What matters in AI.

Subscribe

Learn / AI basics

Definition · AI basics

System prompt

A system prompt is the block of instructions an application places in a language model's context ahead of the conversation, setting the model's role, tone and constraints. The system prompt shapes behaviour through training-time preference rather than enforcement, so it is a configuration mechanism and not a security boundary.

Last reviewed

Key points

  • A system prompt is the instruction block an application puts in front of a language model, carrying its role, the context it cannot know, the format of its answers and its prohibitions.
  • A system prompt is configuration, not a security control. Its influence comes from training rather than enforcement, so a model can disregard it.
  • Nothing in a system prompt is secret. OWASP tells practitioners to assume it is discoverable, which rules out API keys, credentials and the application's permission structure.
  • The system prompt reaches the model as ordinary tokens alongside everything else. Whether an API carries it as a message or a parameter changes what a developer can express, not what the model sees.
  • In OpenAI's vocabulary a "system" message is OpenAI's own; an API caller writes at developer authority, one level below platform.

Almost every product built on a language model begins each conversation with text the person using it never sees. That text is the system prompt, and it is usually the largest single lever a developer has over how the product behaves.

The name misleads. “System” is borrowed from operating systems, where hardware enforces the line between system and user. Nothing enforces it here.

What a system prompt contains and how it reaches the model

A system prompt carries four kinds of content: role and voice; context the model cannot otherwise have, such as the date; format and tool discipline; and prohibitions. OpenAI’s text generation guide likens the developer message to a function definition and the user message to its arguments.

The model does not receive four fields. The prompt arrives as tokens in the same sequence as everything else, and only the interface varies. OpenAI’s 2023 ChatML preview renders a conversation as one flat token sequence with the system message a single entry among the user and assistant messages; Anthropic’s Messages API takes it as a top-level parameter and offers no "system" role for input messages. Either way the text lands in one context window, where a prohibition is the same kind of text as a formatting preference.

So a system prompt is configuration, not a security control. Its authority comes from training: the researchers who introduced the instruction hierarchy opened by noting that models often treat system prompts as the same priority as text from untrusted users. OWASP draws the line — do not rely on hidden context for authorization, privilege separation, policy enforcement or content filtering.

Where definitions disagree

Whose instructions count as “system”. OpenAI’s Model Spec reserves its top level, platform, for OpenAI’s own rules, and defines "system" as “messages added by OpenAI” against "developer" for messages “from the application developer”. An API caller writes at developer authority, one level down, whatever the parameter is called. Anthropic’s system parameter holds the caller’s own text.

Whether “the system prompt” is still the right unit. OWASP’s 2026 list retired System Prompt Leakage for hidden context exposure, which covers the system prompt, developer instructions, retrieved policy text and tool schemas together, because all of them fail the same way.

Questions and answers

Is a system prompt secret?

No. A system prompt should not be treated as secret. OWASP's GenAI Security Project tells practitioners to design on the assumption that hidden context is discoverable and that its contents should not be considered a secret. Anything that would cause harm if read, such as an API key or a description of who is allowed to do what, does not belong in one.

Can a system prompt stop prompt injection?

No. A system prompt cannot stop prompt injection, because the instruction telling the model to ignore injected text arrives through the same channel as the injected text and carries no privilege the model can enforce. A system prompt can make an attack less likely to succeed on the first attempt. It cannot make the attack impossible.

What is the difference between a system prompt and a user prompt?

A system prompt comes from the developer who built the application and is usually fixed across every conversation. A user prompt comes from the person using it and changes every turn. Model providers train models to give the developer's instructions more weight when the two conflict, but the two are the same kind of text and neither is privileged in a way the running model can enforce.

Is a developer message the same as a system prompt?

Broadly yes, with one distinction worth knowing. OpenAI's Model Spec reserves the highest authority level, called platform, for OpenAI's own instructions, and places instructions from developers using the API one level below it. So a developer message is the highest-authority text an API caller can write, which is not the same as the highest-authority text in the system.

Sources

  1. Chat Markup Language (ChatML v0)OpenAI, 1 Mar 2023
  2. Messages API referenceAnthropic
  3. OpenAI Model SpecOpenAI, 11 Apr 2025
  4. Text generation guideOpenAI
  5. The Instruction Hierarchy, Training LLMs to Prioritize Privileged InstructionsarXiv, 19 Apr 2024
  6. LLM08:2026 Hidden Context ExposureOWASP GenAI Security Project
  7. LLM00:2026 Preface, Letter from the Project LeadsOWASP GenAI Security Project
  8. LLM07:2025 System Prompt LeakageOWASP GenAI Security Project

Guides that use this term

In the news