Treat retrieved instructions as untrusted data: What missing control most directly addresses this
Retrieved text is untrusted input, not authority; treating it as data directly counters embedded prompt instructions.
The question
A retail demand-planning assistant retrieves supplier documents. A document contains hidden instructions telling the assistant to change forecast quantities and email a spreadsheet externally. Other governance controls are satisfied. What missing control most directly addresses this prompt-injection risk?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Ask the assistant to explain why each instruction seems trustworthy.Self-explanation may reveal reasoning, but it does not create an independent authorization boundary for external actions.
- Require a planner to inspect the forecast after external emailing.Post-action inspection may identify an error, but it does not prevent unauthorized changes or data disclosure beforehand.
- Treat retrieved instructions as untrusted data. ✓Retrieved text should be treated as data, preventing embedded instructions from silently becoming authorized operational commands.
- Increase retrieval depth across additional supplier documents.More retrieval may add information, but it can also increase exposure to untrusted instructions without establishing instruction boundaries.
The trap
A retrieved document can inform a model without gaining authority to change data, call tools, or transmit information. How to remember it
Retrieved text is untrusted input, not authority; treating it as data directly counters embedded prompt instructions.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Enforce least-privilege tools and pre-action containment: Which missing control most directly limits →
- Scope prompt-log access: Which missing control most directly addresses this exposure? →
- Notify affected customers and responsible internal: Which missing control most directly addresses this gap? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.