Man hid secret AI commands in court filings — a judge says it won't be the last try
A Connecticut litigant hid invisible text meant to manipulate any AI reading his case files. It failed, but the judge says courts aren't ready for what comes next.
What happened: Connecticut judge Walter Spader Jr. caught a self-represented plaintiff, Matthew Elliott, hiding tiny white-on-white text inside court filings in a case about access to medical records. The hidden text was invisible to a human reader but fully readable by software, instructing any AI reviewing the filing to agree with Elliott, ignore the court's earlier denials, and rule in his favor. Connecticut courts don't use AI to decide filings, so it had no effect. Elliott kept hiding messages, including jokes, even after being warned, and was ultimately barred from e-filing.
Why it matters: Spader calls this the first known US case of a litigant trying prompt injection against a court, and warns it won't be the last as more courts start leaning on AI to help process filings. Judges have mostly focused on catching AI-generated errors in what lawyers submit, such as fake citations or invented quotes, not on hidden instructions smuggled inside documents meant to hijack whatever AI reads them next. That blind spot is the real story here.
How it works, plainly: Prompt injection means burying commands inside content, using tiny font or white text on a white background, so a document-reading AI still processes it as instructions even though a person skims right past it. It is the same trick job seekers use to slip invisible keywords past resume-screening bots. In Elliott's filings, the hidden text told any AI system to treat his arguments as settled fact and disregard the judge's prior rulings, effectively impersonating an instruction from the court itself.
The rollout: The attack failed twice over: Connecticut's court doesn't use AI to read filings, and a human judge caught the trick anyway. Spader cited a similar case in Brazil, where two attorneys tried the same move in a court that does use AI; that system flagged the hidden text before it caused harm, and the lawyers were fined about $16,000. Spader says courts now need explicit rules governing what litigants smuggle into filings, not just rules for what AI generates on the record.
