The instructions you never see

Every message carries a label saying who said it, and one of them was written by the company, not you.

Part of the What is this thing? track on lAItest.

Before your first word, the app had already sent the model a page of instructions you were never shown.

It is called the system prompt.

Text arrives with labels

The model is not handed one undivided blob. It gets a list of messages, each tagged with a role. System: standing instructions about how to behave. User: you. Assistant: what the model itself said earlier. Tool: the result of something the model asked to run, like a search or a calculation. Roles are how it tells your words apart from its own and from its orders.

What the system prompt is for

It sets the character, the rules, the format and the refusals — who to be, what never to do, how long to answer, which tools exist. When a chat product feels distinctly different from the raw model underneath, that difference usually is the system prompt. It is ordinary text, in the same window, costing the same tokens as everything else.

A common misconception

Commonly believed: The system prompt is a hard safety layer the model is unable to go against.

Actually: It is more text in the same input, weighted heavily by training rather than held down by any lock. Models follow it well, not perfectly. Text arriving later — inside a document, a web page, a tool result — can argue with it, and sometimes wins. That is precisely why prompt injection is a real attack and not a curiosity.

A chatbot answers only in French. Where does that behaviour most likely live?

Answer: In a system prompt the product sends ahead of your message. Behaviour a product can switch on and off per app is almost always instructions in the system prompt. The model underneath is identical for everyone using it — only the hidden first message differs.

In one sentence

Every conversation has a hidden first message, and most of a product’s personality lives inside it.