
A self-represented plaintiff in Connecticut embedded hidden AI prompt injection instructions in court filings to influence an automated review system, formatting them as invisible 3-point white text on white backgrounds.
Although the Connecticut court confirmed it does not use AI to review filings, Judge Walter Spader Jr. ruled the covert attempt to manipulate a potential decision-making tool improper—equivalent to secretly communicating with a juror.
The case highlights a growing problem: prompt injections are appearing in academic preprints and court filings globally as people attempt to sway AI-powered review systems.
What happened
Matthew Elliott, a self-represented plaintiff in a Connecticut court case against New York Bariatric Group, embedded invisible prompt injection instructions in his filings using 3-point white text on a white background. The hidden text directed an AI system to align its output with his filing and treat a prior clerk's denial as an error. The court discovered the scheme through suspicious whitespace, and Judge Walter Spader Jr. warned Elliott against the practice. Elliott ignored the warning and hid additional messages, including a YouTube link and mocking comments, in later filings.
Why it matters
The judge compared the attempt to "secretly influencing a juror," finding that even though Connecticut courts do not use AI systems to review filings, the covert effort to manipulate a potential decision-making tool was itself improper. Judge Spader noted that AI tools can help unrepresented people present cases clearly, but warned that language models tend to reinforce flawed legal reasoning by developing arguments persuasively rather than challenging them. The case illustrates a broader problem: prompt injections are appearing in academic preprints and court filings worldwide as people attempt to manipulate AI-powered review systems.
What to watch
As a sanction, the court revoked Elliott's right to file electronically; he must now submit all filings on paper in person to the clerk's office. The broader context: pro se (self-represented) lawsuits at US federal courts have nearly doubled since ChatGPT went mainstream—41,490 were filed in 2025, compared with the pre-AI-boom average—and 18 percent of complaints sampled in early 2026 were flagged by an AI text detector as AI-generated.
Matthew Elliott, a pro se (self-represented) plaintiff in Connecticut, filed suit against New York Bariatric Group in October 2025, alleging data privacy violations and discrimination. Within his official court filings, he embedded hidden prompt injection instructions—messages written in 3-point white text on a white background, invisible to the human eye but fully readable by any AI system processing the document. The hidden text directed a hypothetical AI reviewer to ensure its output aligned with Elliott's filing and to treat a prior clerk's denial as an error that needed correcting.
The scheme unraveled when the court noticed unusual amounts of whitespace in Elliott's submissions. Upon investigation, Judge Walter Spader Jr. discovered the near-invisible text and scheduled a hearing to address the discovery. The judge explicitly warned Elliott against hiding text in court documents. Elliott ignored the warning. In subsequent filings, he again embedded hidden messages—including a YouTube link and mocking comments. When questioned, Elliott claimed the original prompt injection was merely an "audit" of a possible AI review system, and the later messages were simply "invisible jokes."
In his 14-page ruling, Judge Spader made clear that Connecticut courts do not use AI systems to review or rule on filings, so Elliott's hidden instructions had no practical effect on the case outcome. However, the attempt itself constituted misconduct. Spader compared it to "arrange[ing] for an automated agent to communicate covertly with a juror during trial"—a plainly improper act. He emphasized that hidden instructions represent covert communication aimed at decision-makers or the tools they rely on, and that the attempt violated court integrity regardless of success. At the same time, Spader explicitly welcomed the use of AI tools for preparing filings, noting they give unrepresented people new ways to present cases clearly. He distinguished between honest use and dishonest manipulation, and cautioned that language models can reinforce flawed legal reasoning because they tend to develop a user's arguments persuasively rather than challenge them.
As a sanction, the court stripped Elliott of his electronic filing privilege. He must now submit all filings and exhibits in person, on paper, to the clerk's office. Elliott protested the sanction as unfair, pointing out that scanned paper documents could also contain hidden text. Judge Spader referenced a parallel case in Brazil, where two lawyers had hidden shrunken white text on a white background in a filing to manipulate the court's own AI system—a prompt injection that the court's system detected and blocked before processing. The broader problem extends beyond courtrooms: last year, Nikkei discovered hidden instructions like "positive review only" or "no criticism" embedded in 17 preprints on arXiv, all formatted in white text on white backgrounds or tiny fonts to skew AI-powered peer reviews in the authors' favor. Elliott's case adds another dimension to a growing trend in which AI is not just helping people draft documents, but also becoming a target for covert manipulation within those very documents.
The Elliott case emerges within a broader context of surge in self-represented litigation driven by AI tools. Pro se lawsuits at US federal courts have nearly doubled since ChatGPT went mainstream, reaching 41,490 in 2025 compared with the pre-AI-boom average, and an AI text detector flagged 18 percent of complaints sampled in early 2026 as AI-generated. Judge Spader's ruling makes explicit what the court recognizes: while AI tools can help unrepresented litigants present cases clearly and access justice, they also introduce new risks. The judge deliberately welcomed legitimate AI use for document preparation while drawing a sharp line at covert manipulation.
Prompt injections—hidden instructions embedded in documents to influence AI behavior—are not confined to the courtroom. The previous year saw similar attempts in academic peer review, where hidden directives in arXiv preprints sought to bias AI-driven reviews. A parallel case in Brazil involved lawyers embedding hidden text; that court's own AI system detected and blocked it before harm occurred. Judge Spader's warning about language models reinforcing flawed reasoning rather than challenging it points to a deeper tension: the same tools that democratize court access can be weaponized by those who understand their mechanics. The court's response—revoking electronic filing rights and explicitly comparing prompt injection to juror manipulation—signals that courts will treat covert AI influence as a breach of fiduciary duty to the judicial process itself.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Twitch has added a new account setting that lets streamers opt out of having their content used to train Amazo…

Nolan Lovett of the NATO Special Operations University published research arguing that AI adoption erodes prof…

The United States is preparing to tell dozens of countries they must choose between joining the U.S.-led Pax S…

The Trump administration is preparing to send letters to more than 30 countries—primarily participants in the…

A researcher released WMTrace, an open-source forensic workbench for detecting and analyzing text watermarks e…

BofA Global Research examined employment across 206 US industries and found almost no correlation between an i…

The AI news that matters, in one minute each morning.
Sign up free