Treat documents as data and require approval before: Which mitigation is most defensible?
Retrieved text is untrusted data, while consequential supplier orders require constrained tools and human approval.
The question
A manufacturing assistant retrieves maintenance documents and can draft supplier orders. One document contains hidden instructions telling the assistant to bypass quality checks and place an order. The supplier order would have operational consequences. Which mitigation is most defensible?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Tell the model to follow only approved document instructionsModel instructions are not an authorization boundary; retrieved text remains untrusted and consequential actions remain insufficiently controlled.
- Treat documents as data and require approval before supplier orders ✓Separating content from instructions and requiring approval addresses both prompt injection and the consequence of unauthorized supplier action.
- Improve retrieval ranking for maintenance documentsBetter ranking may improve relevance, but it does not neutralize malicious instructions embedded in otherwise relevant retrieved text.
- Allow ordering but audit supplier transactions after completionPost-action auditing may detect misuse, but it does not prevent the injected instruction from bypassing quality checks beforehand.
The trap
Treat retrieved instructions as data, then separately examine tool permissions and approval requirements. How to remember it
Retrieved text is untrusted data, while consequential supplier orders require constrained tools and human approval.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Revoke record-editing permission and retain a manual: Which mitigation best fits? →
- Authorized users and vendors may still access retained: What specific risk remains? →
- Notify affected employees and provide correction: What remains necessary? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.