Signal
Treat every pasted file like it can fight back
AI can't tell your notes from a vendor's marketing. A three-line header before you paste changes what it treats as fact.
The move Before pasting mixed sources into AI, add a three-line header that labels what is trusted, what is not, and what the model is allowed to do with each.
The short version: When you paste a vendor PDF, a client email, and your own notes into the same prompt, AI treats all of it as equally reliable. Your draft quotes vendor marketing with the same confidence as your own analysis. A thirty-second labeling header changes what AI treats as fact versus what it flags for you to check.
OpenAI published a security incident writeup last month about interactions involving content on Hugging Face. The details are for security teams. The part that matters to your Tuesday is simpler.
When you paste a vendor PDF, a client email, and your own notes into the same prompt, AI treats all of it as equally reliable. Your draft quotes vendor marketing with the same confidence as your own analysis. Not because the model is broken. Because nothing told it which source was vetted and which was not.
The issue is not your prompt wording. It's the missing boundary. Treat every pasted file like it can fight back.
The header
Before drafting from mixed sources, paste a three-line header above your material:
TRUSTED (my notes, verified data): [paste here]
UNTRUSTED (vendor claims, forwarded material): [paste here]
ALLOWED ACTION: Draft from trusted sources. Flag anything from untrusted sources as unverified.
Why this helps: your draft pulls from your analysis and treats outside claims as input to question, not facts to repeat.
The catch
AI labels what you tell it to label. Whether the vendor's number is real is still yours to check.
What to skip this week
The takes that treat this writeup as proof AI security is fundamentally broken. For most knowledge workers, the takeaway is not a policy overhaul. It's one labeling habit before you paste.
Take the Quiz