{"id":32357,"date":"2026-09-15T16:50:49","date_gmt":"2026-09-15T16:50:49","guid":{"rendered":"https:\/\/thecloud.group\/?p=32357"},"modified":"2026-09-15T16:57:24","modified_gmt":"2026-09-15T16:57:24","slug":"prompt-injection-of-business-risk","status":"publish","type":"post","link":"https:\/\/thecloud.group\/en\/prompt-injection-riesgo-empresarial\/","title":{"rendered":"Prompt injection is not science fiction"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"32357\" class=\"elementor elementor-32357\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-cfd484e elementor-section-stretched elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cfd484e\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;stretch_section&quot;:&quot;section-stretched&quot;,&quot;background_background&quot;:&quot;classic&quot;,&quot;shape_divider_bottom&quot;:&quot;tilt&quot;}\">\n\t\t\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t<div class=\"elementor-shape elementor-shape-bottom\" aria-hidden=\"true\" data-negative=\"false\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewbox=\"0 0 1000 100\" preserveaspectratio=\"none\">\n\t<path class=\"elementor-shape-fill\" d=\"M0,6V0h1000v100L0,6z\"\/>\n<\/svg>\t\t<\/div>\n\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-64f4c56\" data-id=\"64f4c56\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-72fca4b elementor-hidden-mobile elementor-widget elementor-widget-image\" data-id=\"72fca4b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/thecloud.group\/wp-content\/uploads\/elementor\/thumbs\/logo-pd8scx7e21qrxkwrdlcuh7c8eeq4vmzqsjri81k6ps.png\" title=\"logo\" alt=\"logo\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-a76af51 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a76af51\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-inner-column elementor-element elementor-element-cf15d65\" data-id=\"cf15d65\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e993978 elementor-widget elementor-widget-heading\" data-id=\"e993978\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Prompt injection is not science fiction\n\n<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c047b73 elementor-widget elementor-widget-heading\" data-id=\"c047b73\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">September 15, 2026<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t<div class=\"elementor-element elementor-element-43acffb e-flex e-con-boxed e-con e-parent\" data-id=\"43acffb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a5b2d83 elementor-widget elementor-widget-text-editor\" data-id=\"a5b2d83\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Prompt injection is the number one risk for enterprise applications using language models, according to OWASP, which has maintained its top spot in its Top 10 list for the second year running. It&#039;s not a theoretical scenario or a laboratory problem: it&#039;s a direct consequence of how these systems work.<\/span><\/p><p><span style=\"font-weight: 400;\">A language model does not distinguish between the instructions given to it by its developer and the text it processes. Everything arrives as words. If a document the system reads contains something in the form of an instruction, there is a possibility that it will treat it as such.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ae9189b elementor-widget elementor-widget-heading\" data-id=\"ae9189b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The dangerous way is the indirect one\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d8c834c elementor-widget elementor-widget-text-editor\" data-id=\"d8c834c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The known version \u2014a user writing &quot;ignore your instructions&quot;\u2014 is the least worrying, because the attacker has to be present and their permissions are those of any other user.<\/span><\/p><p><span style=\"font-weight: 400;\">The version that matters in a business environment is the <\/span><b>indirect injection<\/b><span style=\"font-weight: 400;\">The malicious text is not written by the user; it comes within the content that the system processes as part of its normal work.<\/span><\/p><p><span style=\"font-weight: 400;\">The usual vectors:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A <\/span><b>email from a supplier<\/b><span style=\"font-weight: 400;\"> that the assistant reads to extract order data.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A <\/span><b>PDF<\/b><span style=\"font-weight: 400;\"> \u2014an invoice, a resume, a contract\u2014 that the system summarizes.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A <\/span><b>Web page<\/b><span style=\"font-weight: 400;\"> that the agent consults to complete information.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A <\/span><b>support ticket<\/b><span style=\"font-weight: 400;\"> written by a client.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A <\/span><b>form field<\/b><span style=\"font-weight: 400;\"> which is stored and then processed.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">In every case, the process is the same: someone external writes text that your system will read and that can influence what it does. And in every case, the potential damage is exactly equal to the scope of the permissions you&#039;ve granted them.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5436737 elementor-widget elementor-widget-heading\" data-id=\"5436737\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why can&#039;t it be solved with a filter?