Lesson 896 of 1455
AI and Hidden Instructions in Shared Documents
Why pasting a classmate's text into ChatGPT can hijack your AI session.
Builders · Safety & Governance · ~4 min read
The big idea
People can hide instructions in white text or document metadata that hijack AI when you paste their content. It's prompt injection — and it's already in classroom group projects.
Some examples
- A 'helpful summary' from a classmate makes ChatGPT lie to you.
- White-on-white text is invisible to you but readable to AI.
- PDFs and Google Docs both can hide injection payloads.
- Always paste suspect text into Notes first — it strips formatting.
Try it!
Copy any document you've received this week. Paste it into Notes or a plain-text editor and look for hidden white text.
Key terms in this lesson
Practice this safely
Try this with a school, hobby, or family example where the stakes are low. Use the AI output as a draft you can question, not as the final answer.
- 1Ask AI to explain prompt injection in plain language, then underline anything that sounds uncertain or too broad.
- 2Give it one detail from "AI and Hidden Instructions in Shared Documents" and ask for two possible next steps plus one reason each step might be wrong.
- 3Check invisible text against a trusted source, teacher, adult, expert, or original document before you use it.
End-of-lesson quiz
Check what stuck
8 questions · Score saves to your progress.
Lesson help
Questions are best handled with a grown-up here.
For this age range, Tendril keeps freeform AI chat paused until parent/guardian consent and child-safe moderation are fully verified. Use the quiz, notes, and related lessons below, or ask a parent, guardian, teacher, or librarian to work through the question with you.
Progress saved locally in this browser. Sign in to sync across devices.
Related lessons
Keep going
Builders · 26 min
AI and spotting jailbreak prompts: when a 'fun trick' is actually shady
Learn to recognize jailbreak prompts your friends paste so you don't help break the rules.
Builders · 7 min
AI and Dating App Catfish 2026: Spotting Generated Faces
AI faces on Tinder and Hinge passed the 2026 detector tests. Learn the four tells humans still beat machines on.
Adults & Professionals · 11 min
Prompt Injection Defense: Protecting AI Systems From Malicious Inputs
Prompt injection is the SQL injection of the AI era — and it's already being exploited in production systems. Defending against it requires multiple layers, not a single fix.
