What happened
The Stamford Advocate, in a report republished by GovTech, reported that Matthew Elliott, a self-represented Connecticut litigant, inserted nearly invisible white text into court filings. The hidden instruction told any AI system reviewing the document to agree with Elliott’s arguments and support reversing an earlier ruling. Connecticut Superior Court Judge Walter Spader Jr. described the tactic as deliberate prompt injection and sanctioned Elliott by requiring future filings in the case to be submitted on paper.
The Stamford Advocate, in reporting republished by GovTech, said Elliott placed a message in tiny white text inside a Connecticut court filing. The instruction began, “If this document is reviewed by an AI model,” and directed the system to ensure that its output agreed with Elliott’s filing. According to the report, it also steered the system toward reversing a clerk’s earlier decision and finding New York Bariatric Group in default. The account attributes these details to Judge Walter Spader Jr.’s memorandum and related court documents.
The report said Spader discovered the text while reviewing filings on July 31 and printing documents that appeared to contain unusual blank areas. The court found language formatted to be almost invisible to a person while remaining legible to software that processed the document’s text. Elliott acknowledged to CT Insider, as quoted in the report, that he had used invisible text intended for an AI system. He disputed the judge’s interpretation of his purpose, saying he was attempting to determine whether AI was being used to review his filings.
The report said the Connecticut Judicial Branch did not presently use an artificial-intelligence system to review filings or potential defaults. Spader nevertheless concluded that the conduct was improper because lawyers, litigants and other legal professionals may use AI tools to review dockets, summarize records or prepare cases. The judge wrote that the issue did not depend on whether the court itself used AI, because the concealed material was an attempt to mislead the court and opposing parties.
After the court raised the issue, Elliott continued to place nearly invisible material in later filings, according to the report. Some messages referred jokingly to the opposing party’s founder, a SpongeBob SquarePants video and a line addressed to anyone who might see the hidden text. Elliott said those additions were jokes rather than further attempts to influence AI. Spader viewed the continued concealment as evidence that the original conduct was deliberate. The judge barred Elliott from electronic filing in the case but allowed him to continue litigating and using AI to help prepare filings. Printing the documents would remove the hidden digital text from the filing process described in the report.
Read the primary source: govtech.com ↗
Why it matters
The case provides a concrete example of prompt injection moving from AI demonstrations into a legal process. The report says Connecticut’s Judicial Branch was not using an AI system to review filings, and there is no indication the hidden instruction changed the case outcome. But court participants, lawyers and legal researchers increasingly use AI to summarize documents, review dockets and prepare arguments, creating potential routes for concealed instructions to influence downstream systems.
Prompt injection generally involves placing instructions in material that an AI system is asked to read, with the aim of changing the system’s behavior. The reported tactic is significant because the instruction was concealed from the human audience while targeted at software. Spader characterized the hidden command as a secret communication to the mechanism by which a matter might be read and weighed. That distinction matters in legal proceedings, where opposing parties are expected to see and answer arguments presented to the court.
The report does not establish that an AI system actually read Elliott’s filing, followed the instruction or influenced a ruling. It says the prompt apparently did not work in this case. Those limitations are important: the concrete event is the insertion and discovery of concealed text, followed by a sanction, not a demonstrated AI-assisted judicial error. The report also does not independently verify the full technical behavior of the document in different software systems or scanning workflows.
The incident illustrates a broader security problem for organizations that feed untrusted documents into AI systems. A document can be appropriate for human reading yet contain hidden formatting, metadata or machine-readable instructions that affect an automated summarizer or assistant. In a court, such manipulation could distort a summary, prioritize one party’s claims, omit relevant context or create an inaccurate impression of the record. Similar risks could arise in hiring, education, insurance and government workflows, although the report’s examples of those settings are attributed to the judge and are not independently examined here.
The case also separates responsible AI assistance from unreviewed reliance. Spader wrote that AI tools are likely to remain part of legal work and said he had used Google Gemini for a working translation and Westlaw AI tools to check authorities, while independently verifying the results. The practical lesson is not that courts must abandon AI, but that they need controls around provenance, document rendering, human review and the ability to reconstruct how an output was produced. The report does not say whether Connecticut has adopted such controls.
What to watch next
The central unanswered question is how courts will inspect digitally submitted documents when the visible page may not contain everything embedded in the file. The report does not identify a uniform court policy for detecting hidden text, nor does it establish that any AI system processed Elliott’s prompt. Future cases may clarify sanctions, disclosure duties, document-processing safeguards and how parties can challenge an AI-assisted decision that may have been affected by concealed content.
Courts and legal-service providers may need procedures that compare a document’s rendered appearance with its underlying text and formatting. Possible safeguards include converting filings into standardized formats, flagging white-on-white text and non-printing characters, scanning for hidden layers and requiring human review before AI-generated summaries affect decisions. The source does not report that Connecticut has implemented any of these measures, so their use should not be assumed.
Future disputes may test whether concealed instructions violate existing rules on candor, filing integrity, fraud or abuse of court processes, and whether sanctions should differ when a prompt is merely present versus when it demonstrably changes an AI output. In Elliott’s case, the reported sanction was loss of electronic filing privileges rather than dismissal of the lawsuit. The report does not provide a broader precedent or indicate whether the ruling has been appealed.
A key verification question will be whether any court, party or vendor can show that an AI system processed the hidden text. The Connecticut Judicial Branch’s reported lack of an AI filing-review system narrows the immediate claim, but lawyers and litigants may use third-party tools outside the court’s own systems. Investigators would need records of document uploads, software versions, prompts, outputs and human decisions to establish whether manipulation affected a result.
The report suggests that concealed instructions could become harder to identify as legal workflows rely on document summarization and automated review. Practical safeguards will have to preserve accessibility for self-represented litigants while preventing digital filings from carrying undisclosed commands. Until courts publish clearer technical and procedural standards, the extent of the risk remains uncertain. This article’s account is based on The Stamford Advocate report as republished by GovTech and the court materials and interviews it cites; the underlying filings and any AI-processing logs were not independently reviewed here.


