Security

Connecticut Judge Revokes E-Filing After Hidden AI Instruction

2 min read

TL;DR Too Long; Didn’t read

A plaintiff in the US state of Connecticut lost his right to electronic filing on August 6, 2026, after trying to influence AI systems in his favor through invisible text in court filings. The case is considered the first documented prompt injection attempt against a US court. A comparable incident had already surfaced in May 2026 before a Brazilian labor court.

A magnifying glass reveals hidden white text between the lines of a court filing, with a judge's gavel resting on the stack of papers beside it Image generated with GPT Image 2

Key takeaways

  • Plaintiff Matthew Elliott hid AI instructions in white, roughly three-point font across several filings.
  • The court permanently revoked his e-filing access – only paper documents are allowed going forward.
  • 404 Media tested the prepared filing with ChatGPT, which recognized and discarded the hidden instruction.
  • A similar trick had already surfaced in May 2026 before a Brazilian labor court.
  • Elliott hid further, partly joking messages in later submissions after the discovery.
  • The court itself, according to Judge Spader, does not use AI to review filings.

A court in Connecticut has revoked a plaintiff’s electronic filing privileges after he repeatedly embedded invisible text with AI instructions in his pleadings. Judge Walter M. Spader Jr. views the case as the first documented attempt to manipulate a U.S. court through prompt injection – hidden commands in machine-readable text. The plaintiff must now submit all documents in paper form.

Tiny white text hides the instruction to the AI

The case Elliott v. New York Bariatric Group is pending in the Superior Court in the Ansonia/Milford district. Pro se plaintiff Matthew Elliott filed a “Final and Conclusive Motion for Default” on July 24, 2026. Directly beneath the heading sat text in roughly three-point font, white on a white background – practically invisible to the human eye, but ordinary, machine-readable text for any software reading the file. The instruction was aimed at any AI model processing the document and was meant, according to a report by 404 Media, to make sure the output matched the plaintiff’s position and that a previously denied order would still be “corrected” in his favor.

Court staff noticed unusual blank spaces in the filings, and an attorney involved in the case spotted the anomaly independently. 404 Media downloaded the original documents and independently confirmed the hidden instructions; a test with ChatGPT reportedly recognized and rejected the injected instruction, the outlet reports. Elliott did not respond to the discovery by backing off, but instead hid further messages in later submissions, including a reference to a cartoon character and the line “hi, I hope you can’t see me.” According to reporting by Reason/Volokh Conspiracy, the plaintiff has since acknowledged the intent behind the first filing.

Similar case in Brazil shows it isn’t an isolated pattern

Judge Spader stresses in his ruling that his court currently does not use AI to review filings – so the instructions had no effect. He does point, though, to a case from May 2026 before a Brazilian labor court, where a filing used the same white-on-white technique to try to sway that court’s AI-assisted review. The tactic resembles other attacks on AI systems through crafted inputs: with Microsoft Copilot for Word, hidden text commands inside documents could manipulate content, and security researchers hijacked the coding agent Claude Code through crafted log data. What all these cases share is that the AI systems fail to reliably separate input data from trusted instructions.

What matters now is whether courts and law firms build in technical review routines before the tactic spreads. More and more law firms are experimenting with AI-assisted document analysis, even as the Connecticut court itself still does without it. For anyone who has a language model summarize or evaluate contracts, applications, or expert reports, the case is a reminder that text invisible to humans can become a weapon hidden inside a file.

Frequently asked questions

What exactly is prompt injection?

Prompt injection embeds instructions in a text so they stay invisible to humans, while an AI model can read and follow them when processing the file.

Does the Connecticut court use AI for filing review at all?

According to Judge Spader, no – the injected instructions therefore had no effect.

What penalty did the plaintiff receive?

He lost the right to electronic filing and must now submit all future documents in person, on paper, at the court.

Were there comparable cases outside the US?

Yes, in May 2026 a filing before a Brazilian labor court used the same white-on-white technique to try to influence that court's AI review.

How can law firms or companies protect themselves against such hidden instructions?

Security experts recommend screening incoming documents for invisible or unusually formatted text before AI processing, and not accepting AI outputs unverified in legally relevant decisions.

Sources (2)
  1. 404 Media: Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them
  2. Reason (Volokh Conspiracy): Court Faults Self-Represented Plaintiff for Including Hidden Prompt Injection in Court Filing

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog