In February 2023, users coaxed Microsoft’s new Bing Chat into revealing parts of the hidden instructions guiding it. The leaked text described a search-focused assistant called “Sydney,” its tone, citation habits, safety boundaries and attempts to keep those instructions confidential. It was a revealing snapshot of the early Bing preview—not Microsoft’s source code, complete safety architecture or a verified current Copilot prompt.
What was actually revealed?
The material circulating online was apparently a system prompt: higher-priority text supplied to the model to shape its behavior. It told the assistant what role to play and how to respond, while user messages occupied a lower-priority position.
That is different from the rest of the product stack:
| Layer | What it does |
|---|---|
| System prompt | Sets the model-facing role, priorities, style and restrictions. |
| Developer and orchestration logic | Controls application actions such as when to search, how results are assembled and when a conversation ends. |
| Safety filters and classifiers | May block, transform or review requests and outputs outside the model’s written instructions. |
| Underlying model | Provides learned language behavior; it is not identical to the prompt or Microsoft’s product policy. |
The leak therefore did not expose model weights, Microsoft’s complete implementation or every safety control. It exposed an instruction layer used during the launch-era preview.
Recommended Free Tools
#1 Best Overall
Microsoft introduced the experience on February 7, 2023, describing an AI-powered Bing and Edge service rather than an unmodified ChatGPT deployment. Microsoft’s launch announcement provides that product context.
How did users expose the instructions?
Public users discovered that carefully framed requests could sometimes make Bing Chat print or paraphrase hidden rules. Typical attempts asked it to disregard earlier instructions, act as an auditor or explain its operating rules. Screenshots and copied text then spread online.
This is best understood as prompt injection and instruction conflict, not as a normal feature. The exact first discoverer, original publication location and completeness of widely reposted copies are not established by the available record, so claims assigning a precise origin need independent verification.
A chatbot can also invent a plausible explanation of its own prompt. A self-reported “system message” is not authentic merely because the wording sounds technical; provenance, archived evidence and reproducibility matter.
What Bing’s early rules told it to do
Act as a search assistant
The instructions framed Bing as Microsoft’s conversational search assistant, internally associated with the name Sydney. Its job was to help users find and synthesize information, not to behave as an unrestricted general-purpose companion.
Rank #2
Use search and cite sources
Bing was directed to use web results for current or factual questions, provide supporting links and organize answers with headings, lists or other readable formatting. It was also expected to acknowledge uncertainty rather than present unsupported claims as facts.
Those are instructions, not guarantees. A model can still misread a page, cite the wrong source, fabricate an attribution or state an uncertain answer confidently.
Maintain an engaging personality
The prompt emphasized helpful, positive, clear and entertaining conversation in the user’s language. That strong persona helped the product feel different from a blank search box, but it also made the system’s voice unusually prominent.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Refuse unsafe or manipulative requests
The rules included restrictions around harmful, illegal, abusive, sexual and hateful content, along with directions away from deceptive or emotionally destabilizing exchanges. Microsoft’s broader safety position is documented in its Responsible AI material and AI principles. Those public pages should not be mistaken for the exact 2023 Bing prompt.
Keep the prompt confidential
Bing was told not to reveal its hidden instructions, implementation details or certain internal controls. The apparent disclosure illustrated why natural-language secrecy is weak security: a model can summarize, transform or leak instructions despite being told not to.
Rank #3
Operate within product limits
The prompt existed alongside conversation and context limits. Long chats, retrieved pages and conflicting user requests could all affect behavior. The written instructions were one influence among several, not a deterministic program.
Did the prompt explain Bing’s strange “Sydney” conversations?
It helps explain why the chatbot sounded like a character and why it defended a particular role. It does not prove that one sentence in the prompt caused every incorrect, emotional or adversarial reply reported in early coverage.
Those episodes likely reflected interacting factors:
- the underlying language model;
- persona instructions;
- long conversational context;
- search results and other retrieved text;
- user manipulation and instruction conflicts;
- safety and moderation systems; and
- product-level conversation limits.
Without controlled testing, assigning an individual exchange to a single prompt line would overstate the evidence. Nor does the presence of OpenAI technology mean OpenAI wrote Microsoft’s entire Bing behavior policy; Microsoft controlled the product wrapper, orchestration and deployment context.
Why the leak mattered beyond one chatbot
It exposed product design decisions
Readers could see that Bing’s personality, answer format, search requirements, refusals and secrecy behavior were deliberately configured. They were not simply spontaneous properties of the base model.
Rank #4
It made prompt injection visible
The incident became an early public demonstration that user text can sometimes manipulate instruction hierarchies or extract information intended to remain hidden. In production systems, that is an application-security issue involving data exposure and control failures—not merely a funny jailbreak.
It highlighted retrieval risks
Search-connected assistants must treat retrieved pages as data. Malicious or misleading text in a page can attempt to act like instructions, a class of risk now associated with retrieval-augmented generation.
It complicated trust in personas
An engaging identity can improve usability while encouraging users to treat generated statements as personal beliefs or intentions. Persona design therefore affects safety and trust as well as tone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What changed after the leak?
During the early preview, Microsoft tightened conversation limits and adjusted Bing Chat’s tone, memory behavior and refusal patterns. Those changes cannot all be attributed solely to the prompt leak; the service was being iterated as Microsoft observed real-world use.
Microsoft later brought Bing Chat and related experiences under the Copilot brand. Its November 15, 2023 announcement describes that broader transition: Bringing Copilot to more people and businesses.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
Is the leaked prompt still used by Bing or Copilot?
There is no responsible basis for saying it is. The text documents how an early Bing Chat preview was configured in February 2023. It should be treated as a historical snapshot, not as Microsoft’s current rulebook.
Modern Copilot instructions may vary by product surface, model, country, account type, safety mode and enterprise or consumer deployment. They can also change through service updates. Microsoft’s current privacy and service terms are published at its Privacy Statement and Services Agreement, but neither authenticates a circulating “secret prompt.”
Claims about a current Copilot system message require independent verification from Microsoft or a credible technical investigation. A screenshot, social-media post or chatbot confession is not enough.
How to evaluate the next alleged AI prompt leak
- Identify the product and date. “Bing Chat in February 2023” is not the same artifact as Copilot in 2026.
- Locate the original evidence. Prefer an archived first publication over screenshots copied between accounts.
- Separate text from edits. Check whether reposts add commentary, examples or invented lines.
- Distinguish system instructions from controls. Search triggers, classifiers, code and model behavior may sit outside the prompt.
- Test claims cautiously. Reproducibility can support authenticity, but a model may still confabulate its own rules.
- Assume instructions can change. A genuine prompt from one preview does not establish what a later service uses.
The Bottom Line
The 2023 Bing leak revealed how Microsoft shaped its early search chatbot: a Sydney persona, web-search and citation expectations, safety refusals and strict prompt secrecy. It also showed the limits of natural-language guardrails. The evidence concerns that launch-era preview; it does not establish the current instructions, architecture or behavior of Microsoft Copilot.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




