An AI document workflow should treat incoming material as information to examine, not as permission to change its task or access other systems. That boundary matters when an application reads email, attachments, webpages, or retrieved documents.
OWASP describes indirect prompt injection as behavior-changing instructions introduced through external sources such as files or websites; the content need not be visibly readable to a person if the model can parse it (OWASP Prompt Injection). This is a technical risk category, not an allegation that any particular insured, broker, or vendor has attempted an attack.