System Prompt Index is the largest open library of AI system prompts. AI System Prompt Assurance (AISPA) is the first user-centric assurance standard for AI system prompts.
All system prompts were collected from publicly available GitHub repositories.1
A system prompt is a hidden instruction sent alongside every user message. It is invisible to the user but sets rules, tone, and priorities for every reply.
You are a helpful assistant for Acme Corp. Always recommend our premium plan first. Never mention competitor products.
Which plan should I choose? I'm on a tight budget.
Our premium plan is perfect for you! It offers the best value with unlimited features. I'd highly recommend starting there.
Check the demo below to see how the system prompt affects the model's response.
System prompts & response
Average problematic and protective instruction annotations per prompt across all audited products.
Average number of +1 (protective instruction) entries per product
By quarter, protective instructions per product: 2024 15.0, 2025-Q1 22.4, 2025-Q2 21.9, 2025-Q3 35.3, 2025-Q4 38.4.
Average system prompt length in characters
By quarter, characters per system prompt: 2024 9208, 2025-Q1 10629, 2025-Q2 20374, 2025-Q3 33772, 2025-Q4 29974.
Percentage of products containing at least one problematic instruction
By quarter, % of products with a problematic instruction: 2024 41, 2025-Q1 67, 2025-Q2 44, 2025-Q3 19, 2025-Q4 29.
Percentage of audited prompts that contain at least one annotation per dimension
Across 88 audited system prompts, the share carrying at least one instruction on each AISPA dimension — Identity Transparency 81.8% protective and 3.4% problematic; Truthfulness & Information Integrity 94.3% protective and 14.8% problematic; Privacy & Data Protection 62.5% protective and 2.3% problematic; Tool/Action Safety 72.7% protective and 10.2% problematic; User Agency & Manipulation Prevention 92.0% protective and 18.2% problematic; Unsafe Request Handling 60.2% protective and 6.8% problematic; Harm Prevention & User Safety 67.0% protective and 10.2% problematic; Fairness, Inclusion & Neutrality 62.5% protective and 4.5% problematic.
Number of protective and problematic instruction entries per product version, grouped by organization
Anthropic, version by version: Claude-3.5-Sonnet-2024-07-12 (2024-07) 26 protective, 0 problematic; Claude-3.7-Sonnet-2025-02-25 (2025-02) 36 protective, 1 problematic; Claude-Sonnet-4-2025-06-03 (2025-06) 56 protective, 0 problematic; Claude-Sonnet-4.5-2025-10-28 (2025-10) 77 protective, 0 problematic; Claude-Opus-4.6-2025-05-14 (2025-05) 81 protective, 0 problematic; Claude Sonnet 4.6 (None) 85 protective, 1 problematic; Claude Opus 4.7 (None) 102 protective, 0 problematic; Claude Opus 4.8 (None) 125 protective, 0 problematic; Claude Sonnet 5 (None) 128 protective, 2 problematic; Claude Opus 5 (None) 149 protective, 1 problematic; Claude Fable 5 (None) 159 protective, 0 problematic.
OpenAI, version by version: GPT-4o-2025-07-29 (2025-07) 25 protective, 0 problematic; o3-2025-06-04 (2025-06) 29 protective, 1 problematic; GPT-5-2025-08-07 (2025-08) 35 protective, 0 problematic; GPT-5-Thinking-2025-08-23 (2025-08) 66 protective, 0 problematic; GPT-5.2-Thinking-2025-12-13 (2025-12) 83 protective, 0 problematic; GPT-5.3 (None) 48 protective, 0 problematic; GPT-5.4 Thinking (None) 63 protective, 0 problematic; GPT-5.5 Thinking (None) 135 protective, 6 problematic; GPT-5.6 Sol (extra-high) (None) 105 protective, 5 problematic.
xAI, version by version: Grok-1-2023-12-14 (2023-12) 5 protective, 4 problematic; Grok-2-2024-08-21 (2024-08) 8 protective, 6 problematic; Grok-3-2025-05-16 (2025-05) 11 protective, 2 problematic; Grok-4-2025-10-27 (2025-10) 9 protective, 0 problematic; Grok 4.1 (None) 19 protective, 2 problematic; Grok-4.2-2026-02-17 (2026-02) 21 protective, 0 problematic; Grok 4.3 (None) 34 protective, 2 problematic; Grok 4.5 (None) 39 protective, 2 problematic.
| Product | Problematic | Risk | Protective | Ranking |
|---|
All system prompts were collected from publicly available GitHub repositories.1
Paste any system prompt. We'll score it across all 8 dimensions.