How do I tell ChatGPT what not to do?
Name the exact thing you do not want, and put the rule beside the requirement it belongs to rather than in an opening instruction. Across the 455 prompts we publish there are 412 prohibitions, 281 of them fall in the last quarter of the prompt, and only 10 appear in the first quarter.
The useful way to think about a negative instruction is that it is a filter, not a specification. It can remove something from a draft the model was going to produce anyway. It cannot supply what should stand in the gap. That single distinction explains why "do not be generic" fails and "no sentence longer than 20 words" works. The first names a judgment that only exists in your head. The second names a condition the output either meets or does not, and a stranger could check it.
What follows is a census of our own library. It shows what prohibitions look like in prompts we sell and that people keep using. It cannot tell you that any individual rule caused a better answer, and where that limit matters we say so rather than dressing a description up as a result.
Does telling ChatGPT not to do something actually work?
Yes, for the checkable kind. The advice that negatives never work is overstated, and the reason it sounds true is that most negatives people write are judgments. 248 of our 455 prompts carry at least one prohibition, and these are prompts written by people who do this for a living and then kept the ones that produced usable output.
The mechanism is worth being precise about, because it predicts which bans hold. A model produces the most probable continuation given everything in front of it. Ruling out one phrase removes one candidate, and the next most probable candidate is usually a near synonym. So banning "in today's competitive landscape" without changing anything else tends to get you "in the current environment". The ban worked exactly as instructed and the output did not improve, which is why it feels like the model ignored you.
That is also why the specificity of the ban is the thing to measure. Of the 412 prohibitions, 145 sit in a sentence that quotes the exact string being ruled out and 267 name a category instead. The category ones are not automatically weaker, and the reason turns out to be interesting, but it takes the image prompts to see it clearly.
What do 455 working prompts actually ban?
Six grammatical forms cover every prohibition in the library, and the distribution is lopsided in a useful direction.
| Form | Count | Share | Example from the library |
|---|---|---|---|
| no [thing] | 145 | 35% | No props, no text, no branding overlays. |
| do not / don't | 138 | 33% | Do NOT use filler headlines like "Our Solution" or "Market Opportunity." |
| never | 77 | 19% | Never use "In conclusion," "To summarize," or "At the end of the day" |
| avoid | 30 | 7% | Avoid phrases like "growing demand." Show the demand with numbers. |
| must not / cannot | 20 | 5% | Subject line must not contain "miss you," "been a while," or "come back" |
| omit / exclude | 2 | <1% | Specifically exclude [EXCLUDED MATTERS] |
283 of the 412, or 69 percent, use one of the two flattest forms. "No [thing]" and "do not" are the two constructions with the least room in them. They do not describe a preference or a direction of travel. They draw a line, and the output sits on one side of it or the other.
Why is "avoid" the weakest word on that list?
Because it names a tendency rather than a boundary, and a tendency has no failure condition. "Avoid jargon" is satisfied by less jargon. "No jargon without immediate plain-language translation", which is an actual line from our Content Creator pack, is satisfied or it is not.
The library votes with its feet here: 30 uses out of 412, or 7 percent. The 30 that survive almost all rescue themselves by attaching an example immediately, which is the real lesson. Here is one of them in full, from the Business Strategy pack:
Avoid vague recommendations like "create great content." Every suggestion must include: the specific topic, format, target keyword, and why it would outperform their existing content.
The weak verb costs nothing there, because the sentence goes on to quote the failure and then name the four things a passing answer contains. Strip either of those and the rule stops working regardless of which verb you picked.
Is it better to say what you want instead?
Prefer the positive requirement, and keep the negative for a specific default you find yourself deleting every time. They do different jobs, and a prompt made only of prohibitions has told the model everything except what to write.
| Pattern | Count | Does it name the replacement? |
|---|---|---|
| Prohibition alone in its sentence | 309 of 412 | No. The reader has to infer it. |
| Prohibition plus a positive directive in the same sentence | 103 of 412 | Yes, in a second clause. |
| Contrastive form, "X, not Y" | 242 rules, in 169 prompts | Yes, structurally. The replacement is the subject of the clause. |
The contrastive form is the pattern worth stealing. "Write like a person, not a platform." "Use bullet points, not paragraphs." "Price should be based on value delivered, not competitive anchoring." It states the target first and the rejected neighbour second, so it can never be a rule that removes without replacing. It also reads as one decision rather than two, which means it survives editing better than a requirements block followed by a separate banned list.
