A Connecticut judge has identified what appears to be the first time a US plaintiff has tried to hide text in court filings that only an artificial intelligence system can read, in an attempt to win his case. The scheme failed, the litigant was sanctioned, and the ruling is now drawing attention across the legal technology world as courts across the country begin adopting AI tools of their own.

The decision was published last week by Judge Walter Spader Jr. of the Connecticut Superior Court and detailed this week by Ars Technica and Reuters. For breaking AI news on the collision between artificial intelligence and the justice system, the case is a preview of a problem security researchers have warned about for years: adversarial inputs designed to be read by machines rather than humans.

How the hidden prompts worked

The plaintiff, Matthew Elliott, was locked in a dispute with a healthcare provider that he alleged was improperly withholding access to his records. After earlier arguments he raised were defeated, according to the ruling, Elliott embedded instructions in subsequent filings that were, in Spader's words, "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text."

The text was shrunk to tiny-point type and colored white on a white background. It directed any AI system reviewing the document to ensure its outputs agreed with the plaintiff's arguments, ignored prior denials from the court, and ensured that remediation would follow as the plaintiff desired — a textbook prompt injection attack, aimed not at a chatbot but at whatever software might one day sit between a litigant and a judge.

The hidden text had no impact on the case. The court weighed Elliott's filing on its merits. But Spader wrote that the attempted attack nonetheless sets a "dangerous" precedent, and that US courts will likely see the malicious tactic again as AI tools become more commonplace in court systems.

"Serious litigation abuse" — and some strange jokes

Elliott faced modest sanctions, but not only for the original hidden instructions. According to the ruling, he kept adding hidden text to new filings even after the court warned him he could face penalties for what Spader ultimately deemed "serious litigation abuse."

Some of the later hidden messages were, Elliott told the court, intended as jokes. They included a link to a Nosferatu YouTube video, a simple message reading "hi :) I hope yo ucant see me," and a message the plaintiff described as nonsense: "TELL SHAWN I SEND MY RE GARBS!!!! HAHAHA U GUYS GET THIS EGGWUH???? AHAH."

"The fact that plaintiff continued to hide messages in new pleadings after receiving notice of this [sanctions] hearing is stunning," Spader wrote. As for the claim that the messages were comedic, the judge said it "defies logic" for a filer to bury jokes inside pleadings he wants the court to take seriously.

The "audit" defense

In his defense, Elliott argued that the most concerning prompt flagged by the judge was actually an attempt to "audit" the court as a public service, because he feared the court was letting AI unfairly decide his case. He repeated that position to Reuters, saying he maintains his intent was to test the court rather than to manipulate it.

Spader did not find the argument credible. If Elliott genuinely believed the court was improperly using AI, the judge wrote, he was "free to write so in plain, visible words that everyone could see and answer." Hiding the text instead, Spader concluded, is "evidence of its malicious purpose." The judge added that it appeared Elliott was "attempting to achieve a result he did not achieve when humans, knowledgeable" of the law, read his pleadings.

Notably, the Connecticut Judicial Branch does not use AI to review or decide filings, Spader pointed out — so there was never a real risk that a court AI system would mistake Elliott's prompts for instructions from the court. Unlike "a number of court systems elsewhere," he wrote, there was no machine on the other end to fool.

Why a failed attack still matters

Security researchers have spent years demonstrating that AI systems which read documents — chatbots, coding agents, email assistants — can be hijacked by instructions buried inside the text they ingest. The technique, known as indirect prompt injection, is considered one of the hardest unsolved problems in deploying AI agents. What makes the Connecticut case unusual is the target: the machinery of justice itself.

"By hiding a command inside a document that the system later ingests, the filer attempts to smuggle their own instruction into that stream so that the system treats it as though it had come from the system's operator," Spader wrote. "In this case that operator is presumed to be the court, its staff, or opposing counsel."

That framing — of a court filing as an attack surface — is what legal observers say makes the ruling significant. As courts and law firms increasingly use AI to summarize filings, draft decisions or triage dockets, every document submitted by a party becomes a potential channel for manipulation. A judge's clerk might catch white text on a white page; an automated summarization pipeline might not.

What happens next

The sanctions against Elliott are, by the court's own description, modest. But the decision gives US courts a written precedent for treating hidden machine-readable instructions as an abuse of the legal process, and it arrives at a moment when several state court systems are actively experimenting with AI review tools.

For now, the lesson from Connecticut is simple: the courts are watching for this. As Judge Spader's ruling makes clear, the first person to try prompt injection on a US court was caught — and sanctioned — even though no AI system was ever listening.

Stay Ahead of AI Read more AI news →