A document is more than a visible page

What you see on screen is one rendering of a file. Depending on its format, the underlying document may also contain text objects, annotations, optional layers, metadata, links, attachments or active features.

These structures often support accessibility, review and navigation. They also create a difference between the page a person sees and the material software may be able to read.

Extraction creates the AI-facing version

AI tools commonly process a document through a parser, converter or retrieval pipeline. That process decides which text and structures become model-readable context.

A parser may extract content that is not prominent in the rendered page. It may also remove layout cues that helped a person distinguish a footnote, annotation or quoted example from the main text.

Evidence and instructions arrive together

Once extracted, legitimate evidence and instruction-like content can enter the same context window. A project prompt may ask for a summary while the source contains language telling the AI to change its behaviour.

Both are expressed in natural language. That ambiguity is why indirect prompt injection is not simply a matter of filtering one forbidden phrase.

Influence can outlast the first response

The immediate effect might be a distorted summary, omitted warning or altered recommendation. In a persistent project, the affected output may then be saved into notes, incorporated into later work or used to trigger another tool.

The severity depends on the system’s permissions. An AI that can only draft text presents a different risk from one allowed to modify files, send messages or call services.

Break the chain before intake

SourceReady addresses the first boundary. It checks supported document surfaces before they become project context, then gives you a Ready or Held result and the evidence needed for the next step.

  • Scan the outside document before adding it.
  • Hold documents with findings or incomplete required checks.
  • Review findings alongside coverage and limits.
  • Limit the destination AI to the permissions it needs.
  • Require human approval before consequential actions.

Sources and further reading

Primary guidance used to check the technical claims in this article.