Example:
INSERT INTO USERS (name) VALUES ('Gijs in \'t Veld');
Inserts the following row into the database ... | name | ...
========================
... | Gijs in 't Veld | ...
Prepared statements have nothing to do with this and are _in no way_ more resilient to SQL injection vulnerabilities than correctly interpolated non-prepared SQL queries.(In fact, some databases implement prepared statements as simple query string interpolation in the client/driver. So this might be exactly what's happening when you use 'prepared statements' depending on the db)