A language model can't reliably tell the difference between instructions from its owner and instructions that arrive inside the content it reads. Prompt injection exploits that: a user, or text the model processes, tells it to ignore its rules and do something else.
Direct injection comes from the person typing. Indirect injection hides in documents, web pages, emails or tool results the agent reads on someone's behalf — the user may never see it.
+Why it matters
Once an agent has tools and data access, a successful injection isn't a bad answer — it's an action taken with the agent's permissions.
+How Intertrace handles it
Instruction-override language is a structural floor that blocks on its own. Content the agent reads is inspected for hidden and model-addressed instructions, and tool calls are authorized before they run, so an injection that slips past detection still can't act outside policy.
+Keep reading
+ The AI watching your AI
See it on your own traffic.
Book a 30-minute risk assessment, or open the Simulation Lab and try it now.