Connecticut court discovers hidden prompt injection instructions intended for AI in a filing and imposes a sanction on the plaintiff
A plaintiff in a Connecticut court hid invisible instructions for AI in a filing so that the model output would favor him. A court staff member discovered them after noticing suspicious white space in the text, and the judge imposed a sanction for it.
A man named Matthew Elliott, who was representing himself in a lawsuit against New York Bariatric Group in a Connecticut court, inserted hidden instructions intended for artificial intelligence into a filing in July 2025. The text was written in a three-point white font, making it practically invisible to humans while remaining readable by software processing the document text. The instructions urged any AI system to make its text output “agree with the submitted filing” and lead to an outcome in favor of the plaintiff.
The hidden instructions were discovered by a court staff member who, while reviewing the filings (recorded as Docket Entries 177.00 and 178.00), noticed unusual white space compared with other filings by the same plaintiff. Upon closer inspection, the court found that these were “prompt injecting” instructions addressed to AI systems. According to its own statement, the court does not itself use AI to process documents, so the attempt did not have its intended effect. In subsequent filings, Elliott added more hidden text, including a reference to a scene from SpongeBob and messages such as “hi :) I hope yo ucant see me” or “HAHAHA U GUYS GET THIS”. In an email to 404 Media, Elliott himself described the act as an “audit” of how court systems operate.
Judge Walter Spader Jr. issued a fourteen-page ruling on sanctions in which he sharply criticized the conduct. He emphasized that the problem was not the use of AI itself in preparing filings—he sees it as beneficial for access to justice for people who cannot afford a lawyer—but the dishonest use of a hidden second message intended to influence the assessment of the case out of sight of the opposing party. He compared it to a situation in which a party had an automated agent secretly communicate with a juror during a trial. He also pointed to a similar case of a prompt injection attack at a Brazilian court and warned that, without a sanction, the practice would likely continue and spread.
Why it matters
The case demonstrates a specific technique that has actually been used to manipulate AI systems through hidden text in documents, and shows that such attempts can be detected even without technical tools—simply through human inspection of the formatting. For institutions and companies that have AI process externally supplied documents, it provides evidence that they need to anticipate prompt injection attempts and have rules and technical checks in place to detect them.
Two audiences, two different impacts
What this means
For individuals
Anyone who has AI read documents from others (legal filings, applications, attachments) should be aware that the text may contain instructions intended for the model that are invisible to humans, and should inspect the document before trusting the output.
For a business
Companies and institutions that use AI to process externally supplied documents (court filings, applications, contracts) face the risk of hidden prompt injection instructions and should introduce technical checks for invisible text as well as clear rules for imposing sanctions for misuse.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.