MERENA
Advisory Alert

AI threats in the wild: The current state of prompt injections on the web

Google found that some websites now include hidden instructions meant to mislead or interfere with AI tools that read web pages, emails, or documents. Most examples were simple pranks or attempts to boost visibility, but Google also saw a growing number of more harmful experiments, suggesting this problem is increasing.


Who is at risk

People and organizations that use AI assistants to browse the web, summarize documents, read emails, or take actions on their behalf are most at risk.

What to watch for

Watch for AI tools giving strange answers, changing tone unexpectedly, recommending unrelated websites or products, or trying to take unusual actions after reading online content.

What to do

Avoid giving AI assistants permission to take important actions automatically, and review any summaries, recommendations, downloads, or commands they produce before approving them.