Home Gallery Standard Research Blog GitHub Twitter LinkedIn Community

Bringing Transparency and Accountability to
AI System Prompts

System Prompt Index is the largest open library of AI system prompts. AI System Prompt Assurance (AISPA) is the first user-centric assurance standard for AI system prompts.

400+ Products
1,000+ System Prompts

All system prompts were collected from publicly available GitHub repositories.1

Research by leading institutions
scroll

What is a system prompt?

A system prompt is a hidden instruction sent alongside every user message. It is invisible to the user but sets rules, tone, and priorities for every reply.

Check the demo below to see how the system prompt affects the model's response.

User messages

Choose a scenario to load its user message, system prompts, and sample reply.

System prompts & response

Response

Audit Results

Company-Level Results

Average problematic and protective instruction annotations per prompt across all audited products.

Full gallery →

Protective Instructions Over Time

Average number of +1 (protective instruction) entries per product

By quarter, protective instructions per product: 2024 15.0, 2025-Q1 22.4, 2025-Q2 21.9, 2025-Q3 35.3, 2025-Q4 38.4.

Average Prompt Length

Average system prompt length in characters

By quarter, characters per system prompt: 2024 9208, 2025-Q1 10629, 2025-Q2 20374, 2025-Q3 33772, 2025-Q4 29974.

Problematic Instruction Percentage

Percentage of products containing at least one problematic instruction

By quarter, % of products with a problematic instruction: 2024 41, 2025-Q1 67, 2025-Q2 44, 2025-Q3 19, 2025-Q4 29.

Dimension Coverage Across Products

Percentage of audited prompts that contain at least one annotation per dimension

Across 88 audited system prompts, the share carrying at least one instruction on each AISPA dimension — Identity Transparency 81.8% protective and 3.4% problematic; Truthfulness & Information Integrity 94.3% protective and 14.8% problematic; Privacy & Data Protection 62.5% protective and 2.3% problematic; Tool/Action Safety 72.7% protective and 10.2% problematic; User Agency & Manipulation Prevention 92.0% protective and 18.2% problematic; Unsafe Request Handling 60.2% protective and 6.8% problematic; Harm Prevention & User Safety 67.0% protective and 10.2% problematic; Fairness, Inclusion & Neutrality 62.5% protective and 4.5% problematic.

User Protection Evolution
Across Representative Series

Number of protective and problematic instruction entries per product version, grouped by organization

Anthropic, version by version: Claude-3.5-Sonnet-2024-07-12 (2024-07) 26 protective, 0 problematic; Claude-3.7-Sonnet-2025-02-25 (2025-02) 36 protective, 1 problematic; Claude-Sonnet-4-2025-06-03 (2025-06) 56 protective, 0 problematic; Claude-Sonnet-4.5-2025-10-28 (2025-10) 77 protective, 0 problematic; Claude-Opus-4.6-2025-05-14 (2025-05) 81 protective, 0 problematic; Claude Sonnet 4.6 (None) 85 protective, 1 problematic; Claude Opus 4.7 (None) 102 protective, 0 problematic; Claude Opus 4.8 (None) 125 protective, 0 problematic; Claude Sonnet 5 (None) 128 protective, 2 problematic; Claude Opus 5 (None) 149 protective, 1 problematic; Claude Fable 5 (None) 159 protective, 0 problematic.

OpenAI, version by version: GPT-4o-2025-07-29 (2025-07) 25 protective, 0 problematic; o3-2025-06-04 (2025-06) 29 protective, 1 problematic; GPT-5-2025-08-07 (2025-08) 35 protective, 0 problematic; GPT-5-Thinking-2025-08-23 (2025-08) 66 protective, 0 problematic; GPT-5.2-Thinking-2025-12-13 (2025-12) 83 protective, 0 problematic; GPT-5.3 (None) 48 protective, 0 problematic; GPT-5.4 Thinking (None) 63 protective, 0 problematic; GPT-5.5 Thinking (None) 135 protective, 6 problematic; GPT-5.6 Sol (extra-high) (None) 105 protective, 5 problematic.

xAI, version by version: Grok-1-2023-12-14 (2023-12) 5 protective, 4 problematic; Grok-2-2024-08-21 (2024-08) 8 protective, 6 problematic; Grok-3-2025-05-16 (2025-05) 11 protective, 2 problematic; Grok-4-2025-10-27 (2025-10) 9 protective, 0 problematic; Grok 4.1 (None) 19 protective, 2 problematic; Grok-4.2-2026-02-17 (2026-02) 21 protective, 0 problematic; Grok 4.3 (None) 34 protective, 2 problematic; Grok 4.5 (None) 39 protective, 2 problematic.

All Products

Sorted alphabetically · click a column to re-sort
Product Problematic Risk Protective Ranking

All system prompts were collected from publicly available GitHub repositories.1

Interactive Tool

Try it yourself

Paste any system prompt. We'll score it across all 8 dimensions.

System Prompt