Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Connecticut plaintiff embeds hidden AI prompts in court filings to manipulate automated review
00

Connecticut plaintiff embeds hidden AI prompts in court filings to manipulate automated review

Aug 14, 2026

In what is believed to be the first documented prompt injection attack on a U.S. court, self-represented plaintiff Matthew Elliott embedded invisible, white-on-white text in his filings in Elliott v. New York Bariatric Group. The hidden prompts instructed any reviewing AI system to rule in his favor. Connecticut Superior Court Judge Walter Spader Jr. sanctioned Elliott by revoking his electronic filing privileges. Although the Connecticut court does not use AI, the judge warned that such covert attempts to influence automated systems pose a dangerous threat to judicial integrity.

Hidden AI prompt injection attempt

  • ▪Matthew Elliott, a self-represented plaintiff in Elliott v. New York Bariatric Group, embedded hidden text in his court filings to instruct any reviewing artificial intelligence system to side with him.
  • ▪The hidden text in Matthew Elliott's filings was formatted in tiny, white-on-white font to be invisible to human readers while remaining machine-readable to document-processing software.
  • ▪After being warned by the court, Matthew Elliott continued to hide messages in subsequent filings, including a YouTube link, a SpongeBob SquarePants clip, and phrases he described as jokes.
  • ▪Matthew Elliott's hidden prompts instructed any reviewing AI model to ensure its output agreed with his filing, treat a prior clerk's ruling as an error, and ensure remediation.

Court sanctions for litigation abuse

  • ▪Connecticut Superior Court Judge Walter Spader Jr. sanctioned Matthew Elliott on August 6, 2026, by revoking his electronic filing privileges and requiring him to submit future filings on paper.
  • ▪Judge Walter Spader Jr. declined to issue monetary sanctions against Matthew Elliott, citing his status as a self-represented litigant, but characterized the hidden prompts as serious litigation abuse.
  • ▪Matthew Elliott defended his actions by stating the hidden directives were designed as an audit to determine whether the Connecticut court was using AI to process and decide cases.

Prompt injection security threat

  • ▪An analysis by Nikkei found hidden instructions like 'positive review only' embedded in white text on white backgrounds across 17 scientific preprints on arXiv to influence AI-powered peer reviews.
  • ▪In a separate May 2024 case in Brazil, Elisandro Martins de Barros v. Renato Ribeiro de Lima, two attorneys used a hidden prompt injection in a petition to manipulate the court's AI system.

AI use in judicial systems

  • ▪The Connecticut Judicial Branch does not use artificial intelligence systems to review, process, or decide court filings, meaning Matthew Elliott's hidden prompts had no impact on his case.
  • ▪Judge Walter Spader Jr. noted that Brazil's court AI system successfully detected and blocked the hidden prompt injection used by two attorneys before the text could be processed.

Pro se litigation challenges

  • ▪A study by MIT and USC found that the number of lawsuits filed without a lawyer at US federal courts surged to 41,490 in 2025, nearly double the pre-AI-boom average.
  • ▪Judge Walter Spader Jr. warned that language models can reinforce flawed legal reasoning for pro se litigants because chatbots tend to develop a user's arguments persuasively rather than challenge them.

4 sources

Arstechnica
Suspecting court of using AI, man injected prompts in filings to try to win case
View source article
Gizmodo
Dude Reportedly Hides Prompt Injections in Legal Filing, Just in Case Judge Is Really That Lazy
View source article
The Decoder
Plaintiff hid invisible AI instructions in court filings to secretly influence automated review
View source article
Newsweek
First known hidden AI directive in court filing raises "massive" concern
View source article

Featured stories

View more in AI security

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

OpenAI and Anthropic CEOs called to appear at Australian AI inquiry

Sep 27, 2026 · 2 sources

Protesters rally against OpenAI at DevDay over corporate practices

Sep 29, 2026 · 7 sources

Trump signs voluntary AI safety accord with tech executives

Sep 29, 2026 · 14 sources

Story comments

Loading comments…

Topics

AI securityJailbreaking & prompt injectionAI governancePrompt injection

Featured stories

View more in AI security

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

OpenAI and Anthropic CEOs called to appear at Australian AI inquiry

Sep 27, 2026 · 2 sources

Protesters rally against OpenAI at DevDay over corporate practices

Sep 29, 2026 · 7 sources

Trump signs voluntary AI safety accord with tech executives

Sep 29, 2026 · 14 sources