Skip to content

AI prompt injection and untrusted content: assess, limit and test the risk

For IT staff, team leads and power users who set up, approve or rely on AI assistants, agents and connectors that read email, documents, web pages, tickets or a shared knowledge base. Complete 'Using AI assistants at work responsibly' first: it introduces prompt injection for all staff. This course goes further, for the people who decide what an AI tool can reach and do. You'll learn to recognise direct and indirect injection, including instructions people can't see; map a tool's untrusted inputs, data access and actions to find what an attacker could make it do; choose controls that limit the damage, since the UK NCSC and OWASP both say current models can't reliably separate instructions from data; test a tool safely with harmless canary instructions; and respond when an injection may have worked. Checking AI drafts and deciding what data may go into AI tools are covered in other courses. Your organisation's AI policy, approved-tools list and security testing rules govern what you may connect and test.

Level
Intermediate
Length
About 95 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify direct and indirect prompt injection in content an AI tool reads, including instructions people can't see
  • Map an AI tool's untrusted inputs, data access and actions to judge what an injected instruction could make it do
  • Choose controls that limit injection damage: least privilege, human approval of high-impact actions and treating model output as untrusted
  • Write safe test cases that use harmless canary instructions to check an AI tool's defences
  • Respond to a suspected prompt injection: contain the tool, preserve evidence and report it

Course outline

  1. 1.Identify direct and indirect prompt injection in content an AI tool readsLesson · 18 min
  2. 2.Map an AI tool's untrusted inputs, data access and actionsLesson · 20 min
  3. 3.Choose controls that limit injection damage: least privilege, human approval and untrusted outputLesson · 20 min
  4. 4.Write safe test cases with harmless canary instructionsLesson · 17 min
  5. 5.Respond to a suspected prompt injection: contain, preserve evidence and reportLesson · 12 min
  6. 6.AI prompt injection and untrusted content: assess, limit and test the risk: knowledge checkKnowledge check · 15 questions
  7. 7.AI prompt injection and untrusted content: assess, limit and test the risk: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.