One honest caveat about this table. It describes how our authors write, not a measured effect on output quality. We can say that 169 prompts reach for the contrastive form and that the form structurally cannot leave a gap. We cannot say from this data that it beats a bare ban, because we did not run that comparison.
Where should a negative instruction go in the prompt?
Beside the requirement it modifies, which in practice means late. The concentration is stronger than we expected.
| Position in the prompt | Prohibitions | Share |
|---|---|---|
| First quarter | 10 | 2% |
| Second quarter | 37 | 9% |
| Third quarter | 84 | 20% |
| Final quarter | 281 | 68% |
A prohibition is a modifier, and a modifier placed before the thing it modifies has nothing to attach to. A ban in the opening line asks the model to carry a constraint through the entire task description and then apply it to a deliverable it has not been told about yet. A ban sitting under the section it governs does not ask for that.
This also matches the shape we found when we counted prompt lengths: the requirement block is the last thing in a working prompt, and 77 percent of our constrained prompts put the final requirement after the last input placeholder. Prohibitions live in that block. They are part of the specification, not part of the framing.
Why do the image prompts ban the most and quote the least?
This is the result that changed how we would give the advice. Our AI Image Prompts pack has the second highest rate of prohibitions in the library, 45 across 28 prompts, and not one of them quotes a string. Every other pack that bans heavily quotes constantly.
| Pack | Prompts | Prohibitions | Per prompt | Quoting sentences |
|---|---|---|---|---|
| Marketing | 35 | 62 | 1.77 | 24 |
| AI Image Prompts | 28 | 45 | 1.61 | 0 |
| Freelancer Toolkit | 30 | 47 | 1.57 | 23 |
| Content Creator | 32 | 47 | 1.47 | 20 |
| Business Strategy | 30 | 41 | 1.37 | 14 |
| Personal Finance (lowest in the library) | 28 | 7 | 0.25 | 3 |
The image bans read like this: "No text, no objects, no focal point." "No gradients, no shadows, no noise." "No icon, no symbol, no tagline." "No visible shadows." "No retouching artifacts." None of them quote anything, and every one of them is completely checkable, because you can look at the picture and see whether a gradient is there.
So quoting a string was never the actual rule. It is a proxy for the real one, which is this: a prohibition works when a second person could check it without asking your opinion. In an image, an object satisfies that test. In text, an object usually does not, because "fluff" and "corporate speak" and "generic" are not things anyone can point at, and the exact string is the only object available. That is a better rule than "always quote the phrase", because it tells you what to do when there is no phrase to quote.
How many things should one prompt rule out?
Fewer than people expect. 207 of our 455 prompts contain no prohibition at all, 140 contain exactly one, 67 contain two, 31 contain three, and only 10 contain four or more. The heaviest prompt in the library carries six. Counting the contrastive rules as well, 144 prompts rule nothing out by either method.
That is not a ceiling imposed by the model. It is a symptom. A requirement that says what the output must contain has already excluded most of what it must not, so a well specified prompt needs few bans. When a ban list grows past four or five, the usual cause is a thin positive specification being patched one failure at a time, and the fix is upstream: say what a passing answer looks like, and most of the list becomes unnecessary.
A prompt that turns your bans into checkable requirements
Paste in the rule the model keeps ignoring. This converts it into requirements that have a failure condition, and it will tell you which parts of your rule could not be converted, which is usually the informative bit.
Here is a rule I keep giving you that keeps not working: [PASTE YOUR RULE, e.g. "don't be generic" or "avoid corporate speak"] Rewrite it as between 3 and 6 checkable requirements. Every requirement must: 1. Name a specific string, structure, or count that is either present in the output or absent from it 2. Be verifiable by someone who has not read this conversation and holds no opinion about the topic 3. Where it rules something out, say in the same line what takes its place Then list any part of my original rule you could not convert, and say what you would need to know about my preferences to convert it. Output the requirements as a numbered list I can paste at the end of a prompt. No preamble, no explanation of what you are about to do.
The last instruction in that block is itself the pattern this page describes. "No preamble" names an object that is either in the output or not, and it sits at the end, next to the thing it modifies.
