Found in AI Ep 44: OpenAI’s Prompt Injection Framework and Google’s Personal Intelligence

This week brought two major AI updates that, on the surface, look like they’re about very different things: OpenAI’s Prompt Injection Framework and Google’s Personal Intelligence. But when you look at them together, they tell a much bigger story about where AI search is heading — and what it means for content strategy.

On March 11, OpenAI published a detailed framework on how they’re designing AI agents to resist prompt injection attacks. And on March 17, Google announced the expansion of Personal Intelligence across AI Mode in Search, the Gemini app, and Gemini in Chrome.

Both updates point to the same conclusion: AI systems are getting smarter about trust. And the brands that earn that trust — through clear content, consistent authority, and real relationships with their audience — are the ones that will stay visible.

OpenAI’s Prompt Injection Framework: What It Is and Why Marketers Should Care

What Is Prompt Injection?

Prompt injection is when someone hides instructions inside external content—a webpage, an email, a shared document—with the goal of making an AI agent follow those instructions instead of doing what the user actually asked.

Think of it as social engineering, but targeting AI systems instead of humans. And as AI agents become more capable of browsing the web, managing emails, and taking actions on behalf of users, the attack surface grows.

OpenAI shared a real example from their internal testing: a malicious email was planted in a user’s inbox. When the user asked ChatGPT’s Atlas agent to draft an out-of-office reply, the agent followed the hidden instructions in the email instead and composed a resignation letter to the user’s CEO. The out-of-office reply was never written.

How OpenAI Is Responding

Rather than treating prompt injection as a problem that can be “solved,” OpenAI is framing it as an ongoing threat—comparable to social engineering and online scams. Their approach focuses on designing systems so that even if an attack partially succeeds, the consequences stay contained.

OpenAI’s defensive strategy includes several layers:

  • Constraining agent capabilities so that even successful manipulation has limited impact
  • Requiring user confirmation before consequential actions like sending emails or completing purchases
  • Building an automated red teaming system — an AI-powered attacker trained with reinforcement learning to find new prompt injection vulnerabilities before bad actors do
  • Rolling out stress-tested model updates to all ChatGPT Atlas users based on newly discovered attack patterns

The key takeaway from OpenAI’s announcement is that these systems are being trained to be increasingly skeptical of the content they encounter on the open web. And that skepticism has direct implications for how brands think about content.

What This Means for Content Strategy

If AI agents are being trained to resist manipulative content, the question for marketers becomes: what does “trustworthy content” look like to these systems?

It looks like content that is clearly structured and easy for machines to extract cleanly. Content that has consistent authority signals across multiple surfaces. Content that doesn’t try to game the system or use manipulative patterns to force its way into AI-generated answers.

This connects directly to the FSA Framework (Freshness, Structure, Authority). The structure component is about making content legible to machines—not to manipulate them, but to be interpretable by them. The authority component is about building a consistent, verifiable brand presence across the web.

As AI agents become more sophisticated at detecting manipulation, the gap between brands doing real content strategy and brands trying to game their way into AI answers will only widen. The brands stuffing content with conversational keywords or using shady tactics to appear in AI responses are building exactly the kinds of patterns these systems are being trained to resist.

AI visibility rewards the brands that build trust, not the ones that try to trick the algorithm. OpenAI’s announcement this week confirms that from the security side.

Google’s Personal Intelligence: Search Just Got Deeply Personal

What Google Announced

On March 17, Google announced the expansion of Personal Intelligence across AI Mode in Search, the Gemini app, and Gemini in Chrome for free-tier users in the U.S.

Personal Intelligence connects a user’s Google apps—Gmail, Google Photos, and more—to deliver answers that are uniquely tailored to that individual. Not generic recommendations. Not “top 10” lists. Answers based on that person’s actual purchase history, travel confirmations, photos, and preferences.

