We Are Not Reading the Same Brief

Last November, I wrote a piece called Are We Reading the Same Brief? I had read about “white text” being used to influence automated review in academia and started wondering what would happen when the same idea reached the courts. As judges and clerks began using GenAI to summarize filings, review records, and check compliance with court rules, could someone hide instructions in a filing that the judge could not see but the machine could read?

At the time, it was a thought exercise. I ended the article by saying, “I hope that I am wrong and that this article is way off base.” Sadly, I was not.

Jason Koebler at 404 Media reported this week on Elliott v. New York Bariatric Group, LLC, a Connecticut case in which a self-represented litigant placed hidden prompt-injection instructions in court filings using tiny white text on a white background. The instructions were not meant for the judge. They were meant for any AI system that might later process the filing, telling the system, in substance, to favor the litigant’s position.

What caught my attention was how the court found it. No sophisticated security system detected the prompt, and no AI tool sounded an alarm. Someone noticed that the filings seemed to contain more white space than the plaintiff’s other filings and took a closer look.

The attempted prompt injection never actually reached a court AI system because the Connecticut courts do not use one to review the filings. Judge Walter Spader had reviewed the motion from a printed copy. But that misses the point.

The filing was designed to have two conversations at once. One was visible to the judge and opposing counsel. The other was hidden inside the document for a machine that might eventually read it. Judge Spader compared that hidden communication to an ex parte communication because it created a channel intended to influence part of the process that the other side could not see or answer.

See the decision here: Elliott v. New York Bariatric Group, LLC, DOCKET NO: AAN-CV-25-6066141-S

Judge Spader also pointed to a recent labor case in Brazil involving the same basic technique. There, hidden white-on-white instructions were aimed at the court’s AI system, but the system detected the concealed material and blocked it before it could be processed.

That is where this gets more interesting because the problem is broader than courts.

Judge Spader noted that the hidden instruction was aimed at whatever AI tool any reader of the filing might use, including opposing counsel. He then went further, warning lawyers to think about the documents they feed into their own tools. An opponent’s production, a witness statement, or an expert report could contain the same kind of hidden instruction.

Courts may eventually need to build protections into the AI layer over their case management systems. But lawyers and judges are already using these tools today, which means we need to start paying attention now. I am not a technologist, so I will leave the mechanics to people who are. But any system we use should probably be designed so that hidden instructions in a document cannot quietly steer the AI tool, and suspicious material is flagged for human review.

Next
Next

Very Good May Be Good Enough