Learn how Google Workspace with Gemini helps to protect users from malicious content and prompt injection attacks.
Malicious content and prompt injection in generative AI
Similar to email and content threats like malware and phishing attacks, security threats can target generative AI tools. Prompt injection is an attempt to elicit an unintended or harmful response from generative AI tools. Attackers may commit prompt injection by directly submitting queries. They may also share malicious content with a user who then unintentionally references this malicious content in prompts in generative AI tools like Gemini Apps or Google Workspace with Gemini.
To help protect Gemini users, Google uses advanced security measures to identify risky and suspicious content.
How Google detects malicious content and prompt injection
To help protect you from malicious content and prompt injection, Gemini in Workspace may filter or block some responses if malicious activity is detected.
When Gemini identifies activity related to a prompt that may be malicious
- Gemini in Workspace warns you that the content has security risks.
- In some instances, none of your content will be used to generate a response.
- In other instances, only some of your content will be used to generate a response, with the malicious content excluded by Gemini.
For example, if you ask Gemini in Gmail to summarise email messages and one of those messages has malicious content, Gemini may not respond to your prompt for safety reasons.
Help to avoid unsafe content
Pay attention when interacting with content from someone who you don't know
- Take notice of warnings from Google on content that you receive in other tools like Gmail.
- Avoid clicking links from untrustworthy sources.
- Use caution when interacting with shared content from unknown senders, like files in Drive.
Report malicious messages in Gmail
If you get a deceptive message or URL in Gmail, you can report it as phishing. Phishing is an attempt to steal personal information using deceptive emails, messages, ads or websites that appear legitimate. For example, a phishing email may look as though it's from your bank and request private information about your bank account. Learn how to report phishing in Gmail.
Report malicious documents in Docs editors
If you get malicious documents, files, images and other content in Docs editors, you can report them. Learn how to report abusive content.
Report malicious behaviour in Gemini in Workspace apps
If you get a response that's inaccurate or that you feel is unsafe, you can give feedback on that response to let us know. Learn how to report abuse in Gemini in Workspace apps.