How it works
Chat APIs take a list of messages. The system (or developer) message says who the model is and how it must behave, for example 'You are a support assistant for a shoe shop. Answer only from the policy below, in under 100 words.' User messages carry the questions and assistant messages hold earlier replies. Clear instructions, a few worked examples (few-shot prompting) and an explicit output format do more for quality than clever wording.
Treat prompts like code: keep them in version control and test them against known cases (often called evals) before changing them. Long prompts that repeat on every call can be cached by most providers at a large discount. Anything a user types, or any page or document the model reads, may try to override the rules (prompt injection), so the system prompt on its own is never a security boundary.
Related terms
More in AI and LLMs
Basics