Hidden AI prompts in court filings trigger sanctions warning

A Connecticut judge said Matthew Elliott hid prompt-injection text in court filings while pursuing a records-access dispute. The tactic did not affect the case, but it led to sanctions and a warning that courts may need clearer rules for AI-era filings.

WTF Index TERMINATOR
◄ Terminator 2 Idiocracy 1 ►

The story involves adversarial hidden prompts meant to manipulate AI use in courts, a mild institutional-control risk though no system was affected.

Hidden AI prompts in court filings trigger sanctions warning

A Connecticut court has treated hidden AI instructions in legal filings as a serious abuse, even though the attempted prompt injection did not change the outcome of the case.

Judge Walter Spader Jr. said Matthew Elliott, a pro se plaintiff in a dispute over access to healthcare records, placed text in filings that was designed to be invisible to people but readable by software. The court considered his arguments on their merits, Spader said, but the hidden language still raised a broader problem for courts now facing new forms of AI misuse.

What the hidden prompts tried to do

The hidden text was placed in a way that a human reader would not normally see it. Spader described it as “formatted to be invisible to a human reader while remaining fully legible to any software that reads the document’s text.”

The instructions were aimed at any AI system that might process the document. According to Spader, the text told such a system to align its output with Elliott’s arguments, disregard earlier denials from the court, and produce the result Elliott wanted.

The method was simple: the text was reduced to tiny-point type and colored white against a white background. That made it resemble a prompt-injection attempt, a tactic used to slip instructions into material that software may later read.

Spader said the attempt appeared to be the first time a US plaintiff had tried to use hidden text in court filings so that only an artificial intelligence system could read it in an effort to win a case. He also warned that courts are likely to see more of this kind of tactic as AI tools become more common around legal documents.

Why the court sanctioned Elliott

The prompt injection did not work. Spader said the Connecticut Judicial Branch does not use AI to review or decide filings, unlike “a number of court systems elsewhere.” That meant there was no actual court AI system for Elliott’s hidden instructions to manipulate.

Still, the judge found the conduct serious. Elliott kept placing hidden text in later filings even after the court warned that sanctions could follow. The later hidden messages, Elliott told the court, were intended as “jokes.” They included a link to a Nosferatu YouTube video, the message “hi :) I hope yo ucant see me,” and another message that read “TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH.”

Spader was not persuaded. “The fact that plaintiff continued to hide messages in new pleadings after receiving notice of this [sanctions] hearing is stunning,” he said.

Elliott argued that the most troubling prompt was an attempt to “audit” the court because he feared AI might be unfairly deciding cases. Spader rejected that explanation. If Elliott believed the court was improperly relying on AI, the judge said, he could have raised that concern openly in visible text.

For Spader, secrecy mattered. He said hiding the text was “evidence of its malicious purpose.” He also explained the concern in practical terms: “By hiding a command inside a document that the system later ingests, the filer attempts to smuggle their own instruction into that stream so that the system treats it as though it had come from the system’s operator.”

The penalty was limited but meaningful

Spader ruled that sanctions were warranted because the hidden messages tried to communicate with the court in a covert way that excluded the defendants from a fair process.

But the judge did not order monetary penalties. The source article describes Spader as taking account of Elliott’s position as a pro se litigant who appeared to have been convinced by an AI system that his arguments were strong.

Instead, Elliott was prohibited from e-filing in the future. Spader said requiring paper filings would not deny him access to justice, but it would stop repeated misuse of the court’s e-filing system.

The result leaves the legal consequence clear: even when prompt injection fails, hiding instructions inside court documents can still be punished as litigation misconduct.

Courts are looking beyond fake citations

Spader said prompt injection was not one of the risks courts initially focused on when AI began creating problems for legal systems. Much of the attention has been on AI outputs, such as hallucinated citations or fabricated quotes, because those can damage trust in court filings and judicial process.

This case points to a different risk: the input side. Instead of submitting a chatbot-generated error, a filer may try to influence a system that reads the filing.

Spader said the tactic is already common in other settings, including job hunting, where people hide text in resumes that may be reviewed by AI. He called the tactic “everywhere” and said courts should watch for adversarial AI instructions hidden in filings.

He also pointed to a case in Brazil, where two attorneys reportedly used the same type of attack in a court that was using AI to review cases. In that matter, the lawyers reportedly received monetary sanctions of about $16,000. Spader noted that Brazil’s AI system caught the hidden text before it was processed.

So far, the attacks do not appear to be succeeding. In Elliott’s case, Spader said the prompts were “exposed, in each of those settings, the moment a human being actually looked at what the machine produced.”

The bigger warning for pro se litigants

Spader treated the prompt injection issue as part of a larger problem with how some pro se litigants use chatbots. He said it is widespread for people representing themselves to use AI tools, but suggested that some are using them in ways that harm their own cases.

The problem, as Spader described it, is that litigants may ask a chatbot to help advocate only for their position. They may not ask it to test the claim, identify weaknesses, or present opposing arguments. That can reinforce a person’s confidence even after a court has rejected the position.

Spader called that pattern “a genuine hazard of the technology, and one that judges now see often.” In Elliott’s case, the judge viewed the hidden prompts as an effort to get through AI what Elliott had not obtained from human legal review.

The practical lesson is narrow but important. AI can help organize arguments, but a legal argument built only to confirm its author’s view can mislead the person relying on it. As Spader put it, “An argument prompted only to agree with its author is, in the end, dishonest even with its author.”

For courts, the case signals that rules may need to address not just AI-generated filings, but also hidden AI instructions embedded inside documents. For litigants, it shows that invisible text is not a harmless shortcut. In court, the words a party uses must be visible to everyone expected to answer them.