AML.T0094
MITRE ATLAS / Delay Execution of LLM Instructions
Adversaries embed instructions the AI system should follow in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass review at the time of injection.
In plain English
An injected instruction that does nothing today passes review today. It waits for a trigger word or the next session, so the malicious behavior and the malicious input never appear together.