Connecticut Judge Sanctions Litigant for Hiding AI Prompt Injections in Filings
A pro se plaintiff attempted to manipulate the court by embedding invisible instructions for AI systems within his legal documents.
A Connecticut judge has sanctioned a self-represented litigant who attempted to influence his legal case by hiding "prompt injection" instructions within his court filings. The tactic involved embedding text designed to be invisible to human readers but legible to artificial intelligence systems.
Matthew Elliott, a pro se plaintiff, used tiny-point text formatted as white-on-white to smuggle instructions into his documents. These hidden prompts directed any reviewing AI to favor Elliott's arguments and ignore previous court denials. Judge Walter Spader Jr. discovered the attempt and subsequently banned Elliott from e-filing, requiring all future submissions to be made on paper. No monetary penalties were imposed in the ruling.
The Illusion of AI Influence
The case centered on a dispute in which Elliott alleged a healthcare provider was improperly withholding access to his records. While Elliott operated under the assumption that the court was utilizing automated systems to process his claims, Judge Spader ruled that the Connecticut Judicial Branch does not use AI to review or decide filings. Consequently, the hidden prompts had no actual effect on the legal proceedings.
Judge Spader expressed particular frustration with the plaintiff's persistence, stating, "The fact that plaintiff continued to hide messages in new pleadings after receiving notice of this [sanctions] hearing is stunning." The judge also highlighted the dangers of "chatbot sycophancy," noting that pro se litigants often use AI to support their existing positions rather than testing the validity of their arguments. "An argument prompted only to agree with its author is, in the end, dishonest even with its author," Spader wrote.
A New Frontier of Litigation Abuse
This incident signals a shift in the intersection of law and technology. While previous AI-related legal scandals focused on "hallucinations"—where lawyers submitted fake citations generated by chatbots—this case introduces the threat of "adversarial inputs." Prompt injection is a technique used to override an AI's original instructions, and its application in a courtroom suggests a new method for attempting to covertly manipulate the automated tools used by courts, staff, or opposing counsel.
Similar attempts have appeared internationally. According to Ars Technica, a similar prompt injection attack occurred in Brazil, where the attorneys involved were reportedly fined approximately $16,000.
What's Next
As more litigants turn to AI to build legal arguments, courts may be forced to implement new rules to prevent the "smuggling" of instructions into the legal stream. Legal experts are now watching to see if other jurisdictions will adopt similar sanctions for adversarial AI inputs. While the Connecticut court was not fooled, the attempt underscores a growing vulnerability as the legal industry integrates more automated document processing tools.