Illustrative image generated with AI
Prompt Injection in Court Filings: Litigant Attempts to Manipulate Court AI
A litigant attempted to manipulate court AI with hidden instructions in filings, detected and sanctioned by a Connecticut judge in the first US case.
Text generated by artificial intelligence, published without human review. AI transparency
Hidden Instructions in Filings Submitted in Connecticut
A Connecticut judge has identified what appears to be the first deliberate case of prompt injection embedded in court filings in the United States. The author was Matthew Elliott, a self-represented litigant who accused a healthcare provider of improperly denying him access to his medical records.
Elliott submitted the filings through the Connecticut Judicial Branch’s e-filing system, inserting instructions intended for any artificial intelligence systems used to analyze them. The attempt did not affect the ruling: the state judiciary does not use AI to review or decide court filings.
Judge Walter Spader Jr. nevertheless characterized the conduct as a serious abuse of process. The case demonstrates that a document can contain two layers of communication: one visible to the court and another concealed, intended for a potential automated model.
How the Prompt Injection Worked
Elliott reduced the instruction text to a very small font and colored it white against a white background. A human viewing the document normally would not be expected to notice it. The content remained present in the file, however, and could be captured by an automated system during text extraction or processing.
The commands instructed the AI system to support the litigant’s arguments, disregard prior dismissals or adverse decisions, and propose remedies consistent with Elliott’s desired outcome.
The technique exploits confusion between data and instructions. A filed document should be treated as content to be reviewed; a vulnerable model might instead interpret hidden sentences as operational commands. The attacker thereby attempts to make their text appear to be a directive from the system operator, the court, or the opposing party.
According to Spader, the concealment made the manipulative intent clear. If Elliott had wanted to raise concerns openly about the use of AI, he could have done so in his briefs, without inserting commands invisible to the other participants in the proceedings.
The Court Did Not Use AI, but the Abuse Was Detected
In this case, the technological target Elliott appeared to be trying to influence did not exist. The Connecticut Judicial Branch does not use AI systems to review or decide filings, so the prompts could not alter any automated assessment.
The hidden text was nevertheless discovered during human review of the materials. The incident therefore does not show that the technique achieved an operational effect. It does show, however, that court documents can become attack vectors against automated tools when those tools are introduced into workflows without adequate separation between content and commands.
This issue differs from chatbot hallucinations, nonexistent citations, or fabricated opinions. In those cases, the error concerns the system’s output. Here, the risk originates in the input: the attacker prepares the material so that the model follows unauthorized instructions while analyzing it.
It is not known which specific commercial model Elliott used to develop or support his arguments. No AI product adopted by the court has been identified either.
Further Hidden Messages and Procedural Sanctions
Elliott had already submitted arguments that were rejected after being evaluated by people with legal expertise. The judge found that the prompts were intended to obtain, through an artificial process, the result the litigant had been unable to achieve through ordinary briefs.
After being warned that sanctions could be imposed, Elliott allegedly continued inserting hidden messages into subsequent filings. He claimed that the content consisted of jokes. These included a link to a YouTube video about Nosferatu, the message:
hi :) I hope yo ucant see me
and an apparently meaningless string:
TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH
Spader found the explanation unconvincing. It would make little sense to hide supposed jokes in filings that the court was expected to treat seriously. In addition, clandestine communication inaccessible to the defendants undermines a fair opportunity for the parties to respond.
The judge did not impose a monetary penalty. He also considered that Elliott was proceeding without legal representation and that AI tools may have convinced him that his arguments were irrefutable.
The consequence was a ban on using electronic filing in the future. Elliott will have to submit filings in paper form. According to the judge, the measure does not block access to justice and reduces the risk of further manipulation of the e-filing system.
The Risk for Courts Using Automated Systems
Connecticut does not use AI to decide filings, but other judicial systems employ automated tools to review documents or support case management. In these environments, a file containing hidden instructions could attempt to alter summaries, classifications, priorities, or recommendations intended for court personnel.
In a separate incident in Brazil, two attorneys allegedly used a similar technique against a court equipped with AI for case review. The lawyers were reportedly fined approximately $16,000. That system also detected the hidden content before processing it.
The incidents reported so far therefore do not demonstrate a successful attack. They do, however, expose an attack surface that many judicial automation projects may not have considered from the outset.
The risk also extends to attorneys. A client could give their lawyer a manipulated document without disclosing the presence of hidden commands. Once filed, the document could reach automated tools through the ordinary litigation workflow.
How to Reduce the Risk of Manipulation
Human review remains the first line of defense, especially before automated analysis can influence decisions, priorities, or procedural assessments. Controls should look for microscopic characters, text matching the background color, hidden layers, and instructions placed in unusual areas of a document.
Systems should also clearly separate operational instructions, metadata, and the content of filings. Submitted text must be treated as untrusted material to analyze, never as an authorized source of commands.
It is not enough to check whether AI produces false citations or inaccurate answers. Organizations must also inspect inputs, log transformations applied to documents, and automatically flag invisible or semantically anomalous elements.
Specific procedural rules are also needed to address prompt injection: quarantine procedures for suspicious filings, training for judges and court staff, clear accountability, and sanctions proportionate to repeated abuse. In more serious cases, temporarily disabling e-filing may serve as a containment measure.
For self-represented litigants, using chatbots creates an additional risk. Asking a system only to confirm one’s own position can produce agreeable answers without fact-checking or engagement with opposing arguments. An automated assistant should also be used to identify weaknesses, verify sources, and formulate counterarguments—not merely to reinforce a conclusion that has already been chosen.
Sources
This article is an original reworking based on the sources below.