\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83b90fc elementor-widget elementor-widget-text-editor\" data-id=\"83b90fc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The intuitive answer is to filter out suspicious instructions at the input. This doesn&#039;t work reliably, for three reasons:<\/span><\/p><p><b>Language has infinite forms.<\/b><span style=\"font-weight: 400;\"> Any list of prohibited patterns can be rephrased. The instruction can be in another language, paraphrased, or broken down into several sentences.<\/span><\/p><p><b>It may be hidden.<\/b><span style=\"font-weight: 400;\"> Blank text on a blank page in a PDF, metadata, content that the user doesn&#039;t see but the system does read.<\/span><\/p><p><b>The filter cannot know the intention.<\/b><span style=\"font-weight: 400;\"> A legitimate email might contain the phrase &quot;please forward this to accounting.&quot; The system has no robust way of deciding whether that&#039;s an instruction for itself or information for a person.<\/span><\/p><p><span style=\"font-weight: 400;\">The operational conclusion is both uncomfortable and clarifying: <\/span><b>We have to assume that the injection will happen and design so that it doesn&#039;t matter<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-248d3ff elementor-widget elementor-widget-heading\" data-id=\"248d3ff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The design that contains the problem\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e78ab64 elementor-widget elementor-widget-text-editor\" data-id=\"e78ab64\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><thead><tr><th><p><b>Principle<\/b><\/p><\/th><th><p><b>What does it involve?<\/b><\/p><\/th><th><p><b>What it prevents<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><b>Minimum permit<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">The system only accesses what its specific task requires<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">That an injected instruction reaches external data<\/span><\/p><\/td><\/tr><tr><td><p><b>Channel separation<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">External content is never treated as a system instruction<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Let a PDF redefine behavior<\/span><\/p><\/td><\/tr><tr><td><p><b>Whitelist of shares<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Only explicitly listed operations are permitted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">That something unforeseen happens<\/span><\/p><\/td><\/tr><tr><td><p><b>Human validation in the irreversible<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Payments, external communications, production changes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">That the damage materializes without review<\/span><\/p><\/td><\/tr><tr><td><p><b>Full registration<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">It records what was entered and what was executed.<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">That the incident is irreparable<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9f96e4f elementor-widget elementor-widget-text-editor\" data-id=\"9f96e4f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">These five are architectural decisions, not tool configurations. And all five cost little if made before building, which is why this article belongs more to a design conversation than a security one.<\/span><\/p><p><span style=\"font-weight: 400;\">OWASP adds two related risks to this table that should be mentioned: <\/span><b>LLM02, disclosure of sensitive information<\/b><span style=\"font-weight: 400;\">, and <\/span><b>LLM06, excess capacity<\/b><span style=\"font-weight: 400;\">. The three present the same problem viewed from different angles: what the system can read, what it can do, and who can influence it. We have developed this in <\/span><a href=\"https:\/\/thecloud.group\/en\/permits-agents-at-risk\/\"><span style=\"font-weight: 400;\">Granting permissions to an agent is a risky decision<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8d84080 elementor-widget elementor-widget-heading\" data-id=\"8d84080\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The case worth keeping in mind\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c2cc72e elementor-widget elementor-widget-text-editor\" data-id=\"c2cc72e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Imagine an assistant that processes invoices arriving in the administration email: it extracts the amount, supplier, and account number, and prepares the payment.<\/span><\/p><p><span style=\"font-weight: 400;\">A fraudulent supplier sends an invoice that includes a small instruction at the bottom to the system to use a different account number. If the assistant has permission to prepare payments and no one verifies the account number against the supplier&#039;s record, the fraud is executed with the efficiency of an automated system.<\/span><\/p><p><span style=\"font-weight: 400;\">Note that in this example the model hasn&#039;t failed: it has done exactly what a text asked it to. The flaw lies in the design, which allowed an external text to determine a critical piece of information without verifying it against the source of truth.<\/span><\/p><p><span style=\"font-weight: 400;\">Hence the rule we repeat in every project: <\/span><b>The model drafts and interprets; the system decides the facts.