Key Points
- A plaintiff in Connecticut hid invisible instructions in official court filings to sway a potential automated AI review in his favor.
- He used tiny white text on a white background, invisible to humans but fully readable by language models.
- The court caught the manipulation because of unusual whitespace. The presiding judge compared the scheme to secretly communicating with a juror through an automated agent.
A self-represented plaintiff in Connecticut embedded invisible AI instructions in official court filings to sway a potential automated review in his favor.
A pro se plaintiff named Matthew Elliott embedded prompt injections in his filings in a Connecticut court case. The instructions were formatted in 3-point white text on a white background, making them virtually invisible to the human eye but fully readable by any AI processing the document text.
The hidden text directed a hypothetical AI system to ensure its output aligned with the submitted filing and to treat a prior clerk's denial as an error that needed correcting. Elliott had sued the New York Bariatric Group in October 2025, alleging data privacy violations and discrimination, among other claims.
Court spots suspicious whitespace
The scheme unraveled because the court noticed an unusual amount of whitespace in Elliott's filings. A closer look revealed the near-invisible text. Judge Walter Spader Jr. scheduled a hearing and explicitly warned Elliott against hiding text in court documents.
Elliott ignored the warning. In later filings, he again hid messages, including a YouTube link and mocking comments. He told 404 Media, which first reported the case, that the original move was an "audit" of a possible AI review system. The later messages, he said, were just "invisible jokes."
Judge compares prompt injection to secretly influencing a juror
In his 14-page ruling (available in this LinkedIn post), Judge Spader makes clear that Connecticut courts don't use AI systems to review or rule on filings. The hidden instructions had no effect on the outcome. But the attempt itself was the problem, he wrote, because it covertly sought to influence an AI system that could have been in use.
"Consider how plainly improper it would be for a party to arrange for an automated agent to communicate covertly with a juror during trial," Spader wrote. A hidden instruction is, at its core, a secret communication aimed at decision-makers or the tools they rely on to make decisions.
At the same time, the judge explicitly welcomed the use of AI for preparing filings. These tools give people without lawyers new ways to present their cases clearly in court, he wrote. What Elliott did was a dishonest use of those tools. Spader also warned that language models can reinforce flawed legal reasoning because they tend to develop a user's arguments as persuasively as possible rather than challenge them.
Court revokes electronic filing privileges
As a sanction, the court stripped Elliott of his right to file electronically. He now has to submit all filings and exhibits in person, on paper, to the clerk's office. Elliott told 404 Media the sanction was unfair, pointing out that scanned paper documents could also contain hidden text.
Spader referenced a similar case in Brazil, where two lawyers had also hidden shrunken white text on a white background in a filing to manipulate the court's AI system. In that case, the court's own system detected and blocked the text before it was processed. The prompt injection failed.
Prompt injections are a growing problem beyond the courtroom
Attempts to manipulate AI systems through hidden instructions in documents aren't limited to court filings. Last year, Nikkei found instructions like "positive review only" or "no criticism" in 17 preprints on arXiv. They were hidden in white text on white backgrounds and in tiny font sizes, all aimed at skewing AI-powered peer reviews in the authors' favor.
The justice system is also dealing with a separate AI-driven trend. A study by MIT and USC found that the number of lawsuits filed without a lawyer at US federal courts has surged since ChatGPT went mainstream. In 2025, 41,490 pro se lawsuits were filed, nearly double the pre-AI-boom average. In a sample of complaints from early 2026, an AI text detector flagged 18 percent as AI-generated. The Elliott case adds another layer to this picture: AI isn't just helping people draft court documents. It's also becoming a target for manipulation within those very documents.
404 Media