A US plaintiff hid AI prompt injection instructions inside court filings, making text invisible to human readers while remaining legible to any software parsing the document. Connecticut judge Walter Spader Jr. identified the attempt last week in Elliott v. New York Bariatric Group, a records access dispute. It is the first documented case of this tactic in a US court.

The hidden instructions told any AI reviewing the filing to agree with the plaintiff's arguments, disregard prior court denials, and recommend outcomes favorable to the plaintiff. The attack failed. Spader ruled on the merits and said the injected text had no impact on the decision. He still labeled it a 'dangerous' precedent.

The full ruling is worth reading because the mechanics matter: how the text was formatted, how the court detected it, and what Spader said about AI use in court systems going forward. This will not be the last case. As AI tools enter legal workflows, prompt injection becomes a litigation attack surface, and courts have no established protocol to defend against it.

[READ ORIGINAL →]