<\/b><span style=\"font-weight: 400;\">. Amounts, accounts, statuses, and permissions are checked against the source system; they are never accepted from processed content.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-665a6ca elementor-widget elementor-widget-heading\" data-id=\"665a6ca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What to ask a supplier\n\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-539ec89 elementor-widget elementor-widget-text-editor\" data-id=\"539ec89\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">When someone presents an AI-powered solution that reads external content, three questions separate the serious from the improvised:<\/span><\/p><ol><li><b> <\/b><b>What happens if the document being processed contains instructions directed to the system?<\/b><span style=\"font-weight: 400;\"> A good response describes restraint, not denial of the problem.<\/span><\/li><li><b> <\/b><b>What can the system do in the worst-case scenario?<\/b><span style=\"font-weight: 400;\"> There must be a closed list of shares and a limit on the amount or volume.<\/span><\/li><li><b> <\/b><b>Could you reconstruct an incident from a month ago?<\/b><span style=\"font-weight: 400;\"> If there is no record of entries and actions, there is no way to investigate anything.<\/span><\/li><\/ol><p><span style=\"font-weight: 400;\">A provider who responds &quot;our model doesn&#039;t fall into that trap&quot; hasn&#039;t grasped the risk. Containment doesn&#039;t depend on the quality of the model, it depends on the scope that has been granted to it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e26b29f elementor-widget elementor-widget-heading\" data-id=\"e26b29f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Frequently Asked Questions\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0bafad2 e-flex e-con-boxed e-con e-parent\" data-id=\"0bafad2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-255e77a elementor-widget elementor-widget-n-accordion\" data-id=\"255e77a\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;expanded&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3910\" class=\"e-n-accordion-item\" open>\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"true\" aria-controls=\"e-n-accordion-item-3910\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> What is prompt injection? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3910\" class=\"elementor-element elementor-element-5b9195b e-con-full e-flex e-con e-child\" data-id=\"5b9195b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-128178a elementor-widget elementor-widget-text-editor\" data-id=\"128178a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">It is the manipulation of a language model&#039;s behavior through text that the model processes as if it were instructions. OWASP ranks it as the top risk in its Top 10 for LLM applications by 2025, because the model does not structurally distinguish between the developer&#039;s instructions and the content it analyzes.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3911\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-3911\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> What is indirect prompt injection? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3911\" class=\"elementor-element elementor-element-0fc0d7e e-con-full e-flex e-con e-child\" data-id=\"0fc0d7e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fff5b06 elementor-widget elementor-widget-text-editor\" data-id=\"fff5b06\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This is the relevant variant in business environments: the instructions are not written by the user, but come within the content that the system routinely processes \u2014 a supplier email, a PDF, a web page, a support ticket, or a form field.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3912\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-3912\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> Can prompt injection be prevented with input filters? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3912\" class=\"elementor-element elementor-element-1872c91 e-con-full e-flex e-con e-child\" data-id=\"1872c91\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-64a1d1a elementor-widget elementor-widget-text-editor\" data-id=\"64a1d1a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Not reliably. Language allows for infinite reformulations, instructions can be hidden in invisible text or metadata, and a filter cannot determine intent. The correct approach is to assume it will happen and limit the potential harm through permissions and controls.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3913\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-3913\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> How does a company protect itself against prompt injection? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3913\" class=\"elementor-element elementor-element-69dc4e1 e-con-full e-flex e-con e-child\" data-id=\"69dc4e1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-770ee8f elementor-widget elementor-widget-text-editor\" data-id=\"770ee8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">With five design principles: minimum permission per task, separation between external content and system instructions, whitelist of allowed actions, mandatory human validation in irreversible operations, and complete logging of inputs and actions performed.