Living definition
A working definition built to be challenged.
The phrase is current but not standardised. This page defines its useful scope and points to more precise language when precision matters.
Canonical wording
Cite as: Context Bleed, v1.0
Context bleed is the unwanted transfer of information, instructions, behaviour or authority from one AI context into another where it is irrelevant, unintended or unauthorised.
“Context” includes message history, system instructions, retrieved documents, tool outputs, persistent memory, summaries, caches and workflow state. “Transfer” includes disclosure and subtler influence over reasoning or action.
Terminology status
The label is useful because it connects several boundary failures. Its limits should remain visible.
Current use
Emerging umbrella term
Increasingly used in practitioner guidance, product reports and early research; not a settled standard.
Research language
Mechanisms are narrower
Instruction bleed, contextual entrainment and long-context degradation name distinct measurable effects.
Security language
Impact decides the label
Use retrieval leakage, prompt injection, memory poisoning or broken isolation when those diagnoses apply.
01Scope test
Four conditions, one diagnosis.
The more conditions are observable, the stronger the claim.
- 01
A distinct origin
The material began in another task, session, user, tenant, agent, source or trust level.
- 02
A meaningful boundary
The destination has different relevance, purpose, identity or authority requirements.
- 03
Unwanted transfer
The crossing is irrelevant, unintended or unauthorised — not designed continuity.
- 04
Observable influence
The material affects output, reasoning, retrieval, memory, access or action.
02Use the precise term
Umbrella first. Diagnosis second.
| Observed situation | Preferred technical name |
|---|---|
| Old topic affects a new task | Context contamination / cross-task carryover |
| Performance declines with more input | Context rot / long-context degradation |
| Another tenant's chunk is retrieved | Cross-tenant retrieval leakage |
| Malicious content persists in memory | Memory poisoning |
| External content redirects the agent | Indirect prompt injection |
| Prompt modules alter one another | Instruction bleed / compositional behavioural leakage |
03Important exclusion
An unfamiliar answer is not proof of a leaked conversation.
Confabulation, training artefacts, legitimate personalisation and retrieval errors can look alike. A cross-user claim requires reproducible evidence about identity, source or system state — not model self-explanation alone.
04Revision policy
A definition should move when the evidence does.
Material revisions receive a new version, date and change note. Terminology proposals are assessed against published usage, explanatory value and overlap with established security or ML terms.