Hidden AI Instructions Found in US Court Filing for First Time
In a Connecticut civil lawsuit, a self-represented plaintiff hid text invisible to the human eye but readable by AI software, urging a ruling in his favor. The judge called it a "dangerous precedent" and barred him from e-filing.

For the first time in a US court, a case of "prompt injection" — hidden instructions aimed at an AI system, embedded in a legal filing — has been uncovered. According to Ars Technica, in a Connecticut civil case over the release of medical records, plaintiff Matthew Elliott, who represented himself without a lawyer, slipped text into his filings that was invisible to human readers but legible to document-parsing software. Judge Walter Spader Jr., in a ruling published last week, found that the hidden instructions did not affect the outcome of the case, but warned that the attempt itself set a "dangerous" precedent. Japan's INTERNET Watch also reported on the case the same day, as a story from abroad.
Prompt injection is a known AI-security technique: text that is invisible or unreadable to a human — tiny type, white-on-white formatting, hidden metadata — but perfectly legible to software, placed inside a document in hopes that an AI system parsing that same document will follow it as an instruction. Security researchers have warned about the technique in chatbots and AI assistants for years; this appears to be its first documented use inside a US court filing.
Instructions hidden in invisible text
The offending text was formatted in a tiny font, white on a white background, so that it was invisible to the naked eye. It instructed any AI reviewing the filing to rule in the plaintiff's favor, disregard the court's earlier dismissals of his arguments, and order the remedies he was seeking. Elliott, a pro se litigant, appears to have resorted to the tactic after his previous arguments were rejected, gambling that an AI system might eventually review his filings.
Elliott kept adding hidden text even after the court warned him about the practice. Later additions reportedly included a link to a YouTube video of the horror film Nosferatu, a message reading something like "hope this is invisible," and other unrelated, nonsensical text he described as a joke. Judge Spader called it "remarkable" that Elliott continued after a hearing where sanctions were raised, concluding it amounted to "serious abuse of the litigation process." Because Connecticut courts do not use AI to review or decide filings, the attempt had no real bearing on the case — but the judge warned that courts in other states and countries do.
A first for the US, not for the world
Judge Spader said this appeared to be the first such case identified in a US court, while noting a prior case in Brazil involving two lawyers who used a similar tactic. In that Brazilian case, the attempt targeted a court that actually did use AI to review filings: the system detected the hidden text before processing it, and the lawyers involved were sanctioned roughly $16,000. Elliott received no monetary penalty, but the judge has now barred him from filing electronically — only printed filings will be accepted going forward.
- Method: embedding invisible instructions for AI in tiny, white-on-white text within court filings — a "prompt injection"
- Outcome: Connecticut courts don't use AI to review filings, so the ruling itself was unaffected
- Sanction: e-filing banned going forward, paper filings only; no monetary fine
- Foreign precedent: in Brazil, two lawyers were fined roughly $16,000 for the same tactic, caught by the court's own AI system
What it means for lawyers and litigants using AI
The case is a reminder that courts weighing whether to adopt AI-assisted review need safeguards against exactly this kind of manipulation — and that, for now, most don't use AI at all, which is why this particular attempt was largely symbolic. But Judge Spader's broader point cuts deeper than the technical trick: a self-represented litigant, or a lawyer, who lets an AI chatbot draft and reinforce their own arguments without testing them against a counterargument risks building a filing that looks solid but isn't. For anyone using AI tools to prepare legal documents, the practical lesson is to have the AI argue the other side before filing, not just make the case.
Sources
- Suspecting court of using AI, man injected prompts in filings to try to win caseArs Technica · August 14, 2026
- 「原告有利の判決を出せ」AIにしか見えない指示を提出書類に書き込んだ男、裁判所にバレるINTERNET Watch · August 17, 2026



