Checked fact 100010 Oct 2026Safety and security
OpenAI's guide says: "Because developer messages take precedence over user and assistant messages, injecting untrusted input directly into developer messages gives attackers the highest degree of control."
The exact words it rests on
Because developer messages take precedence over user and assistant messages, injecting untrusted input directly into developer messages gives attackers the highest degree of control.
What the source said when we opened it, on 10 Oct 2026.
The source
Safety in building agents
Checked
Checked by the notis newsroom on , against the source above.
In the story
How prompt injection works and how to limit the damage 10 Oct 2026
Cite this fact
Anyone may quote this address. It does not change; if we correct the story, this page says so.