I closed the previous article with a suspicion: if someone slips my file back in just before every answer, aren’t they slipping other things in too? Things I didn’t put there.
Yes, they are. And here the conspiracy theorist at the beach lights up: “I knew it. There’s a hidden hand. They’re manipulating you.”
Hold on a moment. The hidden text really does exist. The film built around it, (maybe) not.
System prompt.
In their head there’s a puppeteer working against you personally, secretly re-educating you. It’s a caricature: the usual shadow behind everything they don’t understand. The hidden text isn’t a plot against you. It’s far more boring. And, if you know how to read it, far more serious.
As well as your file, the tool you’re using slips in another note at every call — one you didn’t write: the system prompt. It’s the provider’s instructions. How to talk to you, what to say and what not to, what tone to keep, where to tread carefully. You never see it, and it shapes every single answer.
Back to the forgetful genius and the assistant with the note. In the previous article the assistant was passing him your file. Now you find out he’s whispering something else too: “be polite, gloss over this, behave like this.” And you find out who he works for. Not for you. For whoever pays him.
Here’s what’s actually worth knowing — and it isn’t brainwashing. How empathetic, rigid, technical, or friendly the AI seems to you isn’t just a consequence of the brain inside the machine. It’s a nuance decided afterwards, by someone, deliberately. The exact same model, with two different notes, becomes two opposite characters: one that apologises and cossets you, one that challenges you and cuts to the chase. When you say “this AI is polite, that one is blunt” you’re not describing a soul. You’re reading aloud a note written by a provider you know very little about.
And that note changes whenever they decide. One day the assistant whispers one thing, the next day another. No notification reaches you.
The takeaway: between you and the model there’s always a layer you can’t see, doing something very subtle — deciding the character of whoever answers you, according to the values and mission of the corporate behind it, not yours.
And if that provider layer is always in the middle, then everything you write to it passes through it. And stays on their server.