Some examples Google shared:

  • A user asks about a product they bought without remembering the brand, and Google pulls from purchase receipts to provide troubleshooting steps for that exact model
  • A user asks for restaurant recommendations during a layover, and the system factors in dietary preferences, gate numbers, and available time
  • A user asks for a bag to match new shoes, and Google recommends options that match the specific shoes recently purchased, down to hardware color
  • A user asks for travel recommendations and receives suggestions based on past favorites and personal interests, not generic listicles

Google is framing this feature around user control: users choose which apps to connect, can turn connections on or off at any time, and the system does not train directly on Gmail inboxes or Photos libraries.

Why First-Party Data Just Became Even More Critical

Here’s the strategic implication that every marketer should be paying attention to: if Google is now pulling from Gmail to personalize search answers, then every email a brand sends to a customer — every order confirmation, every onboarding sequence, every newsletter — is potentially feeding into how Google understands and recommends that brand back to that person.

First-party data, collected ethically, is no longer just a marketing asset. It’s becoming a visibility asset.

Brands that have strong email relationships with their customers, brands that use first-party data to deliver genuine value, are going to have an enormous advantage in this environment. Post-purchase emails are no longer just customer communication—they’re potential data points that Google’s AI might reference when recommending that brand again. Newsletters read in Gmail become signals of brand affinity that could influence future AI-personalized recommendations.

And the emphasis on “ethically” matters here. Google is building this feature around user control and transparency. Brands that are spammy, manipulative, or reckless with customer data will be on the wrong side of this shift. This isn’t a loophole to exploit. It’s a reward for brands that genuinely care about their customer relationships.

What This Means for Content Strategy

The generic “top 10” content strategy is losing even more ground. If someone can ask Google for recommendations and receive answers tailored to their actual preferences and history, generic listicles become increasingly irrelevant.

Content strategy in a Personal Intelligence environment shifts toward being part of someone’s ecosystem, not just showing up in their search results. That means:

  • Building real email relationships, not just growing a list for the sake of a number
  • Making post-purchase communication genuinely useful, not just transactional
  • Investing in brand experiences that create the kind of customer affinity Google’s system can detect
  • Thinking about entity authority not just across public websites, but across every touchpoint where a brand shows up in someone’s Google ecosystem

If you’ve been thinking about entity building as strictly a public web play— third-party mentions, backlinks, Reddit visibility—this is a wake-up call. Entity authority is expanding into the private, personal layer of how people interact with Google. The brands that show up in someone’s inbox, in their purchase history, and in their daily life are the ones that Personal Intelligence will surface.

What Both Updates Mean Together: AI Trust Is the New Visibility

When you zoom out and look at both of these stories together, the picture becomes clear.

On one side, OpenAI is training AI agents to be skeptical of content that tries to manipulate them. The bar for what counts as “trustworthy content” is going up.

On the other side, Google is making search deeply personal. The answers people receive are no longer just based on what’s publicly available—they’re based on that person’s own history, preferences, and relationships with brands.

Both developments point to the same conclusion: the brands that win in AI search are the ones that earn trust at every level.

Trust in how content is structured and presented. Trust in how a brand shows up across the web. And trust in how a brand shows up in someone’s personal digital life—their inbox, their receipts, their daily experience with a product or service.

The FSA Framework— Freshness, Structure, Authority—still holds. But what this week reveals is that authority is expanding. It’s no longer limited to being mentioned on third-party websites. It’s about being a trusted presence in someone’s actual life.

If we haven’t met yet….

Hi, I’m Cassie, a fractional content strategist for early-stage startups who focuses on AI search optimization.

If AI-generated answers are already influencing your buyers, your content strategy needs to account for that. I build content programs that connect strategy with execution: clear positioning,  systems, and content that actually drive revenue. If you’re ready to stop guessing and start growing, here’s how we can work together.

Want more insights like this? Subscribe to The Visibility Report, where I break down how AI engines interpret authority—and how you can show up in the results.

About the author

Cassie Wilson Clark

CMO & Fractional Content Strategist

Cassie leads AI-first content programs for early-stage startups—connecting strategy with execution so brands earn authority in both Google and AI engines.

What do you think?

Your email address will not be published. Required fields are marked *

No Comments Yet.