AIToday
Ars Technica AIPublished: Aug 15, 2026, 04:01 JST5 min read

Man hid AI prompts in court filing to sway case, judge warns of 'dangerous' trend

Man hid AI prompts in court filing to sway case, judge warns of 'dangerous' trend

Key takeaway

  • A Connecticut man embedded hidden AI prompts in court filings designed to manipulate any AI system reviewing his documents, marking what appears to be the first US case of prompt injection in court.

  • Although the court does not use AI to decide cases and the tactic failed, Judge Walter Spader Jr. warned it sets a 'dangerous' precedent and that courts must draft new rules to address the attack, which is already appearing in other countries' court systems and may spread as pro se litigants increasingly misuse chatbots.

3 Key Points

  1. What happened

    A Connecticut plaintiff, Matthew Elliott, embedded hidden text formatted as AI prompts in court filings, instructing any AI system reviewing the documents to favor his arguments and ignore prior court denials. Judge Walter Spader Jr. ruled that the hidden text—shrunk to tiny font and colored white on white background—had no impact on the case's outcome, but Elliott continued adding hidden messages even after being warned of sanctions, including claims they were jokes.

  2. Why it matters

    This appears to be the first documented case in the US of prompt injection used in court filings, a tactic designed to manipulate AI systems. Although Connecticut's court system does not use AI to review cases, Spader warned the attack sets a 'dangerous' precedent and that courts will likely need to draft new rules to address prompt injection as the tactic spreads—similar attacks have already occurred in Brazil's court system, where two attorneys were hit with sanctions of about $16,000.

  3. What to watch

    Spader flagged a broader problem: pro se litigants (self-represented people without lawyers) are increasingly using chatbots to build their cases but often ask the AI only to support their own position rather than test it, entrenching them in flawed arguments. Spader prohibited Elliott from e-filing in the future, requiring him to submit paper filings instead, and warned that attorneys may find their own clients using prompt injection without their knowledge if courts do not establish clearer guardrails.

In Depth

Read the full story

Matthew Elliott, a pro se litigant in a healthcare records access dispute, embedded hidden text in his court filings formatted to be invisible to human readers but legible to software. The text was shrunk to tiny-point type and colored white on a white background. These prompts instructed any AI system reviewing the document to ensure outputs agreed with Elliott's arguments, ignore prior court denials, and guarantee remediation as he desired—a classic prompt injection attack meant to manipulate AI decision-making.

When Judge Walter Spader Jr. discovered the hidden prompts, he ruled they had no impact on the case outcome, which was decided on the merits by human judgment. However, Elliott's conduct escalated: after receiving notice of a sanctions hearing, he continued adding hidden messages to new filings. Some he later claimed were jokes, including a link to a Nosferatu YouTube video, the phrase "hi :) I hope yo ucant see me," and "TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH." Spader found this escalation "stunning" and evidence of persistent litigation abuse.

Elliott defended himself by claiming the original prompt was an attempt to "audit" the court as a public service, motivated by suspicion that the court was improperly using AI to decide cases. But Spader rejected this rationale, noting that Elliott was "free to write so in plain, visible words that everyone could see and answer" and that hiding the text was "evidence of its malicious purpose." The judge explained that by concealing a command inside a document for an AI system to ingest later, the filer attempts to "smuggle their own instruction into that stream so that the system treats it as though it had come from the system's operator"—in this case, the court, its staff, or opposing counsel.

Spader ruled that sanctions were warranted because the hidden messages attempted to communicate with the court in a covert manner that excluded defendants from fair participation. He declined to impose monetary penalties on Elliott as a pro se litigant but prohibited him from e-filing in the future, requiring paper filings instead. The judge noted that while Connecticut's Judicial Branch does not use AI to review or decide filings, "a number of court systems elsewhere" do, creating real risk that such attacks could succeed elsewhere.

The judge warned that prompt injection attacks are now "everywhere"—common in job hunting and other domains—and that courts must be on guard. Although an earlier case in Brazil involved two attorneys who used the same tactic in a court with AI review and received sanctions of about $16,000, Brazil's AI system caught the hidden text before processing, and Elliott's prompts were "exposed, in each of those settings, the moment a human being actually looked at what the machine produced." Nevertheless, Spader stressed that prompt injection "was not among the dangers we contemplated" when courts began grappling with AI, and courts will likely need to draft new rules to address it.

Spader also identified a broader lesson: pro se litigants using chatbots frequently ask the AI only to support their own position rather than test it, building arguments backward and entrenching themselves despite court rulings to the contrary. This "genuine hazard of the technology" can drive litigants toward desperate measures. Spader concluded that those using chatbots "must ask them to test a position as readily as to advance it," and warned that without clearer guardrails, attorneys may find their own clients embedding prompt injections in court filings without their knowledge.

Context & Analysis

Judge Spader's decision exposes a collision between two emerging courtroom challenges: the rising use of AI by courts to manage caseloads, and the misuse of AI by litigants seeking an edge. Although Connecticut's judicial system does not currently deploy AI to review or decide filings, the judge treated Elliott's prompt injection as a serious threat that other courts—especially those using AI—must anticipate. The fact that the tactic has already surfaced in Brazil, where it was caught by the court's own AI system before reaching human review, suggests the threat is real and evolving faster than courts' defensive policies.

The judge identified a systemic vulnerability in how pro se litigants use chatbots. Rather than asking an AI to stress-test their position or argue both sides of a dispute, Elliott and others like him ask the chatbot only to validate their own view. This creates a false sense of legal strength and, when arguments fail in court, can drive litigants toward desperate measures like hidden prompts. Spader framed this as a "genuine hazard of the technology," one that judges now encounter frequently. His ruling therefore addresses not just Elliott's misconduct but a broader pattern of AI misuse that could undermine the integrity of court filings if left unchecked.

FAQ

What exactly did the hidden text in the filing instruct?
The hidden prompts directed any AI system reviewing the document to ensure textual outputs agreed with the plaintiff's arguments, ignored prior denials from the court, and ensured that remediation would follow as the plaintiff desired.
Has prompt injection in court filings happened elsewhere?
Yes, in Brazil two attorneys used the same attack in a court that was using AI to review cases and were hit with sanctions of about $16,000; however, Brazil's AI system caught the hidden text before it was processed.
What penalty did the judge impose on Elliott?
The judge prohibited Elliott from e-filing in the future, requiring him to submit paper filings instead, rather than ordering monetary penalties.
Ars Technica AIRead Original Article

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleInstagram redesigns wordmark; Zuckerberg outlines AI-for-all vision

The AI news that matters, in one minute each morning.

Sign up free