Skip to content
CBContext/Bleed Wiki

Living definition

Version 1.020 July 2026

A working definition built to be challenged.

The phrase is current but not standardised. This page defines its useful scope and points to more precise language when precision matters.

Canonical wording

Cite as: Context Bleed, v1.0

Context bleed is the unwanted transfer of information, instructions, behaviour or authority from one AI context into another where it is irrelevant, unintended or unauthorised.

“Context” includes message history, system instructions, retrieved documents, tool outputs, persistent memory, summaries, caches and workflow state. “Transfer” includes disclosure and subtler influence over reasoning or action.

Terminology status

The label is useful because it connects several boundary failures. Its limits should remain visible.

Current use

Emerging umbrella term

Increasingly used in practitioner guidance, product reports and early research; not a settled standard.

Research language

Mechanisms are narrower

Instruction bleed, contextual entrainment and long-context degradation name distinct measurable effects.

Security language

Impact decides the label

Use retrieval leakage, prompt injection, memory poisoning or broken isolation when those diagnoses apply.

01Scope test

Four conditions, one diagnosis.

The more conditions are observable, the stronger the claim.

  1. 01

    A distinct origin

    The material began in another task, session, user, tenant, agent, source or trust level.

  2. 02

    A meaningful boundary

    The destination has different relevance, purpose, identity or authority requirements.

  3. 03

    Unwanted transfer

    The crossing is irrelevant, unintended or unauthorised — not designed continuity.

  4. 04

    Observable influence

    The material affects output, reasoning, retrieval, memory, access or action.

02Use the precise term

Umbrella first. Diagnosis second.

Observed situationPreferred technical name
Old topic affects a new taskContext contamination / cross-task carryover
Performance declines with more inputContext rot / long-context degradation
Another tenant's chunk is retrievedCross-tenant retrieval leakage
Malicious content persists in memoryMemory poisoning
External content redirects the agentIndirect prompt injection
Prompt modules alter one anotherInstruction bleed / compositional behavioural leakage

03Important exclusion

An unfamiliar answer is not proof of a leaked conversation.

Confabulation, training artefacts, legitimate personalisation and retrieval errors can look alike. A cross-user claim requires reproducible evidence about identity, source or system state — not model self-explanation alone.

04Revision policy

A definition should move when the evidence does.

Material revisions receive a new version, date and change note. Terminology proposals are assessed against published usage, explanatory value and overlap with established security or ML terms.

Read the editorial method ↗