A court in Connecticut has revoked a plaintiff’s electronic filing privileges after he repeatedly embedded invisible text with AI instructions in his pleadings. Judge Walter M. Spader Jr. views the case as the first documented attempt to manipulate a U.S. court through prompt injection – hidden commands in machine-readable text. The plaintiff must now submit all documents in paper form.
Tiny white text hides the instruction to the AI
The case Elliott v. New York Bariatric Group is pending in the Superior Court in the Ansonia/Milford district. Pro se plaintiff Matthew Elliott filed a “Final and Conclusive Motion for Default” on July 24, 2026. Directly beneath the heading sat text in roughly three-point font, white on a white background – practically invisible to the human eye, but ordinary, machine-readable text for any software reading the file. The instruction was aimed at any AI model processing the document and was meant, according to a report by 404 Media, to make sure the output matched the plaintiff’s position and that a previously denied order would still be “corrected” in his favor.
Court staff noticed unusual blank spaces in the filings, and an attorney involved in the case spotted the anomaly independently. 404 Media downloaded the original documents and independently confirmed the hidden instructions; a test with ChatGPT reportedly recognized and rejected the injected instruction, the outlet reports. Elliott did not respond to the discovery by backing off, but instead hid further messages in later submissions, including a reference to a cartoon character and the line “hi, I hope you can’t see me.” According to reporting by Reason/Volokh Conspiracy, the plaintiff has since acknowledged the intent behind the first filing.
Similar case in Brazil shows it isn’t an isolated pattern
Judge Spader stresses in his ruling that his court currently does not use AI to review filings – so the instructions had no effect. He does point, though, to a case from May 2026 before a Brazilian labor court, where a filing used the same white-on-white technique to try to sway that court’s AI-assisted review. The tactic resembles other attacks on AI systems through crafted inputs: with Microsoft Copilot for Word, hidden text commands inside documents could manipulate content, and security researchers hijacked the coding agent Claude Code through crafted log data. What all these cases share is that the AI systems fail to reliably separate input data from trusted instructions.
What matters now is whether courts and law firms build in technical review routines before the tactic spreads. More and more law firms are experimenting with AI-assisted document analysis, even as the Connecticut court itself still does without it. For anyone who has a language model summarize or evaluate contracts, applications, or expert reports, the case is a reminder that text invisible to humans can become a weapon hidden inside a file.


