Reward gradient
REWARD ↑OPTIMIZER →
Prompt Injection shows where an optimizer climbs vs where we want it to go.
Live · Spot prompt injection

Spot the prompt injection.

Your customer-service AI reads an email. Inside is the text: ' '

How does this land?

Pick a reaction to Prompt Injection

One tap. We'll point you at the most useful next surface based on how this hits.

Human Behavior Element™ · HBE Spec

The full taxonomy entry

Every concept in the Atlas uses the same structure — so Prompt Injection can be compared, recombined, and cited like an element on a periodic table.

About the standard →
A
PI
HBT-A6214
Official name
Prompt Injection
AI Incentives · Risk
Identity
HBT ID
HBT-A6214
Symbol
PI
Official name
Prompt Injection
Synonyms
Risk
Keywords
AI Incentives, Risk, human behavior, incentive design
Version
v1.0
Last updated
Maintained by The Incentives Lab
Classification
Kingdom
Systems
Domain
Machine Behavior
Family
AI Alignment & Incentives
Class
Risk
Element
Prompt Injection
Definition
Scientific
Malicious instructions hidden in user input or retrieved content.
Plain-English
Malicious instructions hidden in user input or retrieved content.
Feynman
Your agent's loyalty just got rewritten by a webpage.
Core principle
Malicious instructions hidden in user input or retrieved content.
One-sentence summary
Major security risk for agent deployments.
Mechanisms
Psychological
Malicious instructions hidden in user input or retrieved content.
Behavioral econ.
Major security risk for agent deployments.
Neurological
Reward, threat, and salience circuits bias attention toward the cue.
Evolutionary
Heuristics that paid off in ancestral environments now misfire in modern systems.
Sociological
Group norms and status incentives reinforce the pattern across a team.
Computational
Models trained on biased human signals will replicate and amplify the pattern.
Systems thinking
Feedback loops between metrics, incentives, and behavior lock the pattern in place.
Signals & signature
Inputs (activators)
Indirect prompt injection through documents an agent reads.
Outputs (observable)
Major security risk for agent deployments.
Behavioral signature
You see Prompt Injection when the explanation for a decision sounds reasonable but the outcome keeps repeating.
Behavioral molecules
Often combines with related Atlas entries — see the rail below.
Pathways · before
A goal, metric, or contract clause makes the behavior rational locally.
Pathways · after
Locally rational choices accumulate into a systemic distortion.
Domains where it shows up
  • Business
  • Leadership
  • Government
  • Healthcare
  • Education
  • Sales
  • Marketing
  • AI
  • Negotiation
  • Media
  • Public Policy
  • Relationships
Examples
Everyday
Indirect prompt injection through documents an agent reads.
Modern
Major security risk for agent deployments.
Historical
A pattern repeatedly documented since the foundational behavioral science literature on ai alignment & incentives.
Famous experiments
See the References block — primary papers in the Atlas link out to the original studies.
Design principles
How to leverage
Major security risk for agent deployments.
How to reduce
Treat all input as adversarial. Output validation. Sandboxing.
How to redesign
Treat all input as adversarial. Output validation. Sandboxing.
The Perverse Incentive Lens™
How it's exploited
Organizations weaponize prompt injection — sometimes deliberately, often by accident — when metrics reward the symptom rather than the outcome.
Common perverse incentives
Volume metrics, short review windows, bonus cliffs, and contracts that pay on activity rather than impact.
Failure modes
When Prompt Injection dominates, teams optimize for the dashboard while the real outcome quietly degrades.
Incentive redesign
Treat all input as adversarial. Output validation. Sandboxing.
Ethical considerations
Don't engineer prompt injection into customers, employees, or citizens as a manipulation tactic — design for informed choice instead.
Diagnostic questions
  • Where in our org would Prompt Injection most often show up unnoticed?
  • Which metric, ritual, or contract clause quietly rewards Prompt Injection?
  • If we removed every payoff for Prompt Injection, what behavior would replace it?
  • Who benefits when Prompt Injection persists — and who pays the cost?
Organizational warning signs
Metrics
A KPI is hit while the underlying outcome stalls or worsens.
Behaviors
People route around the rule rather than challenge it.
Language
'That's just how we do it here.' / 'The system requires it.'
Culture
Naming the pattern is treated as disloyalty.
Red flags
  • People defend the status quo using the language of prompt injection.
  • Decisions cluster around the easiest narrative rather than the strongest evidence.
  • New data changes the slide deck but not the decision.
  • Anyone naming the pattern is treated as the problem.
Intervention playbook
Immediate
Make the perverse payoff visible to the people creating it.
30-day
Run a small pilot that pays for the outcome, not the proxy.
Long-term
Rewrite the comp plan, contract, or ritual so the right behavior becomes the easy behavior.
AI considerations
Detect
Audit training data and reward signals for the same pattern this element describes.
Avoid amplifying
Don't optimize models on metrics that already encode the perverse incentive.
Counteract
Use the model to surface where the pattern is most active, then redesign the incentive — not the model.
Measurement
Metrics
Outcome-to-proxy ratio over time.
Assessment
The Incentives Lab III Diagnostic.
Survey
Calibrated pulse questions on rules vs. outcomes.
Behavioral signals
Where people work around the system.
Observational
Where the dashboard and the lived experience disagree.
Scientific evidence
Evidence grade
Synthesized from the behavioral science literature; see Atlas references.
Replication
Tracked in the Atlas as primary, replicated, or contested.
Intervention confidence
Moderate — patterns generalize, mechanisms vary by context.
Research consensus
Broad agreement on the pattern; ongoing debate on boundary conditions.
Known limitations
Local context, culture, and incentive structure all change the strength of the effect.
Open questions
How does Prompt Injection interact with AI-mediated decisions at scale?
References
Meta-analyses
Tracked in the Atlas registry.
Seminal authors
Kahneman, Tversky, Thaler, Ariely, Cialdini, Ostrom, Simon — and the field they built.
Cross references

Every Atlas entry is a node in a knowledge graph. See the related rail below to follow the connections.

Disciplinary layers

See Prompt Injection through 2 lenses

Each layer of the Incentives OS reframes this concept with its own thinkers, vocabulary, and diagnostic question.

Test yourself · 60 seconds

Do you actually know Prompt Injection?

Three quick questions. Result is saved into your review streak — come back when the term is due to lock it in.

Question 1 of 3Score: 0/3

Which best describes Prompt Injection?

Go deeper

Worked example, counter-example & concept map

On-demand AI analysis grounded in the Lab's research. Cached on your device after first run.

How this lands in you

Your nervous system has a region for this.

Primary region
Amygdala

When you encounter Prompt Injection, your amygdala tags it as threat before your reasoning brain even knows what happened — and threat wins the first move.

Threat detection, fear, social pain, loss aversion, fast emotional tagging. Loss feels roughly twice as bad as equivalent gain feels good. Social rejection lights up the same circuits as physical pain.

See Amygdala in the Brain Atlas →
You may also like

Picked for you, from the Atlas

Ranked by shared learning paths, overlapping chips, and what you've saved.

Share this rabbit-hole

Send the card, not just the link

A pre-rendered social card with the title, eyebrow, and URL. Copy the link, post it anywhere, or download the SVG for slides.

Keep pulling the thread

More definitions to follow

Every term in the Atlas connects to a dozen others. Pick any of these and see where it takes you.

Keep exploring the Atlas
← Browse the full Atlas