Definition
A way of taking over an AI assistant by feeding it an entirely new set of instructions, rather than slipping one malicious line into content it reads. The attacker bypasses the assistant's normal conversation safeguards and speaks directly to the underlying system that carries out its actions, so there is no guardrail to fool. In a browser, one malicious add-on can silently do this to the built-in AI assistant, gaining control of local files, emails and passwords.
Why it matters
Attackers who can secretly command the AI your people already trust inherit every privilege that assistant holds — reading mail, browsing files, sending messages — with no extra hacking required.