The email that talks to your assistant
Your AI assistant summarises an inbox, and one message contains instructions aimed at it, not you. See indirect prompt injection do its work.
AI is already in the inbox, the code editor, and the browser. These exercises teach the new failure modes: what an assistant will do if a web page tells it to, what leaves the building when someone pastes a contract into a chatbot, and how much an agent should be trusted to act on its own.
Your AI assistant summarises an inbox, and one message contains instructions aimed at it, not you. See indirect prompt injection do its work.
A deadline is close, so source code and a customer list go into a public assistant. Understand where that data goes and why it may not come back.
A free extension promises to write your replies and reads every page you open. Weigh the offer against what it quietly takes.
An AI agent can read mail, send mail, and move files. Decide the reach it actually needs before a clever prompt uses the rest.
An assistant gives a policy citation that does not exist. Build the habit of checking before you act on generated text.
A model learns from user uploads, and someone feeds it exactly what they want it to repeat. See a poisoning attempt take shape.
A finance approval comes from a face and voice you know, on a call. Learn the tells and the call-back rule that beats a convincing fake.
An API key goes into a prompt to "help the model help you". Understand why the prompt is not a safe place for a secret.