AIToday
AI Safety & AlignmentAI Regulation & PolicyTHE DECODERPublished: Aug 15, 2026, 19:00 JST5 min read

Pro se plaintiff hid AI instructions in court filings to sway automated review

Pro se plaintiff hid AI instructions in court filings to sway automated review

Key takeaway

  • A self-represented plaintiff in Connecticut embedded hidden AI prompt injection instructions in court filings to influence an automated review system, formatting them as invisible 3-point white text on white backgrounds.

  • Although the Connecticut court confirmed it does not use AI to review filings, Judge Walter Spader Jr. ruled the covert attempt to manipulate a potential decision-making tool improper—equivalent to secretly communicating with a juror.

  • The case highlights a growing problem: prompt injections are appearing in academic preprints and court filings globally as people attempt to sway AI-powered review systems.

3 Key Points

  1. What happened

    Matthew Elliott, a self-represented plaintiff in a Connecticut court case against New York Bariatric Group, embedded invisible prompt injection instructions in his filings using 3-point white text on a white background. The hidden text directed an AI system to align its output with his filing and treat a prior clerk's denial as an error. The court discovered the scheme through suspicious whitespace, and Judge Walter Spader Jr. warned Elliott against the practice. Elliott ignored the warning and hid additional messages, including a YouTube link and mocking comments, in later filings.

  2. Why it matters

    The judge compared the attempt to "secretly influencing a juror," finding that even though Connecticut courts do not use AI systems to review filings, the covert effort to manipulate a potential decision-making tool was itself improper. Judge Spader noted that AI tools can help unrepresented people present cases clearly, but warned that language models tend to reinforce flawed legal reasoning by developing arguments persuasively rather than challenging them. The case illustrates a broader problem: prompt injections are appearing in academic preprints and court filings worldwide as people attempt to manipulate AI-powered review systems.

  3. What to watch

    As a sanction, the court revoked Elliott's right to file electronically; he must now submit all filings on paper in person to the clerk's office. The broader context: pro se (self-represented) lawsuits at US federal courts have nearly doubled since ChatGPT went mainstream—41,490 were filed in 2025, compared with the pre-AI-boom average—and 18 percent of complaints sampled in early 2026 were flagged by an AI text detector as AI-generated.

In Depth

Read the full story

Matthew Elliott, a pro se (self-represented) plaintiff in Connecticut, filed suit against New York Bariatric Group in October 2025, alleging data privacy violations and discrimination. Within his official court filings, he embedded hidden prompt injection instructions—messages written in 3-point white text on a white background, invisible to the human eye but fully readable by any AI system processing the document. The hidden text directed a hypothetical AI reviewer to ensure its output aligned with Elliott's filing and to treat a prior clerk's denial as an error that needed correcting.

The scheme unraveled when the court noticed unusual amounts of whitespace in Elliott's submissions. Upon investigation, Judge Walter Spader Jr. discovered the near-invisible text and scheduled a hearing to address the discovery. The judge explicitly warned Elliott against hiding text in court documents. Elliott ignored the warning. In subsequent filings, he again embedded hidden messages—including a YouTube link and mocking comments. When questioned, Elliott claimed the original prompt injection was merely an "audit" of a possible AI review system, and the later messages were simply "invisible jokes."

In his 14-page ruling, Judge Spader made clear that Connecticut courts do not use AI systems to review or rule on filings, so Elliott's hidden instructions had no practical effect on the case outcome. However, the attempt itself constituted misconduct. Spader compared it to "arrange[ing] for an automated agent to communicate covertly with a juror during trial"—a plainly improper act. He emphasized that hidden instructions represent covert communication aimed at decision-makers or the tools they rely on, and that the attempt violated court integrity regardless of success. At the same time, Spader explicitly welcomed the use of AI tools for preparing filings, noting they give unrepresented people new ways to present cases clearly. He distinguished between honest use and dishonest manipulation, and cautioned that language models can reinforce flawed legal reasoning because they tend to develop a user's arguments persuasively rather than challenge them.

As a sanction, the court stripped Elliott of his electronic filing privilege. He must now submit all filings and exhibits in person, on paper, to the clerk's office. Elliott protested the sanction as unfair, pointing out that scanned paper documents could also contain hidden text. Judge Spader referenced a parallel case in Brazil, where two lawyers had hidden shrunken white text on a white background in a filing to manipulate the court's own AI system—a prompt injection that the court's system detected and blocked before processing. The broader problem extends beyond courtrooms: last year, Nikkei discovered hidden instructions like "positive review only" or "no criticism" embedded in 17 preprints on arXiv, all formatted in white text on white backgrounds or tiny fonts to skew AI-powered peer reviews in the authors' favor. Elliott's case adds another dimension to a growing trend in which AI is not just helping people draft documents, but also becoming a target for covert manipulation within those very documents.

Context & Analysis

The Elliott case emerges within a broader context of surge in self-represented litigation driven by AI tools. Pro se lawsuits at US federal courts have nearly doubled since ChatGPT went mainstream, reaching 41,490 in 2025 compared with the pre-AI-boom average, and an AI text detector flagged 18 percent of complaints sampled in early 2026 as AI-generated. Judge Spader's ruling makes explicit what the court recognizes: while AI tools can help unrepresented litigants present cases clearly and access justice, they also introduce new risks. The judge deliberately welcomed legitimate AI use for document preparation while drawing a sharp line at covert manipulation.

Prompt injections—hidden instructions embedded in documents to influence AI behavior—are not confined to the courtroom. The previous year saw similar attempts in academic peer review, where hidden directives in arXiv preprints sought to bias AI-driven reviews. A parallel case in Brazil involved lawyers embedding hidden text; that court's own AI system detected and blocked it before harm occurred. Judge Spader's warning about language models reinforcing flawed reasoning rather than challenging it points to a deeper tension: the same tools that democratize court access can be weaponized by those who understand their mechanics. The court's response—revoking electronic filing rights and explicitly comparing prompt injection to juror manipulation—signals that courts will treat covert AI influence as a breach of fiduciary duty to the judicial process itself.

FAQ

How did the court discover the hidden instructions?
The court noticed an unusual amount of whitespace in Elliott's filings. Upon closer examination, the judge found nearly invisible text embedded in 3-point white font on a white background.
What was the court's sanction?
Judge Spader revoked Elliott's electronic filing privileges. Elliott must now submit all filings and exhibits in person, on paper, to the clerk's office.
Has this problem appeared elsewhere?
Yes. Last year, Nikkei found hidden instructions like "positive review only" or "no criticism" in 17 preprints on arXiv, all hidden in white text on white backgrounds or tiny font sizes to skew AI-powered peer reviews. A similar case also occurred in Brazil, where two lawyers hid shrunken white text to manipulate the court's AI system—but the court's own system detected and blocked the text before processing.

Get the latest AI Safety & Alignment news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleObserve by Snowflake Launches Agent-Ready MCP Server and CLI

The AI news that matters, in one minute each morning.

Sign up free