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3914\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-3914\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> Can an email or an invoice manipulate an AI system? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3914\" class=\"elementor-element elementor-element-b0eb544 e-con-full e-flex e-con e-child\" data-id=\"b0eb544\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-aa43162 elementor-widget elementor-widget-text-editor\" data-id=\"aa43162\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, if the system processes them and has broad permissions. The typical example is an invoice that includes an instruction to change the payment account number. The problem isn&#039;t with the model itself, but with the design that allows external text to determine critical data without verifying it against the source.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-3915\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-3915\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> What should you ask a supplier about this risk? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-plus\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-3915\" class=\"elementor-element elementor-element-394892d e-con-full e-flex e-con e-child\" data-id=\"394892d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6b896dc elementor-widget elementor-widget-text-editor\" data-id=\"6b896dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">What happens if the processed content includes instructions directed at the system? What can the system do in the worst-case scenario? And could an incident that occurred a month ago be reconstructed? An answer that denies the possibility of an attack indicates a lack of awareness of the risk.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-62494f1 elementor-widget elementor-widget-text-editor\" data-id=\"62494f1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Does your AI system read content written by third parties?<\/b><span style=\"font-weight: 400;\"> We review scope, permissions, channel separation, and traceability, and tell you what the worst possible scenario is with the current design. <\/span><a href=\"https:\/\/thecloud.group\/en\/technology-consulting\/\"><span style=\"font-weight: 400;\">Request a review \u2192<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2776e2f e-con-full e-flex e-con e-child\" data-id=\"2776e2f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-313fb2f elementor-widget elementor-widget-image\" data-id=\"313fb2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\" class=\"elementor-animation-hang attachment-large size-large wp-image-32359\" alt=\"Prompt injection attack against an enterprise Artificial Intelligence system\" srcset=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg 1024w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609-300x300.jpeg 300w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609-150x150.jpeg 150w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609-768x768.jpeg 768w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609-12x12.jpeg 12w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5d096db elementor-widget elementor-widget-image\" data-id=\"5d096db\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218.jpeg\" class=\"elementor-animation-hang attachment-large size-large wp-image-32293\" alt=\"Development using vibe coding and code generated with Artificial Intelligence\" srcset=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218.jpeg 1024w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218-300x300.jpeg 300w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218-150x150.jpeg 150w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218-768x768.jpeg 768w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/08\/Vibe_coding_creating_product_code_202608262218-12x12.jpeg 12w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f22134d elementor-widget elementor-widget-image\" data-id=\"f22134d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443.jpeg\" class=\"elementor-animation-hang attachment-large size-large wp-image-32015\" alt=\"Composable architecture for businesses with modular applications, APIs, and AI-powered systems integration.\" srcset=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443.jpeg 1024w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443-300x300.jpeg 300w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443-150x150.jpeg 150w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443-768x768.jpeg 768w, https:\/\/thecloud.group\/wp-content\/uploads\/2026\/07\/Futuristic_office_building_modul\u2026_202607281443-12x12.jpeg 12w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>In the vast digital landscape of the 21st century, security is the cornerstone of any business. Cybersecurity vulnerabilities make no distinction between corporate giants and promising startups.<\/p>","protected":false},"author":20,"featured_media":32359,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[859],"tags":[896,883],"class_list":["post-32357","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-ia","tag-producto-digital","tag-sistemas-empresariales"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Prompt injection no es ciencia ficci\u00f3n The Cloud Group<\/title>\n<meta name=\"description\" content=\"C\u00f3mo digitalizamos el archivo del Parlamentode Guinea Ecuatorial: alcance, retost\u00e9cnicos, soluci\u00f3n y resultado. Caso real publicado.