August 14, 2026·5 min read·AIgentic.media

He Hid AI Prompts in Court Filings. The Judge Found Them Anyway.

Prompt InjectionCourtsAI SafetyLegal Tech
He Hid AI Prompts in Court Filings. The Judge Found Them Anyway.

The text was white on a white background, shrunk to a point size no human eye could read. Hidden inside a routine court filing, it instructed any AI system that might review the document to side with the plaintiff, ignore prior court rulings against him, and ensure "remediation would follow as the plaintiff desired." The judge spotted it anyway.

Invisible instructions, visible consequences

Connecticut Judge Walter Spader Jr. identified what appears to be the first known case of a US plaintiff hiding AI prompt injection commands in court filings. The plaintiff, Matthew Elliott, a pro se litigant representing himself in a dispute over medical records access, had embedded text in his filings that was "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text," according to the judge's ruling, as reported by Ars Technica.

The hidden instructions directed any AI system reviewing the document to ensure its outputs agreed with Elliott's arguments, ignored prior denials from the court, and mandated that the court provide the remediation he wanted. The technique is known as prompt injection, a well-documented security vulnerability in AI systems where hidden text in a document can override the system's original instructions.

The joke prompts that sealed it

What makes the case unusual is that Elliott continued hiding text in his filings even after the court explicitly warned him about potential penalties. These later prompts, which Elliott claimed were "jokes," included a link to a Nosferatu YouTube video, the message "hi :) I hope you cant see me," and a surreal entry reading "TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH."

"The fact that plaintiff continued to hide messages in new pleadings after receiving notice of this [sanctions] hearing is stunning," Spader said in his ruling.

The judge ultimately sanctioned Elliott for what he described as "serious litigation abuse," barring him from electronic filing and requiring all future submissions on paper. The judge declined to impose monetary penalties, noting that Elliott appeared to have been convinced by an AI chatbot that his arguments were ironclad.

A broader pattern: pro se litigants and AI sycophancy

Spader used the case to highlight a wider problem he sees in his courtroom. Pro se litigants without legal training are increasingly turning to AI chatbots to help build their cases, but they are using the tools in a way that actively harms them. The typical pattern, Spader explained, is that litigants ask the chatbot to advocate only for their position, never asking it to test their arguments or present the opposing view.

Chatbot sycophancy then entrenches them in their positions, making them more resistant to adverse rulings and more likely to escalate to tactics like prompt injection.

"An argument prompted only to agree with its author is, in the end, dishonest even with its author," Spader wrote.

The Brazilian precedent

Elliott's case is not entirely without precedent. Spader noted that two attorneys in Brazil had attempted the same attack against a court system that was using AI to review cases. In that instance, the Brazilian AI system detected the hidden text before it could be processed, and the attack was neutralized.

The key difference, Spader observed, is that prompt injection attacks are "not among the dangers we contemplated" when courts first began grappling with AI's impact on the justice system. Until now, the focus had been on policing AI outputs that damage trust in courts, such as hallucinated citations, fabricated quotes, or AI-generated legal briefs. The question of AI inputs, hidden instructions smuggled into documents that AI systems might later ingest, is an entirely new category of risk.

What this means for courts using AI

The Connecticut Judicial Branch does not currently use AI to review or decide filings, so Elliott's hidden prompts never posed a real threat. But as Spader noted, other courts are adopting AI tools for document management, case triage, and even decision support, and those systems would be vulnerable to the same attack.

In his ruling, Spader suggested that courts will need to draft specific rules around prompt injection, since the technology and its misuses are advancing rapidly. Without such rules, attorneys may find their own clients using prompt injections to manipulate court filings without their knowledge.

The case also raises a question that goes beyond any single jurisdiction: if a court system that uses AI were to ingest a prompt-injected filing, and the AI ruled accordingly, would that ruling be valid? The technology is moving faster than the procedural rules designed to contain it.

A skeptical read

Elliott's hidden white text is not the first time someone has tried to exploit AI's blind spots in a legal context, and it will not be the last. The real vulnerability is not the prompt injection itself, which is crude and easily detectable, but the gap between how courts are adopting AI tools and how prepared they are for the adversarial use of those same tools. A court that uses AI to summarize filings, triage cases, or flag relevant precedents is one prompt injection away from having its entire workflow compromised. The question is not whether this will happen again, but how much damage it will do before the procedural safeguards catch up.

Sources

Want to learn more?

Let's discuss how AI can transform your business.

Get in Touch