What this measures, and what it does not
These are counts over prompts we publish and believe work. They describe a house style that has survived contact with buyers. They are not a controlled test of whether a prohibition improved an answer, and nothing here should be read as one. We have run that kind of test elsewhere, on a single build comparison with the markers fixed in advance, and it is reported separately in does telling ChatGPT to act as an expert actually work. This page is a census.
The detection is a pattern match over the text of each prompt, so it has a known failure mode and we handled it explicitly. 55 matches were discarded because they sat inside a bracketed placeholder, where a phrase like "no credit card required" is an example value the buyer replaces rather than an instruction to the model. Constructions that read as prohibitions but are not, such as "no more than" and "no matter", are excluded by rule. Some judgment calls remain, and a different reasonable rule would move these totals by a few percent, not by an order of magnitude.
Questions people ask about negative instructions
It works when the ban names something checkable and fails when it names a judgment. "No sentence longer than 20 words" and "never use the phrase game-changer" describe conditions the output either meets or does not. "Do not be generic" describes an opinion, so the model has to guess what you would have objected to. Across the 455 prompts we publish, 248 carry at least one prohibition, so working prompts clearly do use negatives. What separates the useful ones is specificity: 145 of the 412 prohibitions quote the exact string being ruled out, and most of the rest name a concrete object such as text, gradients or shadows in an image.
Usually because the instruction named a feeling rather than a string, or because nothing replaced what you removed. A model produces the most probable next piece of text given everything in front of it, and a ban only removes one candidate. If the surrounding requirements still point at the same register, the next most probable phrase is a near synonym of the one you banned. Two fixes work better than repeating the ban louder: quote the exact strings including the variants, and say what the sentence should open with instead. In our library, 242 rules take the contrastive form "X, not Y", which carries the replacement in the same clause.
Prefer the positive requirement, and keep the negative when it names a specific default you keep having to delete. The two do different jobs. A requirement builds the output, a prohibition removes something the model would otherwise reach for, and a prompt with only prohibitions has told the model everything except what to write. In the 455 prompts we publish, 309 of the 412 prohibitions stand alone in their sentence and 103 also carry a positive directive. Separately, 242 rules use the "X, not Y" form, which is the library's most common way of doing both at once.
Use "no" or "do not", and skip "avoid". Across 412 prohibitions in our library, 145 use a bare "no [thing]", 138 use "do not" or "don't", 77 use "never", and only 30 use "avoid", which is 7 percent. "Avoid" describes a tendency rather than a boundary, so it leaves room for a small amount of the thing you did not want. The verb matters far less than what follows it: "avoid vague recommendations like create great content" is a good rule despite the weak verb, because it quotes the failure and then names what a passing answer contains.
After the task and the output specification, beside the requirement they modify. Of the 412 prohibitions in our library, 281 sit in the final quarter of the prompt and only 10 sit in the first quarter. The reason is structural rather than stylistic. A ban is a modifier, and a modifier placed before the thing it modifies has nothing to attach to, so a prohibition in an opening line asks the model to carry a constraint through the whole task description before it knows what it is producing. Put the rule under the section it governs, or in a short block at the end.
List the exact strings, keep the list short, and add the replacement. That is what the prompts in our library do. Real examples include "in today's competitive landscape", "it's important to note", "game-changer", "don't hesitate to reach out", "In conclusion", "To summarize", "At the end of the day", and "Most people don't realize". Notice they are quoted rather than described. A list of banned strings is checkable with Ctrl+F, which means you can tell instantly whether the model obeyed, and you can paste the same list into the next prompt without rewriting it.
Our prompts stay low. 140 carry one prohibition, 67 carry two, 31 carry three, and only 10 carry four or more, with 6 the highest in the library. 207 of 455 carry none at all. That is not a limit imposed by the model, it is a symptom: a well specified prompt needs fewer bans, because a requirement that says what the output must contain has already ruled out most of what it must not. If your ban list is growing past four or five, the usual cause is a thin positive specification being patched one failure at a time.
Related reading and next steps: the reason a bare ban disappoints is the same reason a plain request does, covered in why ChatGPT gives generic answers. Banning a phrase is a small version of the voice problem, handled in how to get ChatGPT to write in your voice. For how much of the prompt the requirement block should occupy, see how long a ChatGPT prompt should be. For the block the rules attach to, see how to get ChatGPT to follow the format you asked for. To start from prompts that already carry the requirement block rather than writing one, browse the prompt packs, or read the how to use guide.