Skip to content
Glossary · Industry term

System prompt

Also known as: system message, system instruction, developer prompt

The instruction passed to a large language model that defines the agent's role, behaviour, allowed actions, and operating constraints. In agent-mode deployments the system prompt is typically several thousand tokens and carries the policy boundary: tool-use rules, refusal patterns, output format requirements, persona, audit metadata. Distinct from the user prompt (the request being handled).

How this publication uses it

The system prompt is where most enterprise agent governance lives in practice — and where most enterprise agent governance audit findings surface. Production system prompts in 2026 are typically 2K-8K tokens, version-controlled, change-managed, and stamped with the policy version reference per Article 12 audit logging. The mistake is treating the system prompt as configuration rather than as a security artefact: every change is a policy change and should be logged accordingly.

Related frameworks

Articles that analyse this term

Primary sources

Vigil · 78 reviewed