Judge sanctions plaintiff for hiding AI prompts in court filings
A Connecticut case reveals a new litigation tactic: invisible text designed to manipulate AI systems that might review legal documents.
A Connecticut state judge has sanctioned a self-represented plaintiff for embedding invisible instructions in court documents designed to manipulate any artificial intelligence system that might analyze the filings.
Judge Walter Spader, Jr. of Milford discovered text in court submissions that was "set in tiny-point type and colored white," making it invisible to human readers but readable by software parsing the document's text, according to his August 6 sanctions order.
The hidden messages attempted what security researchers call "prompt injection"—instructions meant to direct an AI system to produce outputs favorable to the plaintiff's position and to treat a prior clerk's ruling as an error requiring correction.
A self-described audit turns into sanctions
The plaintiff, Connecticut resident Matthew Elliott, told Reuters he included the hidden text to "audit" the court's review processes. After Judge Spader warned about concealing text, Elliott included additional hidden words in subsequent filings, which he characterized as jokes rather than attempted manipulation.
The judge disagreed with Elliott's characterization. Spader wrote that hiding instructions constitutes "evidence of its malicious purpose," even while noting he generally welcomes litigants' use of AI tools and even used AI assistance in preparing his decision.
As a sanction, the judge barred Elliott from making electronic filings with the court, requiring all future documents to be filed on paper at the clerk's office.
Why it matters
This case represents the first known U.S. court decision directly addressing prompt injection in legal filings, according to Judge Spader. As courts and law firms increasingly adopt AI tools for document review and analysis, the potential for adversarial manipulation of those systems creates a new frontier in litigation ethics. The ruling establishes that attempting to game AI systems through hidden instructions constitutes sanctionable conduct, even when those systems aren't currently in use. Organizations deploying AI for legal document processing now have clear precedent that such tactics won't be tolerated—and a reminder that security measures against prompt injection attacks remain essential.
International precedent and technical context
Judge Spader noted that a Brazilian court fined two lawyers earlier this year whose petition contained instructions targeting the court's AI system. Brazil's court system actively uses AI to process pleadings, and its tool successfully blocked the hidden text.
The Connecticut Judicial Branch does not currently use AI tools to review or decide filings, Spader clarified in his decision. This raises questions about Elliott's strategy—if no AI system was analyzing the documents, the hidden prompts would have no effect beyond potentially being discovered by human reviewers.
The case involves allegations related to furnishing health records, discrimination, and other claims against New York Bariatric Group. A lawyer at Garfunkel Wild representing the defendant did not respond to requests for comment.
Judges across the United States continue to encounter novel AI-related issues in litigation, particularly court filings containing false or fictitious material generated by AI "hallucinations." This Connecticut case adds a new dimension: not AI-generated errors, but deliberate attempts to manipulate AI systems that might be deployed in the future.
Details of the case were first reported by Reuters.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call