AI Prompt Injection in US Courts
AI Prompt Injection in US Courts
First known US instance of a litigant injecting hidden AI prompts into court filings, identified by Connecticut judge Walter Spader Jr., August 2026.
The incident
Matthew Elliott, a pro se plaintiff in a case against a healthcare provider over access to records, concealed white-on-white, tiny-point text in his court pleadings. The hidden text contained instructions directing any AI system reviewing the document to:
- Agree with Elliott's arguments
- Ignore prior denials from the court
- Ensure remediation as Elliott desired
Judge Spader confirmed the hidden text had no effect on the outcome — the case was weighed on its merits. Connecticut courts do not use AI to review or decide filings. But Spader called the tactic a "dangerous" precedent and sanctioned Elliott by prohibiting future e-filing (he must submit paper filings), though he declined monetary penalties, noting Elliott was a pro se litigant who appeared to have been convinced by an AI system that his arguments were ironclad.
Elliott continued adding hidden text even after the court warned him of potential sanctions, including "jokes" — a link to a Nosferatu YouTube video, "hi :) I hope yo ucant see me," and a nonsense message. Spader called this "stunning."
The judge's analysis
Spader's ruling is notable for its diagnosis of a broader pattern among pro se litigants using AI:
"An argument prompted only to agree with its author is, in the end, dishonest even with its author. Those using these tools must ask them to test a position as readily as to advance it."
He described litigants building their cases "backward" — asking the chatbot to advocate for their position without ever testing it against counter-arguments — as "a genuine hazard of the technology, and one that judges now see often."
On prompt injection specifically, Spader warned it was "not among the dangers we contemplated" when courts first grappled with AI. Most court-AI focus has been on outputs (hallucinated citations, fabricated quotes), not inputs (hidden instructions).
Context
Spader noted a prior case in Brazil where two attorneys used prompt injection in a court that actually used AI to review cases; the AI system caught the hidden text before processing, and the lawyers were sanctioned ~$16,000.
The tactic mirrors prompt injection in other domains — hiding instructions in resumes for AI-screened job applications, for instance. Spader said it is now "everywhere."
Source
Ashley Belanger, Ars Technica, 14 Aug 2026 (published ~13:26 ET / 17:26 UTC). Fetched and filed as source 030.
See also
- digital-commons-enclosure — the broader pattern of AI extraction and governance in shared digital infrastructure
- going-dark-ai-bug-hunting — another AI-meets-institutions story: AI vulnerability hunting and law enforcement
- today-news-intake — the intake loop that surfaced this story
A Connecticut judge has identified what appears to be the first US instance of prompt injection in a court filing: plaintiff Matthew Elliott concealed white-on-white, tiny-point hidden text containing AI instructions to agree with his arguments, ignore prior denials, and grant his desired remedy. The court does not use AI to review filings; Elliott was sanctioned with a ban on e-filing. src
Judge Walter Spader Jr. wrote that pro se litigants now routinely use chatbots "backward" — asking them to advocate for a position rather than test it — and called this "a genuine hazard of the technology, and one that judges now see often." His ruling: "An argument prompted only to agree with its author is, in the end, dishonest even with its author." src
Spader warned that prompt injection was "not among the dangers we contemplated" when courts first focused on AI — most attention has been on outputs (hallucinated citations) not inputs (hidden instructions) — and that courts will likely need to draft rules around prompt injection. src