It is the closest thing an application has to configuration for a model, and it is ordinary text in the same context window as everything else. Models are trained to weight it more heavily than the conversation, which is why it usually works — and why "usually" is the accurate word.
Two mistakes are common. The first is treating it as a security boundary: it is a strong suggestion, not a permission system, and an instruction not to reveal something is not a control that prevents revealing it. The second is putting secrets in it. Anything in the system prompt was sent to a third-party API and can be coaxed back out; credentials belong in the tool layer, where the model asks for an action and never sees the key.
Related terms
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
Context window
The maximum amount of text a model can take into account at once, counting the instructions, the conversation and the answer together.
AI agent
A language model given tools it can call and a goal to pursue, so it decides the steps rather than following a fixed script.
The bench this belongs to
AI automationThe repetitive half of your week, handed to software that does not get bored. Inbox triage, follow-ups, reporting, data entry between tools that were never meant to talk.