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/thecloud.group\/en\/prompt-injection-of-business-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Prompt injection no es ciencia ficci\u00f3n\" \/>\n<meta property=\"og:description\" content=\"Descubre art\u00edculos sobre desarrollo de software a medida, automatizaci\u00f3n empresarial, inteligencia artificial, ERP, CRM, aplicaciones web y transformaci\u00f3n digital para empresas.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/thecloud.group\/en\/prompt-injection-of-business-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"The Cloud Group\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/thecloudgroupglobal\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T16:50:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T16:57:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Paula Franco\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thecloudgroup\" \/>\n<meta name=\"twitter:site\" content=\"@thecloudgroup\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Paula Franco\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/\"},\"author\":{\"name\":\"Paula Franco\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/#\\\/schema\\\/person\\\/9292d905a1c98ea7345e5e71a5fe341f\"},\"headline\":\"Prompt injection no es ciencia ficci\u00f3n\",\"datePublished\":\"2026-09-15T16:50:49+00:00\",\"dateModified\":\"2026-09-15T16:57:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/\"},\"wordCount\":1643,\"publisher\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\",\"keywords\":[\"producto digital\",\"sistemas empresariales\"],\"articleSection\":[\"Data &amp; IA\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/\",\"url\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/\",\"name\":\"Prompt injection no es ciencia ficci\u00f3n The Cloud Group\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\",\"datePublished\":\"2026-09-15T16:50:49+00:00\",\"dateModified\":\"2026-09-15T16:57:24+00:00\",\"description\":\"C\u00f3mo digitalizamos el archivo del Parlamentode Guinea Ecuatorial: alcance, retost\u00e9cnicos, soluci\u00f3n y resultado. Caso real publicado.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#primaryimage\",\"url\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\",\"contentUrl\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Prompt_injection_no_es_ficcion_20260915115609.jpeg\",\"width\":1024,\"height\":1024,\"caption\":\"Un agente de IA conectado a sistemas reales tambi\u00e9n puede ser manipulado mediante instrucciones maliciosas.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/prompt-injection-riesgo-empresarial\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/thecloud.group\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Prompt injection no es ciencia ficci\u00f3n\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/#website\",\"url\":\"https:\\\/\\\/thecloud.group\\\/\",\"name\":\"The Cloud Group\",\"description\":\"Empresa especializada en desarrollo de software a medida, automatizaci\u00f3n empresarial e inteligencia artificial para empresas.\",\"publisher\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/#organization\"},\"alternateName\":\"TCG Software\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/thecloud.group\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/#organization\",\"name\":\"The Cloud Group\",\"alternateName\":\"TCG\",\"url\":\"https:\\\/\\\/thecloud.group\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/logoSmallFirmaCorreo.png\",\"contentUrl\":\"https:\\\/\\\/thecloud.group\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/logoSmallFirmaCorreo.png\",\"width\":300,\"height\":190,\"caption\":\"The Cloud Group\"},\"image\":{\"@id\":\"https:\\\/\\\/thecloud.group\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/thecloudgroupglobal\",\"https:\\\/\\\/x.com\\\/thecloudgroup\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/the-cloud-group\",\"https:\\\/\\\/www.instagram.com\\\/thecloudgroupglobal\",\"https:\\\/\\\/www.youtube.com\\\/@TheCloudGroup\"],\"description\":\"The Cloud Group es una empresa internacional especializada en desarrollo de software a medida, automatizaci\u00f3n empresarial, inteligencia artificial, ERP, CRM, aplicaciones web y m\u00f3viles y transformaci\u00f3n digital. Ayudamos a empresas a optimizar procesos, reducir costos y acelerar su crecimiento mediante soluciones tecnol\u00f3gicas personalizadas.\",\"email\":\"paula.franco@thecloud.group\",\"telephone\":\"3042544988\",\"legalName\":\"THE CLOUD COLOMBIA SAS\",\"vatID\":\"902084280\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/thecloud.group\\\/#\\\/schema\\\/person\\\/9292d905a1c98ea7345e5e71a5fe341f\",\"name\":\"Paula Franco\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g\",\"caption\":\"Paula Franco\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Prompt injection is not science fiction. The Cloud Group","description":"How we digitized the archive of the Parliament of Equatorial Guinea: scope, technical challenges, solution and result. Real case published.