Applications that include features like AI-powered search, chatbots or content generators require a user prompt in addition to our developer-written system prompt. That means an external party also has the chance to give instructions to our model—and those instructions won’t always be aligned with what we want the model to do.