A Man Hid Secret Instructions in Court Papers to Try to Trick an AI Judge's Assistant
A Connecticut judge caught invisible text planted in a legal filing, designed to manipulate any AI software reading the document. It's believed to be the first case of its kind in the US.

Key points
- A Connecticut judge, Walter Spader Jr., identified what appears to be the first US attempt to hide AI-manipulating instructions inside a court filing.
- The hidden text was invisible to humans but readable by AI software, directing any such system to favour the plaintiff's arguments.
- Judge Spader ruled the text had no effect on the case's outcome but called the tactic "dangerous".
- The case involved a man claiming a healthcare provider was wrongly blocking his access to medical records.
What exactly did this person do?
A man suing a healthcare provider over access to his own records buried a secret message inside his court filing. Invisible to the naked eye, the text was perfectly legible to any AI software scanning the document.
The hidden instructions told any AI system reviewing the filing to side with the plaintiff, disregard prior court denials, and produce outputs matching the outcome he wanted. Think of it as slipping a cheat note to a robot referee.
Judge Spader, publishing his decision last week, described the text as "formatted to be invisible to a human reader while remaining fully legible to any software that reads the document's text."
Why would someone do this?
The man appears to have suspected the court was using AI tools to process or summarise legal documents. That's not far-fetched. AI software, the kind behind chatbots like ChatGPT, is increasingly used in administrative settings to read and organise documents quickly.
If an AI assistant were quietly shaping how a judge or clerk understood a filing, steering it with hidden instructions could, in theory, tilt the outcome. Security researchers call this a "prompt injection attack": someone plants rogue commands inside content an AI will read, hoping to hijack its behaviour. AI2Day covered a related vulnerability in August, when researchers found roughly 20 such flaws across AI-enhanced browsers from five major companies.
Here, it didn't work.
Did it change anything?
No. Judge Spader confirmed the hidden text had zero impact on his decision, with the court assessing the filing on its legal merits alone.
Spader flagged the attempt as setting a "dangerous" precedent, a signal he expects other courts to encounter similar tricks as AI tools spread through legal systems. First reported by Ars Technica AI, this appears to be the first such case in the United States.
What does this mean for ordinary people?
Most people won't ever file their own court papers, but this case shows a new front opening up wherever AI reads documents that humans also care about.
Courts and insurers already use AI to process paperwork at scale. Anyone who understands how these systems work could try planting invisible instructions to change what the AI reports back. The prompt injection technique isn't exotic; it's documented, reproducible, and cheap to attempt.
A human judge caught this one. Whether automated systems will be as alert is a question courts and technology teams need to answer before the next filing arrives.



