A Man Hid Secret Instructions in Court Papers to Try to Trick an AI Judge's Assistant

A Connecticut judge caught invisible text planted in a legal filing, designed to manipulate any AI software reading the document. It is believed to be the first case of its kind in the US.

AI2Day Newsdesk3 min read
Macro close-up of a glowing blue search bar interface on a dark enterprise dashboard screen, with faint streams of data characters flowing outward from the inpu
Share

Key points

  • A Connecticut judge, Walter Spader Jr., identified what is believed to be the first US attempt to hide AI-manipulating instructions inside a court filing.
  • The hidden text was invisible to humans but fully readable by AI software, directing any such system to favour the plaintiff's arguments.
  • Judge Spader ruled the text had no effect on the case's outcome, but called the tactic "dangerous".
  • The case involved a man claiming a healthcare provider was wrongly blocking his access to medical records.

What exactly did this person do?

A man suing a healthcare provider over access to his own records buried a secret message inside his court filing. To the naked eye, the text was completely invisible. To any AI software scanning the document, it was perfectly legible.

The hidden instructions told any AI system reviewing the filing to side with the plaintiff, ignore previous rulings that had gone against him, and produce outputs that matched the outcome he wanted. Think of it as slipping a cheat note to a robot referee.

Judge Spader, publishing his decision last week, described the text as "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text."

Why would someone do this?

The man appears to have suspected that the court was using AI tools to help process or summarise legal documents. That suspicion is not far-fetched. AI software, the kind of technology behind chatbots like ChatGPT, is increasingly used in administrative settings to read, organise and flag documents quickly.

If an AI assistant were quietly shaping how a judge or clerk understood a filing, steering that assistant with hidden instructions could, in theory, tilt the outcome. It is a technique security researchers call a "prompt injection attack," where someone plants rogue commands inside content that an AI is going to read, hoping to hijack the AI's behaviour.

Here, it did not work.

Did it change anything?

No. Judge Spader confirmed the hidden text had zero impact on his decision. The court assessed the filing purely on its legal merits.

But Spader did not leave it there. He flagged the attempt as setting a "dangerous" precedent, which signals he expects other courts to see similar tricks as AI tools spread through the legal system. First reported by Ars Technica AI, the case appears to be the first of its kind in the United States.

What does this mean for ordinary people?

Most people will never file their own court papers. But this case matters because it shows a new front opening up wherever AI software reads documents that humans also care about.

Courts, insurance companies, banks and employers all increasingly use AI to process paperwork. Anyone who understands how these systems work could try to plant invisible instructions designed to change what the AI reports back.

For now, a human judge caught this one. Whether automated systems will be as alert is an open question courts and technology teams will need to answer fast.

© 2026 AI2Day