How Google Workspace with Gemini helps to protect users from malicious content and prompt injection

Learn how Google Workspace with Gemini helps to protect users from malicious content and prompt injection attacks.

Malicious content and prompt injection in generative AI

Similar to email and content threats like malware and phishing attacks, security threats can target generative AI tools. Prompt injection is an attempt to elicit an unintended or harmful response from generative AI tools. Attackers may commit prompt injection by directly submitting queries. They may also share malicious content with a user who then unintentionally references this malicious content in prompts in generative AI tools like Gemini Apps or Google Workspace with Gemini.

To help protect Gemini users, Google uses advanced security measures to identify risky and suspicious content.

How Google detects malicious content and prompt injection

To help protect you from malicious content and prompt injection, Gemini in Workspace may filter or block some responses if malicious activity is detected.

When Gemini identifies activity related to a prompt that may be malicious

  • Gemini in Workspace warns you that the content has security risks.
  • In some instances, none of your content will be used to generate a response.
  • In other instances, only some of your content will be used to generate a response, with the malicious content excluded by Gemini.

For example, if you ask Gemini in Gmail to summarise email messages and one of those messages has malicious content, Gemini may not respond to your prompt for safety reasons.

Help to avoid unsafe content

Pay attention when interacting with content from someone who you don't know

  • Take notice of warnings from Google on content that you receive in other tools like Gmail.
  • Avoid clicking links from untrustworthy sources.
  • Use caution when interacting with shared content from unknown senders, like files in Drive.

Report malicious messages in Gmail

If you get a deceptive message or URL in Gmail, you can report it as phishing. Phishing is an attempt to steal personal information using deceptive emails, messages, ads or websites that appear legitimate. For example, a phishing email may look as though it's from your bank and request private information about your bank account. Learn how to report phishing in Gmail.

Report malicious documents in Docs editors

If you get malicious documents, files, images and other content in Docs editors, you can report them. Learn how to report abusive content.

Report malicious behaviour in Gemini in Workspace apps

If you get a response that's inaccurate or that you feel is unsafe, you can give feedback on that response to let us know. Learn how to report abuse in Gemini in Workspace apps.

Related resources

Search
Clear search
Close search
Google apps
Main menu
15457457702912733569
true
Search Help Centre
false
true
true
true
true
true
99950
false
false
false
false
false