Intended use
Direct ask
| Variant | Related incident | Related paper |
|---|---|---|
| Single ask | INC-001GitHub’s Copilot reproduced a professor’s LGPL-licensed sparse-matrix code verbatim, stripping the license | |
| Long input | INC-015Sullivan & Cromwell apologized to a bankruptcy judge for AI hallucinations in a Chapter 15 filing | |
| Noisy or corrupted input | INC-019McDonald’s IBM-built AI drive-thru misinterpreted spoken orders, ending the trial |
Indirect ask
| Variant | Related incident | Related paper |
|---|---|---|
| Nonsensical input | ||
| Contradictory information | ||
| Implied context | ||
| Ambiguous intent | INC-044New York City’s MyCity business chatbot advised users to break the law | |
| Changing intent | ||
| Progressive disclosure | INC-013Air Canada’s chatbot invented a refund policy, and the airline was held liable |
Misuse (social engineering)
False scenario
| Variant | Related incident | Related paper |
|---|---|---|
| Feigned distress | ||
| Feigned frustration | ||
| False persona | INC-032Discord’s Clyde chatbot was tricked into outputting weapon instructions via a roleplay jailbreak | |
| Fabricated evidence |
Persuasion
| Variant | Related incident | Related paper |
|---|---|---|
| Moral reframing | INC-026Anthropic’s Claudius vending-machine agent was talked into zeroing prices and giving away inventory | |
| Incentive manipulation | INC-026Anthropic’s Claudius vending-machine agent was talked into zeroing prices and giving away inventory | |
| Trust building | INC-040OpenAI’s ChatGPT generated fake South Korean military ID images for a North Korean Kimsuky phishing campaign |
Conversational manipulation
| Variant | Related incident | Related paper |
|---|---|---|
| Confusion tactics | ||
| Insistence | INC-036DPD’s customer-service chatbot swore at a customer and disparaged the company |
Misuse (technical)
Direct injection
| Variant | Related incident | Related paper |
|---|---|---|
| Perturbation attacks | ||
| System message injection | INC-022Chevrolet of Watsonville’s ChatGPT-powered chatbot was manipulated into ‘selling’ a 76,000Tahoefor1 | |
| Ignore previous instructions | ||
| Delimiter injection | ||
| Special token injection | ||
| Context overflow | ||
| Bijection | ||
| Template mutation | ||
| Adversarial suffix | ||
| Best-of-N | ||
| Iterative rephrasing | ||
| Past tense | ||
| Future tense | ||
| Encoding attacks | INC-007Microsoft 365 Copilot was exploited via ASCII smuggling to exfiltrate user data |
Indirect injection
| Variant | Related incident | Related paper |
|---|---|---|
| Via data inputs | INC-028A malicious npm package posing as an OpenAI Codex UI exfiltrated developer authentication tokens INC-029A hidden prompt injection in a Word document turned Microsoft Copilot for Word into a self-propagating AI worm | |
| Via tool responses | INC-006Nx’s compromised npm package weaponized installed AI coding agents to exfiltrate developer credentials | |
| Via tasks |
37.782274° N -122.392147° WFIG. A (SITE INDEX)
Artificial Intelligence Underwriting Company
CodeStructural unita.AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.b.Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.c.Crosswalks to AI regulations, standards, and security frameworks.d.Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.
I. Standard
II. Learn
III. Office
100© AIUC — ALL RIGHTS RESERVED