AI and risk

ChatGPT Work meets the 3 conditions that make a prompt injection dangerous


Simon Willison reviewed the product and concluded it combines private data, untrusted content and the ability to act externally. There's no known defense.

September 3, 2026 · Translated from the Spanish original

What happened

Why it matters

The number

3 conditions. Private data, untrusted content and the ability to communicate externally. The risk appears when all three come together. With two, the attack doesn’t complete the circuit.

Context

Willison coined the term prompt injection in 2022 and described the lethal trifecta in June 2025. Since then he has documented cases in ChatGPT, Google Bard, Amazon Q, GitHub Copilot Chat, Microsoft Copilot, Slack, Mistral’s Le Chat and Claude’s iOS app, among others. The problem doesn’t belong to one brand; it belongs to the way these systems are built.

What’s next

Bottom line

The same week this architecture was documented, Anthropic warned that an attacker was getting into Claude accounts with stolen cookies. Two different routes to the same destination: the permission that had already been granted.

Sources

Related notes

← All notes