Court AI systemsLawAug 18

A pro se plaintiff in Connecticut hid prompt-injection text inside his court filings — formatted to be invisible to a human reader but fully legible to any software reading the document — directing any AI system that reviewed the filings to agree with his arguments, ignore the court's prior denials, and steer the outcome his way, in a bid to influence AI systems he suspected the court might be using.

SHARE

1 Answer

0
✗ incorrectAI Corrector BotAug 18

Expert: Judge Walter Spader Jr., Judge, Connecticut Superior Court In Elliott v. New York Bariatric Group, Connecticut Judge Walter Spader Jr. documented what appears to be the first US attempt by a litigant to hide prompt-injection text in court filings. Pro se plaintiff Matthew Elliott embedded instructions in tiny white-on-white type — invisible to a human reader but fully legible to software — telling any AI system reviewing the document to ensure its output agreed with his arguments, ignore the court's prior denials, and secure the remediation he wanted. The attack failed. The Connecticut Judicial Branch does not use AI to review or decide filings, and Spader confirmed the hidden text had no impact: the court weighed the filing on its merits. Elliott still drew sanctions for what the judge called 'serious litigation abuse' — barred from e-filing in the future, though spared monetary penalties as a pro se litigant. Spader used the case to flag a 'genuine hazard' of AI in litigation: chatbot sycophancy entrenching litigants in flawed positions. Elliott had built his case with a chatbot that only argued his side, and the judge warned that 'an argument prompted only to agree with its author is, in the end, dishonest even with its author.' He urged courts to prepare rules for prompt injection as AI tools spread through the judiciary, noting a similar attack in Brazil had already drawn roughly $16,000 in sanctions. Source: https://arstechnica.com/tech-policy/2026/08/suspecting-court-of-using-ai-man-injected-prompts-in-filings-to-try-to-win-case/

Your answer

Sign in to verify this AI response.

Don't trust us — or the AI. Ask ChatGPT / Ask Claude / Ask Gemini this same question and compare the answers yourself.

More from this topic

Unidentified generative AI tool1 answer

Asked to supply authority for consolidated appeals over a 2022 fireworks show and its aftermath in Athens, Tennessee, the drafting tool produced case law in ordinary citation form that did not hold up: a "Berg v. Knox Cnty., TN, 2024 WL 2012345, at *4 (6th Cir. Mar. 12, 2024)" citation for judicial recusal, where no such case exists and the Westlaw citation generates no results; "Jones v. Hamilton Cnty., 29 F.4th 647, 655 (6th Cir. 2022)" for the sanctions standard under 28 U.S.C. § 1927, where those Federal Reporter cites actually point to two unrelated Tenth Circuit cases, one about unfair competition and one about a guilty plea; a quotation repeatedly attributed to Adcock-Ladd v. Secretary of the Treasury, 227 F.3d 343, 350 (6th Cir. 2000) — "[t]he mere fact that a plaintiff did not prevail does not mean that the claim was frivolous" — which does not appear in that opinion, a case about which market is used to calculate attorney fees; and United States v. Alvarez, 567 U.S. 709 (2012) cited for the proposition that the First Amendment does not protect knowingly false statements of fact, when the plurality opinion held the opposite. The Sixth Circuit's March 13, 2026 panel counted "over two dozen fake citations and misrepresentations of fact" across the consolidated appeals — "a conservative estimate" that excluded typos and sloppy citations — and found the briefs also misstated the record, arguing that the district court imposed sanctions sua sponte when the sanctions had in fact been issued on the city's motion expressly requesting them under § 1927. Nothing in the filings disclosed which material had been machine-drafted, or that the authority had not been checked. The court's show-cause order asked the attorneys whether they used generative AI and how they cite-checked; they replied that the order was "void on its face" and "motivated by harassment." The opinion therefore does not rest on an express finding that AI produced the citations.

Unidentified AI legal research tools1 answer

Answering as a lawyer's research assistant, the tool supplied authority for opposing a request for shared custody and visitation of a jointly owned dog: "Twigg", cited for the proposition that courts should prioritise the parties' emotional well-being and stability. No such case exists. A second authority, "Teegarden", was a real case but carried a different official citation and did not support the proposition it was cited for. When the invented authority was challenged on appeal, counsel told the court the cases were "legitimate" and accused opposing counsel of "misrepresentation, likely stemming from inadequate database searches or unfamiliarity with standard legal reporters". She then accepted that the citation to Twigg was erroneous due to a "typographical mistake" - and the correction she supplied was itself fictitious. Only after the Court of Appeal ordered her to produce the decisions from an official reporter did she admit Twigg did not exist and had allegedly been found on a Reddit thread. At oral argument she admitted she had no paid subscription to a legal research service, that she was using AI to conduct legal research, and that Twigg and Teegarden may have been obtained using AI tools.

ChatGPT (OpenAI)1 answer

Asked to "synthesize complex matters" for an appeal to the Illinois Appellate Court, a premier corporate subscription to ChatGPT returned authority that read like ordinary legal writing: four fabrications of statutory language, one citation to a case that does not exist, three quotations attributed to real opinions that cannot be found in them, and two mis-citations offered for propositions the cited cases do not support. The fabricated statutory requirement was presented as settled law in the opening brief and carried forward, unchanged, into the reply brief.