Back to MITRE ATLAS View canonical source
MITRE ATLAS · AML.M0017
Prompt and content isolation
“Separate untrusted retrieved content from instruction context; enforce structured tool-call boundaries.”
ATLAS mitigation AML.M0017
deployment
Type
mitigation
Parent
—
Sub-items
0
Cross-framework relationships
Lattice uses an explicit, four-type vocabulary and refuses ‘equivalent.’ Each relationship below carries a rationale and an editorial reviewer credit.
informs
1- Risk responses plannedNIST AI RMF · MANAGE 1
NIST MANAGE 1 directs risk responses; ATLAS mitigation prompt-isolation is a concrete control candidate for prompt-injection responses.
Reviewer: Editorial: K. Park · Reviewed 2026-05-02
Version: Pinned 2026.Q1Last reviewed: 2026-05-02