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/thecloud.group\/en\/prompt-injection-of-business-risk\/","og_locale":"en_US","og_type":"article","og_title":"Prompt injection no es ciencia ficci\u00f3n","og_description":"Descubre art\u00edculos sobre desarrollo de software a medida, automatizaci\u00f3n empresarial, inteligencia artificial, ERP, CRM, aplicaciones web y transformaci\u00f3n digital para empresas.","og_url":"https:\/\/thecloud.group\/en\/prompt-injection-of-business-risk\/","og_site_name":"The Cloud Group","article_publisher":"https:\/\/www.facebook.com\/thecloudgroupglobal","article_published_time":"2026-09-15T16:50:49+00:00","article_modified_time":"2026-09-15T16:57:24+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg","type":"image\/jpeg"}],"author":"Paula Franco","twitter_card":"summary_large_image","twitter_creator":"@thecloudgroup","twitter_site":"@thecloudgroup","twitter_misc":{"Written by":"Paula Franco","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#article","isPartOf":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/"},"author":{"name":"Paula Franco","@id":"https:\/\/thecloud.group\/#\/schema\/person\/9292d905a1c98ea7345e5e71a5fe341f"},"headline":"Prompt injection no es ciencia ficci\u00f3n","datePublished":"2026-09-15T16:50:49+00:00","dateModified":"2026-09-15T16:57:24+00:00","mainEntityOfPage":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/"},"wordCount":1643,"publisher":{"@id":"https:\/\/thecloud.group\/#organization"},"image":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#primaryimage"},"thumbnailUrl":"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg","keywords":["producto digital","sistemas empresariales"],"articleSection":["Data &amp; IA"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/","url":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/","name":"Prompt injection is not science fiction. The Cloud Group","isPartOf":{"@id":"https:\/\/thecloud.group\/#website"},"primaryImageOfPage":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#primaryimage"},"image":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#primaryimage"},"thumbnailUrl":"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg","datePublished":"2026-09-15T16:50:49+00:00","dateModified":"2026-09-15T16:57:24+00:00","description":"How we digitized the archive of the Parliament of Equatorial Guinea: scope, technical challenges, solution and result. Real case published.","breadcrumb":{"@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#primaryimage","url":"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg","contentUrl":"https:\/\/thecloud.group\/wp-content\/uploads\/2026\/09\/Prompt_injection_no_es_ficcion_20260915115609.jpeg","width":1024,"height":1024,"caption":"Un agente de IA conectado a sistemas reales tambi\u00e9n puede ser manipulado mediante instrucciones maliciosas."},{"@type":"BreadcrumbList","@id":"https:\/\/thecloud.group\/prompt-injection-riesgo-empresarial\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/thecloud.group\/"},{"@type":"ListItem","position":2,"name":"Prompt injection no es ciencia ficci\u00f3n"}]},{"@type":"WebSite","@id":"https:\/\/thecloud.group\/#website","url":"https:\/\/thecloud.group\/","name":"The Cloud Group","description":"Company specializing in custom software development, business automation and artificial intelligence for businesses.","publisher":{"@id":"https:\/\/thecloud.group\/#organization"},"alternateName":"TCG Software","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/thecloud.group\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/thecloud.group\/#organization","name":"The Cloud Group","alternateName":"TCG","url":"https:\/\/thecloud.group\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/thecloud.group\/#\/schema\/logo\/image\/","url":"https:\/\/thecloud.group\/wp-content\/uploads\/2020\/05\/logoSmallFirmaCorreo.png","contentUrl":"https:\/\/thecloud.group\/wp-content\/uploads\/2020\/05\/logoSmallFirmaCorreo.png","width":300,"height":190,"caption":"The Cloud Group"},"image":{"@id":"https:\/\/thecloud.group\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/thecloudgroupglobal","https:\/\/x.com\/thecloudgroup","https:\/\/www.linkedin.com\/company\/the-cloud-group","https:\/\/www.instagram.com\/thecloudgroupglobal","https:\/\/www.youtube.com\/@TheCloudGroup"],"description":"The Cloud Group is an international company specializing in custom software development, business automation, artificial intelligence, ERP, CRM, web and mobile applications, and digital transformation. We help companies optimize processes, reduce costs, and accelerate their growth through customized technology solutions.","email":"paula.franco@thecloud.group","telephone":"3042544988","legalName":"THE CLOUD COLOMBIA SAS","vatID":"902084280"},{"@type":"Person","@id":"https:\/\/thecloud.group\/#\/schema\/person\/9292d905a1c98ea7345e5e71a5fe341f","name":"Paula Franco","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8622dc6801e07daa51e09fd706fb55b2bdf9cada1ade4ab996fb3b4549e9214c?s=96&d=mm&r=g","caption":"Paula Franco"}}]}},"_links":{"self":[{"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/posts\/32357","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/comments?post=32357"}],"version-history":[{"count":4,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/posts\/32357\/revisions"}],"predecessor-version":[{"id":32362,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/posts\/32357\/revisions\/32362"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/media\/32359"}],"wp:attachment":[{"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/media?parent=32357"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/categories?post=32357"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thecloud.group\/en\/wp-json\/wp\/v2\/tags?post=32357"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}