A system prompt is the standing set of instructions an operator or developer puts in place before a conversation ever starts — setting a tool’s role, tone and boundaries — as distinct from whatever a user then types. Canada’s Cyber Centre uses the term directly in its own list of AI security actions, instructing organizations to “Isolate system prompts and protect prompt history” as part of guarding against prompt injection.
The Cyber Centre’s concern is a security one: if a system prompt is not isolated from what a user or an outside document can supply, an attacker can potentially overwrite the operator’s own instructions with their own, which is one shape of a prompt injection attack. Isolating it means the tool’s underlying role and rules cannot simply be talked away by whoever is typing into it.
What a system prompt actually does mechanically is easiest to see in a vendor’s own product documentation. Anthropic’s developer documentation for its Claude models describes it this way: “Setting a role in the system prompt focuses Claude’s behavior and tone for your use case.” That sentence describes one company’s product, not a Canadian standard, but the mechanism it describes generalizes across tools: a system prompt is written once by whoever sets the tool up, and it shapes every reply that follows until someone with access to configure the tool changes it.
A brokerage’s client-facing chat tool carries a system prompt telling it never to quote a rate and always to hand a client off to a licensed person before anything resembling advice is given. A client’s own typed question is a separate, second layer on top of that standing instruction — the client cannot see the system prompt and, if it is properly isolated in the sense the Cyber Centre describes, cannot simply ask the tool to ignore it either. A well-written system prompt narrows what the tool will attempt; it does not, on its own, stop the tool from getting a fact wrong within the boundaries it has been given — see AI hallucination.
See also prompt and prompt engineering.
This is one term in a plain-English glossary on how AI actually works and where it fits in a Canadian business.